Organizations building or deploying AI in Europe now answer to two regulators at once. The GDPR governs the personal data an AI system learns from and operates on; the AI Act (Regulation 2024/1689) governs the system itself, by risk tier. Neither displaces the other, and the fines stack: up to 4% of turnover under GDPR, up to 7% for prohibited AI practices.
| Regulation | AI Act (2024/1689) + GDPR (2016/679) |
|---|---|
| Max penalty | EUR 35M or 7% of turnover (AI Act Art. 99); EUR 20M or 4% (GDPR) |
| Key dates | In force Aug 2024; prohibitions Feb 2025; GPAI Aug 2025; high-risk Aug 2026 |
| Enforcing authority | EU AI Office, national authorities; DPAs for GDPR |
| Official text | EUR-Lex CELEX 32024R1689 |
The risk-tier architecture
The AI Act sorts systems into four tiers. Article 5 prohibitions are absolute and carry the top fine: social scoring, exploitation of vulnerabilities, untargeted facial-image scraping, workplace and school emotion recognition, and most real-time public biometric identification. High-risk systems, listed in Annex III (employment, credit, education, essential services, law enforcement, and more), carry the heavy machinery: risk management, data governance, technical documentation, logging, human oversight, and conformity assessment. Limited-risk systems get transparency duties (see our AI Act transparency guide), and everything else is minimal risk.
Notice how many prohibited and high-risk categories are privacy problems restated: biometrics, monitoring, profiling people for consequential decisions. That is why the same system usually triggers both regimes.
Where the regimes interlock
Training data. GDPR applies to personal data in training sets regardless of what the AI Act says. The EDPB’s December 2024 opinion on AI models addresses when models trained on personal data can be treated as anonymous and how legitimate interests is assessed; the safe assumption is that scraped-data training needs a documented balancing test, minimization, and a response plan for data subject rights.
Automated decisions. GDPR Article 22 restricts solely automated decisions with legal or significant effects; Annex III makes many of the same systems high-risk. One system, two overlapping duty sets, covered in our automated decision-making guide.
Assessments. A high-risk deployer may owe a fundamental rights impact assessment (Article 27) while the same processing triggers a GDPR DPIA. The AI Act explicitly allows combining them; our combined assessment methodology shows how.
Data governance. Article 10 requires training, validation, and testing data to be relevant, representative, and managed for bias, with a specific legal gate for processing special category data to detect bias. Details in the high-risk data governance guide.
Sequencing compliance
Inventory AI systems and classify them by tier first; the classification drives everything. Kill or redesign anything touching an Article 5 prohibition before February deadlines matter to you. For high-risk systems, stand up the documentation and data governance early, since retrofitting provenance onto trained models is the hardest task in the regulation. And keep the GDPR fundamentals current, because a DPA does not need to wait for AI Act enforcement to fine unlawful processing. If your AI features run on your website, check what data they collect from visitors with a free scan.