EU Privacy Law EU/EEA

EU AI Act and GDPR: How the Two Regimes Apply to AI Systems Together

Where the EU AI Act and GDPR overlap for AI that processes personal data: risk tiers, prohibited practices, dual obligations, and the compliance sequence.

Regulation

Regulation (EU) 2024/1689 (AI Act); Regulation (EU) 2016/679 (GDPR)

Max Penalty

EUR 35 million or 7% of global annual turnover (AI Act prohibited practices)

Enforcing Authority

EU AI Office and national market surveillance authorities; DPAs for GDPR

Official Source

eur-lex.europa.eu

Executive Summary

  • The AI Act (Regulation 2024/1689) entered into force on 1 August 2024, with prohibitions applying from February 2025, GPAI rules from August 2025, and most high-risk obligations from August 2026.
  • It regulates AI systems by risk tier: prohibited practices, high-risk systems, limited-risk transparency cases, and minimal risk.
  • The AI Act does not replace GDPR: any AI system processing personal data must satisfy both, and the AI Act says so explicitly (Article 2(7)).
  • Prohibited practices with privacy weight include untargeted facial-image scraping, workplace emotion recognition, and social scoring, fined at the top tier of EUR 35 million or 7% of turnover.
  • The practical overlap points are lawful basis for training data, Article 22 automated decisions, DPIAs feeding fundamental rights impact assessments, and data governance duties for high-risk systems.

Organizations building or deploying AI in Europe now answer to two regulators at once. The GDPR governs the personal data an AI system learns from and operates on; the AI Act (Regulation 2024/1689) governs the system itself, by risk tier. Neither displaces the other, and the fines stack: up to 4% of turnover under GDPR, up to 7% for prohibited AI practices.

RegulationAI Act (2024/1689) + GDPR (2016/679)
Max penaltyEUR 35M or 7% of turnover (AI Act Art. 99); EUR 20M or 4% (GDPR)
Key datesIn force Aug 2024; prohibitions Feb 2025; GPAI Aug 2025; high-risk Aug 2026
Enforcing authorityEU AI Office, national authorities; DPAs for GDPR
Official textEUR-Lex CELEX 32024R1689

The risk-tier architecture

The AI Act sorts systems into four tiers. Article 5 prohibitions are absolute and carry the top fine: social scoring, exploitation of vulnerabilities, untargeted facial-image scraping, workplace and school emotion recognition, and most real-time public biometric identification. High-risk systems, listed in Annex III (employment, credit, education, essential services, law enforcement, and more), carry the heavy machinery: risk management, data governance, technical documentation, logging, human oversight, and conformity assessment. Limited-risk systems get transparency duties (see our AI Act transparency guide), and everything else is minimal risk.

Notice how many prohibited and high-risk categories are privacy problems restated: biometrics, monitoring, profiling people for consequential decisions. That is why the same system usually triggers both regimes.

Where the regimes interlock

Training data. GDPR applies to personal data in training sets regardless of what the AI Act says. The EDPB’s December 2024 opinion on AI models addresses when models trained on personal data can be treated as anonymous and how legitimate interests is assessed; the safe assumption is that scraped-data training needs a documented balancing test, minimization, and a response plan for data subject rights.

Automated decisions. GDPR Article 22 restricts solely automated decisions with legal or significant effects; Annex III makes many of the same systems high-risk. One system, two overlapping duty sets, covered in our automated decision-making guide.

Assessments. A high-risk deployer may owe a fundamental rights impact assessment (Article 27) while the same processing triggers a GDPR DPIA. The AI Act explicitly allows combining them; our combined assessment methodology shows how.

Data governance. Article 10 requires training, validation, and testing data to be relevant, representative, and managed for bias, with a specific legal gate for processing special category data to detect bias. Details in the high-risk data governance guide.

Sequencing compliance

Inventory AI systems and classify them by tier first; the classification drives everything. Kill or redesign anything touching an Article 5 prohibition before February deadlines matter to you. For high-risk systems, stand up the documentation and data governance early, since retrofitting provenance onto trained models is the hardest task in the regulation. And keep the GDPR fundamentals current, because a DPA does not need to wait for AI Act enforcement to fine unlawful processing. If your AI features run on your website, check what data they collect from visitors with a free scan.

Frequently Asked Questions

Does the AI Act replace GDPR for AI systems?

No. Article 2(7) of the AI Act preserves EU data protection law in full. An AI system that processes personal data needs a GDPR lawful basis, transparency, and rights handling, plus whatever the AI Act adds for its risk tier.

When do the AI Act obligations apply?

Staged: the regulation entered into force 1 August 2024; prohibitions and AI literacy duties applied from 2 February 2025; general-purpose AI rules from 2 August 2025; most high-risk system obligations from 2 August 2026, with some product-embedded cases running to 2027.

What AI practices are banned outright?

Article 5 prohibits, among others: social scoring by or for public authorities, exploiting vulnerabilities, subliminal manipulation causing harm, untargeted scraping of facial images for recognition databases, emotion recognition in workplaces and schools (with narrow exceptions), and most real-time remote biometric identification in public spaces.

Who counts as a provider versus a deployer?

The provider develops the system or places it on the market; the deployer uses it under its own authority. Providers carry the conformity, documentation, and quality obligations; deployers carry use-level duties like human oversight, input data control, and in some cases fundamental rights impact assessments.

Can I train AI models on personal data under GDPR?

Only with a lawful basis, usually legitimate interests with a documented balancing test, plus purpose limitation and data minimization analysis. Several DPAs have examined large-scale training on scraped data; the EDPB's 2024 opinion on AI models sets out how anonymity claims and legitimate interests are assessed.

Regulatory Crosswalk

GDPRISO/IEC 42001NIST AI RMF

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.