ISHIGHRISK AI
Analysis

Where the EU AI Act and the GDPR overlap

The AI Act and the GDPR stack rather than replace one another. Where the duties overlap, where they diverge, and which regulator enforces which breach.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

The AI Act and the GDPR apply cumulatively, so a documented lawful basis and a completed DPIA say nothing about whether a system needs a conformity assessment, an Annex IV file and a registration entry. The Act reaches into data protection in four places only: Article 10(5) on special category data for bias detection, Article 26(9) on the DPIA, Article 27 on the fundamental rights impact assessment and Article 50(3) on emotion recognition and biometric categorisation. Each is a bridge, not a substitution. The Article 27 FRIA is a deployer duty tied to the high-risk application date, 2 December 2027 for standalone Annex III systems, so it is not live today while the Article 35 DPIA duty is. Different authorities enforce the two instruments, so one regulator signing off tells you nothing about your position under the other.

Two regimes, and neither absorbs the other

Regulation (EU) 2024/1689 and the GDPR apply cumulatively. An AI system that processes personal data sits inside both, and satisfying one discharges nothing under the other. Two opposite errors follow, and the same organisation often holds both at once.

Error one: we are GDPR compliant, so the AI Act is covered.A lawful basis, a record of processing and a completed data protection impact assessment are evidence about a processing operation. The AI Act's central duties attach to a system as a product: risk management, data governance, technical documentation, human oversight, accuracy and robustness under Articles 9 to 15, a conformity assessment under Article 43 and registration under Article 49. A data protection programme produces none of it, and no data protection authority assesses it.

Error two: the AI Act replaces the GDPR for AI. It does not, and the text says so. Art 50(3) requires deployers of emotion recognition and biometric categorisation systems to process personal data in accordance with the GDPR. Art 26(9) makes the deployer obligations without prejudice to the Article 35 GDPR duty to carry out a DPIA. Where the Act does reach into data protection ground, at Article 10(5), it grants a narrow permission rather than a carve-out.

The state of play sharpens the point. The GDPR applies in full to every processing operation you run today. The AI Act arrives in stages: the Article 5 prohibitions and the Article 4 AI-literacy duty since 2 February 2025, the general-purpose model chapter and the Article 99 penalties since 2 August 2025, Article 50 transparency from 2 August 2026, and the high-risk obligations from 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I products. Regulation (EU) 2026/1744, which entered into force on 27 July 2026, is what moved that first high-risk date. That staggering is itself a reason to run two assessments rather than one.

What each one is actually regulating

The GDPR regulates the processing of personal data. Its trigger is factual: personal data is being processed, so a controller exists, a lawful basis is needed and individual rights attach. Nothing about the technology matters to whether it applies.

The AI Act regulates the placing on the market and the putting into service of AI systems, and it is built on the European product safety model. Its trigger is a classification: what the system is, what its intended purpose is, and which role you occupy. The output is a conformity architecture rather than a rights framework: documentation drawn up before market placement, an assessment against harmonised requirements, a declaration and a register entry. The high-risk regime is where it is heaviest.

That difference explains most of the confusion. Two systems processing identical personal data can land in different places under the AI Act, because it asks about intended purpose rather than the data. A loan-scoring model and a film recommender may run on the same customer records. Only the first sits in Annex III.

Regulation (EU) 2024/1689GDPR
ScopePlacing on the market, putting into service and use of AI systems and general-purpose modelsProcessing of personal data
TriggerClassification: Article 5 prohibition, Article 6 high-risk, Article 50 transparencyPersonal data is being processed
Who is boundProviders, deployers, importers, distributors, product manufacturers, including third-country actors whose output is used in the UnionControllers and processors
Key artefactAnnex IV technical documentation, conformity assessment, declaration, registrationLawful basis, record of processing, DPIA
RegulatorMarket surveillance authorities under Article 70, AI Office for general-purpose modelsData protection supervisory authorities
Ceiling€35,000,000 or 7% for Article 5, €15,000,000 or 3% for most other duties€20,000,000 or 4% of worldwide annual turnover

The four places the AI Act reaches into the GDPR

The Act is not silent about data protection, but it touches it in four specific places, and knowing them is the difference between reading the Act as an overlay and reading it as a replacement.

  • Article 10(5), special category data for bias detection. Providers of high-risk systems may process special categories of personal data strictly for the purpose of bias detection and correction, subject to safeguards. Read the conditions, not the headline: confined to the high-risk context, confined to that purpose, conditional on the safeguards. It is not a licence to collect Article 9 GDPR data across a product because a fairness metric might one day want it.
  • Article 26(9), the DPIA interaction. Deployer obligations are without prejudice to the Article 35 GDPR duty, and the Article 13 instructions for use may be used to help discharge it. The drafting assumes the DPIA still happens: a source document, not an exemption.
  • Article 27, the fundamental rights impact assessment. A separate deployer duty on certain deployers of Annex III systems, before first use, dealt with below.
  • Article 50(3), emotion recognition and biometric categorisation. Deployers must inform the natural persons exposed to the system and process personal data in accordance with the GDPR. The duty applies from 2 August 2026, and it sits on top of the Article 5 prohibitions that have applied since 2 February 2025, which already bar emotion recognition in the workplace and in education and biometric categorisation inferring sensitive traits. Article 50(3) governs what is left. The full set of limbs is on the Article 50 transparency page. Note that informing a person under 50(3) is a transparency duty under the Act, not a lawful basis under Article 6 GDPR.

The GDPR hooks that bite hardest on AI

Traffic runs the other way. Five provisions do most of the work on an AI pipeline.

  • Article 5, the principles. Purpose limitation and data minimisation are where training-data reuse fails first, because data collected to run a service is not automatically available to train a model on. Article 5(2) accountability means you must be able to demonstrate the answer, not merely hold it.
  • Article 6, lawful basis. Collection, training, evaluation and inference each need one. The AI Act does not supply it and cannot cure its absence: a clean conformity assessment on an unlawfully trained model leaves the model unlawfully trained.
  • Article 9, special categories. The default is prohibition. Article 10(5) of the AI Act helps only inside bias detection and correction for high-risk systems, and inferred special category data is a recurring exposure in models never designed to collect it.
  • Article 22, automated individual decision-making. It turns on whether a decision is based solely on automated processing and produces legal effects or similarly significantly affects the person. That test is independent of the AI Act tier, so a system outside Annex III can still be an Article 22 decision.
  • Article 35, DPIAs. Triggered where the processing is likely to result in a high risk to the rights and freedoms of individuals, not by an AI Act classification, and live today.

Why a FRIA is not a DPIA under another name

This is the merge teams most often attempt and most often regret: the two assessments are owed by different parties, triggered by different facts and due on different dates.

A DPIA under Article 35 GDPR is owed by a controller whenever the processing is likely to result in a high risk to the rights and freedoms of individuals. AI is one route to that threshold, not the test. A fundamental rights impact assessment under Article 27 is owed by a defined class: bodies governed by public law, private entities providing public services, and deployers of the Annex III credit-scoring and life and health insurance systems. It is triggered by who you are and how the system is classified, and it is due before first use. Article 26(9) settles the relationship: deployer obligations are without prejudice to the DPIA duty, drafting that assumes both documents exist.

Timing is the practical difference.

2 Aug 2026Article 50 transparency applies, including 50(3), which requires GDPR-compliant processing on its face.
2 Dec 2027High-risk obligations apply to standalone Annex III systems, and with them the Article 27 FRIA duty for the deployers it names.

No FRIA is due today. The Article 35 DPIA duty, by contrast, bites now on any AI project that meets its threshold. A single combined "AI impact assessment" usually satisfies neither: too much data protection detail for the fundamental rights question, too little on the deployment context the Act asks about. Build the DPIA properly now, and design it so the Article 27 assessment can sit alongside it later rather than inside it. The timeline page sets out the rest of the sequence.

Two enforcers, two penalty ladders

Data protection authorities enforce the GDPR. Most of the AI Act is enforced by market surveillance authorities designated under Article 70, with the AI Office handling general-purpose AI models.

One authority signing off tells you nothing about the other. A data protection authority that accepts your DPIA has expressed no view on your Article 6 classification, your Annex IV file or your registration. A market surveillance authority satisfied with your technical documentation has expressed no view on your lawful basis for training data.

Designation is also uneven. Member states had to designate national competent authorities by 2 August 2025 under Article 70, and only 8 of the 27 did so on time, with the DGCCRF in France, AESIA in Spain and the Bundesnetzagentur in Germany among the front-runners. In several member states the counterpart to your data protection authority is still being stood up while the obligations run, which is a reason to document your reasoning contemporaneously rather than wait.

The penalty ladders are separate. Under Article 99, enforceable since 2 August 2025, Article 5 breaches carry €35,000,000 or 7% of total worldwide annual turnover, and most other obligations, including Article 50 and the high-risk regime, carry €15,000,000 or 3%. Companies pay the higher of the fixed sum and the percentage, except that under Article 99(6) SMEs and start-ups pay the lower. The GDPR upper tier runs to €20,000,000 or 4%, also the higher of the two. Separate instruments, separate bodies, so an AI Act figure tells you nothing about GDPR exposure on the same system. The tiers are broken down on the penalties page.

What transfers, and what does not

A mature data protection function is a real head start, provided you are honest about which parts transfer.

Transfers, with adaptation. The record of processing activities is the skeleton of an AI system inventory, because it already names the systems, the purposes and the owners. The DPIA machinery, the risk register, the review cadence and the habit of consulting affected groups, is the closest thing most organisations have to an Article 27 process. Data lineage work done for minimisation and retention feeds the Article 10 data governance requirements and the training-content summary Article 53 requires of general-purpose model providers. The accountability posture transfers wholesale: contemporaneous records, named owners, documented reasoning.

Does not transfer. Lawful basis has no AI Act equivalent, and no AI Act artefact creates one. Conformity assessment under Article 43, the declaration and registration under Article 49 have no data protection analogue. Neither does the Annex IV technical file, nine blocks drawn up before market placement and retained around ten years, with a simplified form for SMEs under Article 11(2). Role classification does not map either: controller and processor sit on a different axis from provider and deployer, so a processor can be a provider and a controller can be a deployer. Article 25 has no GDPR counterpart at all: it flips a deployer, importer or distributor into a provider that puts its name or trademark on a high-risk system, substantially modifies one so that it stays high-risk, or changes the intended purpose of any system so that it becomes high-risk. The roles page works through the triggers.

The habit worth building this week is small: keep one inventory with two columns, one for the data protection position and one for the AI Act position, and never let an entry in one be offered as evidence for the other. If you have not established which tier your systems fall into, the free classifier runs the tests in order and names the article each answer rests on.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Does GDPR compliance mean we comply with the EU AI Act?

No. The two regulations apply cumulatively and they test different things. A lawful basis, a record of processing and a completed DPIA are evidence about a processing operation; the AI Act asks whether a system is prohibited under Article 5, whether it is high-risk under Article 6, and whether it owes transparency duties under Article 50. A high-risk system needs a risk management system, technical documentation, a conformity assessment under Article 43 and registration under Article 49, none of which a data protection programme produces.

Does the EU AI Act replace the GDPR for AI systems?

No, and the Act says so in its own text. Article 50(3) requires deployers of emotion recognition and biometric categorisation systems to process personal data in accordance with the GDPR. Article 26(9) provides that the deployer obligations are without prejudice to the DPIA duty under Article 35 GDPR, and points at the Article 13 instructions for use as an input to that assessment. Where the Act does touch data protection ground, at Article 10(5), it grants one narrow permission rather than a carve-out.

Do we need a fundamental rights impact assessment as well as a DPIA?

If Article 27 catches you, yes, and they are separate documents. Article 27 binds a defined class of deployers of Annex III high-risk systems: bodies governed by public law, private entities providing public services, and deployers of the credit-scoring and life and health insurance systems. It has to be done before first use, and it is tied to the high-risk application date, which the Digital Omnibus moved to 2 December 2027 for standalone Annex III systems. The Article 35 DPIA duty is triggered separately, where the processing is likely to result in a high risk to the rights and freedoms of individuals.

Can we process special category data to test our AI model for bias?

Article 10(5) of the AI Act permits processing of special categories of personal data strictly for the purpose of bias detection and correction in high-risk AI systems, subject to safeguards. It is narrow on three counts: it is confined to the high-risk context, confined to the bias detection and correction purpose, and conditional on the safeguards. It is not a general licence to collect ethnicity, health or other Article 9 GDPR data across a product, and outside its scope the Article 9 prohibition applies as normal.

Which regulator enforces the EU AI Act, the data protection authority?

Not by default. Data protection authorities enforce the GDPR. Most of the AI Act is enforced by national market surveillance authorities designated under Article 70, with the AI Office handling general-purpose AI models. Designation has been slow: member states were required to name their national competent authorities by 2 August 2025 and only 8 of the 27 did so on time, with the DGCCRF in France, AESIA in Spain and the Bundesnetzagentur in Germany among the front-runners.

Does the AI Act change Article 22 GDPR on automated decisions?

Article 22 GDPR continues to apply on its own terms, and nothing in the AI Act supplies a lawful basis or an exception to it. The two tests are independent: Article 22 turns on whether a decision is based solely on automated processing and produces legal effects or similarly significantly affects the person, while the AI Act turns on the intended purpose of the system and the role you occupy. A system can sit outside Annex III entirely and still be an Article 22 decision, and a high-risk system with meaningful human involvement can fall outside Article 22 while carrying the full Articles 9 to 15 obligation set.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.