EU AI Act vs GDPR
Last reviewed: · By Victor Humenhuk (AIGP certified)
The GDPR regulates the processing of personal data, whoever does it and whatever technology is involved. The EU AI Act (Regulation (EU) 2024/1689) regulates AI systems and general-purpose AI models placed on the Union market or used in the Union, whether or not personal data is involved. The GDPR attaches duties to controllers and processors and gives individuals directly enforceable rights, while the AI Act attaches duties to providers, deployers, importers and distributors and works largely through product-safety style requirements policed by market surveillance authorities. They apply cumulatively, because the AI Act expressly leaves Union data protection law untouched, so a high-risk recruitment tool typically needs a lawful basis and a DPIA under the GDPR and conformity assessment, logging and human oversight under the AI Act.
EU AI Act vs GDPR at a glance
| GDPR | EU AI Act | |
|---|---|---|
| Instrument | Regulation (EU) 2016/679, applicable since May 2018 | Regulation (EU) 2024/1689, in force since August 2024, phased application |
| Object of regulation | Processing of personal data | AI systems and general-purpose AI models on the Union market |
| What triggers it | Personal data is processed | The system's risk category and your role |
| Roles | Controller, joint controller, processor | Provider, deployer, importer, distributor, authorised representative |
| Legal character | Fundamental rights law | Product safety and market access law with a fundamental rights purpose |
| Individual rights | Full suite: access, erasure, objection, Article 22 automated decisions | Narrow: complaint to a market surveillance authority (Article 85) and explanation of individual decision-making (Article 86) |
| Enforcer | National supervisory authorities, coordinated by the EDPB | National market surveillance authorities, and the AI Office for general-purpose AI models |
| Top fine | 20 million euro or 4% of total worldwide annual turnover | 35 million euro or 7% of total worldwide annual turnover |
What does each law actually cover?
The GDPR is technology-agnostic. It bites whenever personal data is processed, so it governs the collection and curation of training data, the lawful basis for training, special category data, transparency to data subjects, storage limitation, security, international transfers, and solely automated decisions with legal or similarly significant effects under Article 22. It says nothing about how accurate your model must be or whether it can go on sale.
The AI Act is agnostic about personal data. It classifies AI by use case: prohibited practices (Article 5), high-risk systems (Article 6 with Annexes I and III), systems subject to transparency obligations (Article 50), general-purpose AI models (Articles 51 to 56), and everything else, which carries no obligations beyond voluntary codes of conduct. Its obligations are about market entry and safe operation: risk management, data governance, documentation, logging, human oversight, accuracy and robustness, conformity assessment and post-market monitoring.
So a fraud model that never touches personal data still falls under the AI Act if it is a high-risk use case, and a spreadsheet-based scoring process that is not an AI system still falls under the GDPR if it processes personal data.
Do they overlap, and which one wins?
Neither wins. Article 2(7) of the AI Act provides that Union law on the protection of personal data continues to apply to personal data processed in connection with the Regulation, and that the AI Act does not affect the GDPR, subject only to the narrow carve-outs it names. In practice the two interlock at several points:
- Assessments. A deployer may need both a GDPR DPIA and an AI Act fundamental rights impact assessment. Article 27(4) says the FRIA complements the DPIA where the obligations are already met, rather than duplicating it, and Article 26(9) tells deployers to use the provider's Article 13 information when carrying out their DPIA.
- Bias testing. Article 10(5) of the AI Act permits processing of special categories of personal data where strictly necessary to detect and correct bias in high-risk systems, subject to listed safeguards. It is a narrow carve-out that has to be read alongside GDPR Article 9.
- Automated decisions. Human oversight under AI Act Article 14 is a design and operational requirement on the system; GDPR Article 22 is a right held by the individual. Satisfying one does not satisfy the other.
- Explanations. AI Act Article 86 gives affected persons a right to clear and meaningful explanations of the role of the system in a decision, while GDPR Articles 13 to 15 require meaningful information about the logic involved in Article 22 decisions.
How do the penalties compare?
| Tier | GDPR | EU AI Act |
|---|---|---|
| Highest | 20 million euro or 4% of total worldwide annual turnover for breaches of the principles, legal basis, data subject rights and transfer rules (Article 83(5)) | 35 million euro or 7% for the prohibited practices in Article 5 (Article 99(3)) |
| Middle | 10 million euro or 2% for most other controller and processor obligations (Article 83(4)) | 15 million euro or 3% for breach of provider, deployer, importer, distributor, notified body or Article 50 transparency obligations (Article 99(4)) |
| Lowest | Not applicable | 7.5 million euro or 1% for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities (Article 99(5)) |
| Smaller undertakings | Whichever of the amount or percentage is higher | For SMEs, including start-ups, whichever is lower (Article 99(6)) |
Fines can stack: the same recruitment tool can attract a GDPR fine from a supervisory authority and an AI Act fine from a market surveillance authority for different failings.
When does each obligation start to apply?
The GDPR has applied since 25 May 2018. The AI Act entered into force on 1 August 2024 and applies in stages under Article 113:
- 2 February 2025 for Chapters I and II: definitions, AI literacy (Article 4) and the prohibited practices in Article 5.
- 2 August 2025 for the general-purpose AI model obligations, notifying authorities and notified bodies, governance, confidentiality and most penalty provisions.
- 2 August 2026 for general application, including the Annex III high-risk systems and the Article 50 transparency duties.
- 2 August 2027 for Article 6(1) high-risk systems embedded in products covered by the Annex I harmonisation legislation, and as the compliance deadline for general-purpose AI models already placed on the market before 2 August 2025.
In November 2025 the European Commission proposed a Digital Omnibus package that would, among other things, adjust some of these high-risk timelines and tie them to the availability of harmonised standards. The dates above are the position set out in the Regulation as adopted; check the current status of that proposal before relying on them. See the Digital Omnibus topic for the detail.
Related study notes
- AI Regulation: The Lay of the Land
- The GDPR and AI
- Article 22 and Automated Decision-Making
- The risk classification framework
- Obligations on Data Controllers
Frequently asked questions
Does the EU AI Act replace the GDPR?
No. Article 2(7) is explicit that the AI Act does not affect Union data protection law. If your AI system processes personal data, every GDPR obligation continues to apply alongside the AI Act requirements.
Does the AI Act apply if no personal data is involved?
Yes. The AI Act is triggered by the system and its use case, not by personal data. An AI system used as a safety component in the supply of water or electricity can be high-risk under Annex III without processing any personal data at all.
Do I need both a DPIA and a fundamental rights impact assessment?
Potentially. A DPIA is required under GDPR Article 35 where processing is likely to result in a high risk to individuals. A FRIA is required under AI Act Article 27 only of certain deployers of certain high-risk systems. Where both apply, Article 27(4) allows the FRIA to complement the DPIA rather than repeat it.
Which law is stricter?
They are strict about different things. The AI Act has the higher headline fine, 7% against 4%, and controls whether a system may be placed on the market at all. The GDPR has broader reach, applies to far more organisations, and gives individuals directly enforceable rights and a route to compensation.
Test yourself
Try the free AIGP practice questions, or read the full AIGP study guide - free.