EuroComply
Free assessment

EU AI Act · comparison

EU AI Act vs GDPR: What Is Different, What Overlaps, and What You Still Need

GDPR compliance does not make you AI Act compliant. Side-by-side comparison of scope, obligations, documentation, fines and enforcement, with the overlaps you can reuse.

Classify my system in 3 minutes

The bottom line

GDPR is a data-protection law enforced by data protection authorities; the AI Act is a product-safety law enforced by market surveillance authorities. Doing GDPR well gives you perhaps a third of the AI Act file for a high-risk system (privacy notice, DPIA, Art. 22 rights) and none of the product-safety core (risk management system, technical documentation, conformity assessment, CE marking, EU database registration).

The most common assumption we hear from companies that have done the GDPR work: “we are covered”. They are not. GDPR regulates personal data; the EU AI Act regulates AI systems as products, whether or not they process personal data. A machine-vision system that inspects welds touches no personal data and can still be a high-risk system. A chatbot that stores nothing can still owe an Article 50 disclosure.

The two laws do overlap, and the overlap is where a GDPR-mature company saves the most time: DPIAs, records of processing, transparency notices and the Article 22 rights on automated decisions all map onto AI Act deliverables. This page shows where the reuse is real and where it is not.

Side by side

EU AI Act vs GDPR

DimensionEU AI ActGDPR
What it regulatesAI systems and general-purpose AI models placed on the EU market or used in the EU, by risk tierProcessing of personal data of people in the EU, regardless of technology
Legal basisRegulation (EU) 2024/1689, in force 1 August 2024, phased application 2025-2028Regulation (EU) 2016/679, applicable since 25 May 2018
Who is obligedProviders (developers), deployers (users), importers, distributors, authorised representativesControllers and processors
ClassificationProhibited / high-risk / limited (transparency) / minimal, by intended purposeNo tiers; risk-based measures (DPIA) for high-risk processing
Core documentationAnnex IV technical documentation, risk management file, data governance records, instructions for use, EU declaration of conformityRecords of processing (Art. 30), DPIA (Art. 35), privacy notices (Arts. 13-14), DPAs with processors
Pre-market stepConformity assessment, CE marking and EU database registration for high-risk systemsNone; prior consultation with the authority only when a DPIA shows high residual risk
Transparency to individualsTell people they interact with AI; label synthetic content; explain high-risk decisions on request (Art. 86)Privacy notice; information about automated decision-making and its logic (Arts. 13-15, 22)
Human oversightDesign requirement for high-risk systems (Art. 14) plus deployer duty to assign overseersRight to obtain human intervention in solely automated decisions with legal or similar effects (Art. 22)
Data qualityTraining, validation and testing data must be relevant, representative and examined for bias (Art. 10)Accuracy principle (Art. 5(1)(d)); no training-data rules
Maximum fines€35M or 7% of global turnover (prohibited practices); €15M or 3% (other obligations)€20M or 4% of global turnover
RegulatorNational market surveillance authorities, notified bodies, the EU AI Office (for GPAI models)National data protection authorities, the EDPB
Applies to non-EU companiesYes, when the system is placed on the EU market or its output is used in the EUYes, when offering goods or services to, or monitoring, people in the EU

Reuse this

Where GDPR work counts toward the AI Act

  • A DPIA (GDPR Art. 35) is a strong input for the AI Act risk management file and, for deployers, for the fundamental rights impact assessment (Art. 27); the AI Act says the two can be combined.
  • Privacy notices already describe automated decision-making; extend them with the AI-specific disclosures and you cover Art. 50(2) expectations.
  • Article 22 rights (human intervention, contesting a decision) are the same mechanism the AI Act expects in human oversight and Art. 86 explanations.
  • Records of processing give you the data provenance and purpose limitation facts that the Art. 10 data governance record needs.
  • Data protection officers usually become the natural AI compliance owner in SMEs.

Still needed

What GDPR does not cover

  • Risk management system across the lifecycle (Art. 9), with testing against defined metrics.
  • Annex IV technical documentation and Art. 12 automatic logging.
  • Accuracy, robustness and cybersecurity requirements (Art. 15).
  • Conformity assessment, EU declaration of conformity, CE marking, EU database registration (Arts. 43-49).
  • Post-market monitoring plan and serious-incident reporting (Arts. 72-73).
  • Prohibited practices that have nothing to do with personal data, such as manipulative techniques.
  • AI literacy duty for staff (Art. 4), which applies even to minimal-risk systems.

Know exactly where you stand under the AI Act

Free 7-question assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

FAQ

Frequently asked questions

If my AI system processes no personal data, does the AI Act still apply?

Yes. The AI Act classifies by intended purpose, not by data. A predictive-maintenance system for a power grid processes no personal data and is high-risk under Annex III(2).

Can one document satisfy both laws?

Partly. The AI Act explicitly allows the fundamental rights impact assessment to build on a DPIA, and financial institutions can integrate AI Act duties into existing governance. The technical file and conformity assessment have no GDPR equivalent and must be produced separately.

Which authority will knock on the door?

For data issues, the data protection authority. For AI Act issues, the market surveillance authority designated by the Member State (in several countries the DPA has been given both roles). Fines can be cumulative if the same conduct breaches both laws.

This page is general information, updated 2026-09-19. It is not legal advice; always check current guidance for both frameworks against your specific system.

Related use cases

High-risk

Recruitment & CV screening

Read →

High-risk

Credit scoring & lending

Read →

Limited risk

Customer service chatbots

Read →