This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
It is normal to find the two EU frameworks difficult to separate because one AI use can engage both at once. This reference distinguishes their tests, roles and application dates so each question can be traced to the relevant primary source.
In short: The AI Act regulates AI systems, models and specified uses according to the operator's role and the system's risk. The GDPR regulates the processing of personal data. A business can be an AI Act deployer and a GDPR controller at the same time, and neither label decides the other.
_Status checked: 3 September 2026. The timeline reflects the AI Act as amended by Regulation (EU) 2026/1744._
The AI Act and GDPR answer different questions
The quickest way to separate the frameworks is to ask what each one regulates. The AI Act starts with an AI system or general-purpose AI model, while the GDPR starts with the processing of information relating to an identified or identifiable person.
| Question | AI Act | GDPR |
|---|---|---|
| What triggers the framework? | Placing an AI system or general-purpose AI model on the EU market, using an AI system in the EU, or specified third-country connections to the EU | Processing personal data within the GDPR's territorial scope |
| What determines the main role? | Whether the organisation is a provider, deployer, importer, distributor, product manufacturer or another defined operator | Whether the organisation is a controller, joint controller or processor |
| What changes the obligations? | The system's intended purpose, risk classification, operator role and application date | The purpose and means of processing, the data involved, the effects on people and the relationship between the parties |
| Can both apply? | Yes | Yes |
Article 2 of the current consolidated AI Act covers providers placing AI systems or general-purpose AI models on the EU market regardless of where they are established. It also covers providers and deployers in a third country where an AI system's output is used in the Union.
Article 3 of the GDPR uses a different territorial test. It covers processing in the context of an EU establishment and certain processing by a non-EU organisation related to offering goods or services to people in the Union or monitoring their behaviour there.
Selling into the EU does not, by itself, produce one universal answer under both laws. The AI Act asks what AI is being supplied or used and where its output is used. The GDPR asks whether personal data is processed and whether Article 3 brings that processing within scope.
Provider or deployer depends on what the business does with the system
A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts the system into service under its own name or trademark. A deployer uses an AI system under its authority outside a personal, non-professional activity. These definitions appear in Article 3 of the consolidated AI Act.
| Business activity | Likely AI Act role on the stated facts | What can change the answer? |
|---|---|---|
| Uses an external vendor's AI assistant for customer support | Deployer | Rebranding, substantial modification or changing the intended purpose |
| Develops an AI product and sells it under its own brand | Provider | Other roles may also arise through distribution or product rules |
| Commissions another company to build an AI system sold under the commissioning business's brand | Provider | Contract wording does not override the statutory definition |
| Resells an AI system made by another provider | Distributor or importer may be relevant | Location in the supply chain and whether the system enters the EU market from a third country |
| Adds its name to, substantially modifies or repurposes a high-risk system | May become the provider of that high-risk system | The conditions in Article 25 and the effect of the change |
Article 25 says a distributor, importer, deployer or other third party is treated as the provider of a high-risk system when it places its name or trademark on the system, substantially modifies it while it remains high-risk, or changes its intended purpose so that it becomes high-risk. The exact conditions are in Article 25 of the AI Act.
Consider a non-EU retailer that licences a third-party chatbot for an EU-facing shop. On those limited facts, the chatbot vendor is ordinarily the provider and the retailer is ordinarily the deployer. If conversations contain customer information, the retailer may separately be a GDPR controller and the vendor may be a processor, but that depends on who determines the purposes and means of each processing activity under Article 4 of the GDPR.
That example is a classification aid, not a conclusion for every hosted chatbot. Product design, branding, contracts, data reuse and actual operating control can change the roles.
The four risk levels are a map, not four interchangeable rulebooks
The European Commission describes the AI Act through four risk levels: unacceptable risk, high risk, transparency risk, and minimal or no risk. The operative provisions sit in different parts of the Act, so the pyramid is a useful map rather than a substitute for checking the relevant article and annex. The Commission's current explanation is on its AI Act overview.
| Level | What the official sources say | Typical reference point |
|---|---|---|
| Unacceptable risk | Specified practices are prohibited | Article 5 |
| High risk | Listed systems face requirements assigned to providers and other operators | Article 6, Annex I and Annex III |
| Transparency risk | Certain systems or content require disclosures, marking or labelling | Article 50 |
| Minimal or no risk | No risk-category-specific regime applies to most ordinary systems | Voluntary codes may still be relevant |
High-risk classification follows two main routes. Article 6(1) covers AI that is a product, or safety component of a product, governed by listed EU product legislation and requiring third-party conformity assessment. Article 6(2) points to Annex III uses, including specified uses in employment, education, essential services, biometrics, critical infrastructure, law enforcement, migration and justice. The formal tests and Annex III list are in the AI Act text.
An Annex III listing is not always the end of the classification exercise. Article 6(3) provides conditions under which a listed system may not be high-risk because it does not pose a significant risk and does not materially influence decision-making. Systems that profile natural persons remain high-risk under that provision.
Transparency rules are separate from high-risk classification. Article 50 addresses matters such as informing people when they interact directly with certain AI systems, marking synthetic outputs in a machine-readable format, and labelling specified deepfakes or public-interest text. The Commission states that these transparency obligations have applied since 2 August 2026 and has published Article 50 guidance.
Minimal-risk classification does not switch off every other rule. Article 4's AI literacy provision can still apply to providers and deployers, Article 50 may apply to a relevant system, and the GDPR remains relevant whenever personal data is processed.
General-purpose AI, or GPAI, is another layer rather than a fifth risk tier. Chapter V assigns obligations to providers of general-purpose AI models, with additional rules for models classified as presenting systemic risk. A business merely using a model through a hosted tool is not automatically the provider of that model.
The dates changed, so the amended timeline matters
The original AI Act timeline is no longer sufficient for high-risk systems. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the main high-risk dates.
| Date | Status recorded by the current official sources |
|---|---|
| 1 August 2024 | The AI Act entered into force |
| 2 February 2025 | The first prohibited-practice provisions and Article 4 on AI literacy began applying |
| 2 August 2025 | Governance provisions and obligations for providers of GPAI models began applying |
| 2 August 2026 | The Act's general application date, Commission and national enforcement powers, and Article 50 transparency rules took effect |
| 2 December 2026 | Two new Article 5 prohibitions take effect: the first concerning specified non-consensual intimate material, the second concerning material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU; a limited transition also ends for Article 50 marking of certain systems placed on the market before 2 August 2026 |
| 2 August 2027 | Providers of GPAI models placed on the market before 2 August 2025 reach their compliance date |
| 2 December 2027 | Requirements for Annex III high-risk systems begin applying |
| 2 August 2028 | Requirements for high-risk systems covered through Annex I product legislation begin applying |
The Commission records the amended dates in its AI Act implementation overview, enforcement framework and GPAI provider guidance.
Article 4 currently says providers and deployers are to take measures supporting the development of AI literacy among relevant staff and other people operating systems on their behalf. The 2026 amendment adds that this does not require them to guarantee a specific level for any individual. The amended wording appears in Regulation (EU) 2026/1744.
GDPR follows the personal data through the AI workflow
The GDPR can apply during data collection, prompt entry, model development, retrieval, output generation, logging and human review. The fact that software is labelled AI does not create a new GDPR lawful basis or remove the existing principles in Articles 5 and 6 of the GDPR.
Controller and processor are not synonyms for provider and deployer
A controller determines the purposes and means of processing personal data. A processor handles personal data on a controller's behalf. Article 28 says processing by a processor is governed by a binding contract or other legal act containing specified terms, but an AI vendor's contractual label is not conclusive if its actual activities indicate a different role. See GDPR Articles 4 and 28.
This produces combinations that initially look odd but are legally coherent. An organisation can be a deployer under the AI Act and controller under the GDPR. An AI provider can be a processor for one activity, a controller for another, or a joint controller where the facts support that result.
Consent and legitimate interests are alternatives only where their conditions fit
Article 6 lists several possible lawful bases, including consent, contractual necessity, legal obligation and legitimate interests. It does not make consent the automatic answer for AI, and legitimate interests is not a general AI exemption.
In Opinion 28/2024, the European Data Protection Board addresses when an AI model may be considered anonymous, when legitimate interests may support development or deployment, and how unlawful processing during development may affect later deployment. The EDPB describes these assessments as case-specific and sets out a three-part legitimate-interest analysis covering the interest, necessity and balancing of rights.
Automated decisions are narrower than all AI-assisted decisions
Article 22 addresses decisions based solely on automated processing that produce legal effects or similarly significant effects. Articles 13 and 14 contain information provisions concerning relevant automated decision-making, including meaningful information about the logic involved and the significance and envisaged consequences. The EDPB's adopted automated decision-making and profiling guidelines explain the Board's position on that boundary.
Human involvement therefore matters to the Article 22 analysis, but a nominal approval click does not answer the question by itself. The actual process, authority and influence of the reviewer remain factual matters.
A DPIA is triggered by processing risk, not by the AI label alone
Article 35 says a data protection impact assessment is carried out where processing is likely to result in a high risk to people's rights and freedoms. Its listed examples include systematic and extensive evaluation based on automated processing that supports legal or similarly significant decisions, large-scale processing of specified sensitive data, and systematic large-scale monitoring of publicly accessible areas. The full test appears in GDPR Article 35.
An AI Act high-risk classification and a GDPR DPIA assessment are related only through their facts. One does not automatically prove the other because the instruments use different tests.
Sending EU personal data abroad remains a GDPR question
Chapter V of the GDPR governs transfers of personal data to third countries or international organisations. The Commission describes adequacy decisions, standard contractual clauses, binding corporate rules and limited derogations among the available mechanisms on its international transfer rules page.
Using a US-hosted AI service does not make the AI Act the transfer mechanism. The AI Act classification and the GDPR transfer analysis remain separate, even when they concern the same vendor relationship.
AI Act and GDPR enforcement also remain separate
National market-surveillance authorities carry much of the AI Act enforcement role, while the European Commission's AI Office has central responsibilities for GPAI models and certain AI systems. The Commission summarises the allocation in its AI Act enforcement framework. National data-protection supervisory authorities and courts enforce the GDPR within its own institutional structure.
Article 99 of the amended AI Act sets maximum administrative fine bands of EUR 35 million or 7 per cent of worldwide annual turnover for prohibited practices, EUR 15 million or 3 per cent for listed other breaches, and EUR 7.5 million or 1 per cent for specified incorrect, incomplete or misleading information. For SMEs, the lower of the fixed amount and percentage applies. The current wording is in the consolidated AI Act.
The GDPR has its own two principal maximum bands under Article 83, reaching EUR 10 million or 2 per cent for one group of infringements and EUR 20 million or 4 per cent for another, with the higher amount used for an undertaking. These are statutory ceilings, not predictions of a penalty in any particular case. See GDPR Article 83.
SME support does not create a general exemption
Article 62 of the AI Act records measures aimed particularly at SMEs and start-ups. These include priority access to regulatory sandboxes for eligible SMEs with an EU registered office or branch, tailored awareness and training activity, communication channels, participation in standardisation and proportionate conformity-assessment fees. The current provisions are in Article 62 of the consolidated Act.
Those measures support implementation but do not remove the need to classify a system and operator. The SME-specific penalty ceiling also changes the maximum calculation rather than creating immunity.
Where the EU sources stop short of a business-specific answer
The official texts provide definitions and classification tests, but they do not classify every commercial arrangement. Provider status can turn on branding, commissioning, intended purpose and modification. GDPR roles can turn on actual influence over the purposes and means of processing, not just a vendor agreement's heading.
Several implementation details also remain dynamic. High-risk requirements are not yet generally applicable, standards and guidance continue to develop, and the Commission expressly describes parts of its guidance as interpretive rather than legally binding. A definitive classification for a disputed use may require the relevant national authority or appropriately qualified EU counsel.
Product liability is a separate boundary. Directive (EU) 2024/2853 includes software in its definition of a product and applies to products placed on the market or put into service after 9 December 2026. It does not replace the AI Act or GDPR tests discussed here. See the Product Liability Directive.
Questions that identify the relevant EU framework and role
These are classification questions for a business, vendor or adviser to answer, not a checklist that certifies compliance:
- Is an AI system or GPAI model being placed on the EU market, put into service there, or producing output used in the Union?
- Who developed or commissioned the system, and whose name or trademark appears on it?
- Is the organisation using the system under its own authority, or supplying it to others?
- Has anyone changed the system's intended purpose or substantially modified it?
- Does Article 6 and Annex I or III identify the use as high-risk, subject to any Article 6(3) exclusion?
- Does Article 50 apply a transparency obligation even if the system is not high-risk?
- Does the workflow process personal data, and which party determines its purposes and means?
- Is a solely automated decision producing a legal or similarly significant effect?
- Does personal data leave the European Economic Area, and what transfer mechanism is relied upon?
- Which application date governs the specific provision being examined?
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: our AI governance by region.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Free tools: AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice | AI Policy Generator to generate a customised AI policy for your business.
Does the AI Act apply to a company that is not established in the EU?
Yes, in some circumstances. Article 2 covers non-EU providers placing AI systems or GPAI models on the EU market and non-EU providers or deployers where an AI system's output is used in the Union. The particular product, use and supply chain determine whether that scope provision is engaged.
Is a business using a third-party AI tool a provider or a deployer?
It is ordinarily a deployer when it simply uses the vendor's system under its authority. It may become a provider of a high-risk system in the circumstances listed in Article 25, including specified rebranding, substantial modification or repurposing.
Does the AI Act replace the GDPR for AI systems?
No. Article 2(7) of the AI Act preserves EU personal-data and privacy law, subject to specified provisions in the Act. The same workflow can therefore be governed by both instruments.
Does GDPR consent always apply when an AI system uses personal data?
No. Article 6 lists multiple possible lawful bases, each with its own conditions, and special-category data raises additional Article 9 questions. EDPB Opinion 28/2024 says legitimate interests in AI-model development or deployment require a case-specific necessity and balancing assessment.
Are all high-risk AI Act obligations already in force?
No. Following the 2026 amendment, the main requirements for Annex III high-risk systems apply from 2 December 2027, while the relevant Annex I product route applies from 2 August 2028. Earlier provisions, including Article 4, GPAI rules and Article 50 transparency rules, have already reached their respective application dates.
Does every customer-service chatbot need an AI disclosure?
Article 50 generally addresses AI systems intended to interact directly with natural persons, unless the interaction with AI is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. The provision also contains specific exceptions, so the system and context remain relevant.
Methodology and source status
This reference was checked on 3 September 2026 against the consolidated AI Act dated 27 July 2026, the Official Journal text of Regulation (EU) 2026/1744, the GDPR, the Product Liability Directive, current European Commission implementation pages, and published EDPB guidance and Opinion 28/2024. It reports documentary research only and does not assess any organisation's legal position.
Next practical step: Use this reference to identify the relevant framework, then move to Need to Know AI's implementation coverage for AI registers, vendor review questions, staff policy and human-review workflow guidance.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Use the free AI register template to record the AI systems, roles and deployment contexts this EU reference applies to.
Use the free AI register template