Compare · 04
As of September 2026
Comply · EU AI Act Readiness · AI Governance
One system,
two rulebooks.
Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744. Rules for AI systems, by risk.
Regulation (EU) 2016/679. Rules for processing personal data, whatever the technology. Applies since 25 May 2018.
01 · Side by side
One asks about AI.
One about data.
They apply side by side: the AI Act says it does not affect the GDPR (Art. 2(7)). Most AI projects with personal data answer to both.
| Dimension | AI Act | GDPR |
|---|---|---|
| Regulates | AI systems and general-purpose AI models: placing on the market, putting into service, use | Processing of personal data, by any means |
| Logic | Product safety: requirements before the market, surveillance after, duties by risk class | Fundamental right: principles, legal basis, rights of the people whose data it is |
| Roles | Provider and deployer (Art. 3(3), 3(4)), plus importer, distributor, authorised representative | Controller and processor (Art. 4(7), 4(8)), joint controllers (Art. 26) |
| Impact assessment | Fundamental rights impact assessment for some deployers of high-risk systems (Art. 27) | Data protection impact assessment where processing is likely to result in a high risk (Art. 35) |
| Transparency | Tell people they are dealing with an AI, mark synthetic content, disclose deepfakes (Art. 50); inform people subject to high-risk systems (Art. 26(11)) | Inform people about the processing (Art. 13, 14), including meaningful information about the logic of automated decisions |
| Automated decisions | Human oversight for high-risk systems (Art. 14, 26(2)); a right to an explanation for decisions based on Annex III systems (Art. 86) | A right not to be subject to decisions based solely on automated processing with legal or similarly significant effects (Art. 22) |
| Authorities | Market surveillance authorities. In Germany the Bundesnetzagentur, under the KI-MIG since 29 July 2026, with sector authorities such as BaFin. The EU AI Office for general-purpose models. | Data protection supervisory authorities. In Germany, for most companies, the authority of their Land. |
| Fines | Up to €35 million or 7 % of worldwide annual turnover for prohibited practices; up to €15 million or 3 % for most other duties (Art. 99) | Up to €20 million or 4 % of worldwide annual turnover; up to €10 million or 2 % for some duties (Art. 83) |
| Dates | In stages since 2 February 2025. High-risk from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), after the Digital Omnibus | Applies since 25 May 2018. Proposed changes in a separate Digital Omnibus were still being negotiated in September 2026. |
02 · Situations
Which one bites,
in six situations.
It is not a choice. The question is which rules a given system triggers. Our reading of six cases we see often.
- 01Screening job applicants with AIAI ActGDPR
High-risk under Annex III (employment) from 2 December 2027. Personal data throughout: a DPIA is close to certain, and Art. 22 applies if no human really decides.
- 02A customer service chatbotAI ActGDPR
Art. 50: tell people they are talking to an AI, since 2 August 2026. The chats are personal data: legal basis, retention period, privacy notice.
- 03Predictive maintenance on machine sensorsAI Actnot GDPR
As long as no operator can be identified, the GDPR stays out. Under the AI Act most likely minimal risk, unless it is a safety component of a product under Annex I.
- 04A rules-based credit check, no machine learningnot AI ActGDPR
Probably not an AI system in the Act’s sense: fixed rules written by people are excluded. Still Art. 22 GDPR if the result decides alone. The CJEU held that a credit score can itself be such a decision (SCHUFA, C-634/21).
- 05Training a model on customer emailsAI ActGDPR
GDPR first: a legal basis for training, purpose limitation, information for the people in the emails. If the result is high-risk, the AI Act adds data governance duties for you as provider (Art. 10).
- 06Generating marketing imagesAI Actnot GDPR
The tool’s provider marks the output as synthetic (Art. 50(2); tools already on the market before 2 August 2026 have until 2 December 2026). If an image is a deepfake of real people, you disclose it (Art. 50(4)). The GDPR joins only if real, identifiable people appear.
Not legal advice Our reading as of September 2026, for orientation. The details of your system decide.
03 · Decide
Which assessments
you need.
Up to five questions about one system. The result lists what applies, what to check, and what you can skip.
01Does the system process personal data?
Names, emails, IDs, voices, images of people: anything that can be linked to a person. Chat logs usually count.
02Is it used in a high-risk area of Annex III?
For example recruiting and managing workers, credit scoring of people, education, access to public services and benefits.
03What is your role?
04Are you a public body or a private entity providing public services, or does the system assess creditworthiness or price life or health insurance?
Art. 27(1) AI Act. Only asked because you use a high-risk system.
05Does it decide about people without a human who really reviews?
Decisions with legal or similarly significant effects: a contract, a job, a loan, a benefit.
Not legal advice A first orientation from your answers, as of September 2026. Not legal advice: for a binding view, have a lawyer check your case.
04 · Overlap
Build the
evidence once.
Where both ask for the same kind of work, one piece of evidence can serve both. Where they pull in different directions, decide it once, in writing.
“… this Regulation shall not affect Regulation (EU) 2016/679 …”
- Impact on peopleAI ActFundamental rights impact assessment (Art. 27); may reference the DPIA (Art. 27(4))GDPRData protection impact assessment (Art. 35)strong
- The provider’s information feeds the DPIAAI ActInstructions for use (Art. 13), which deployers use for their DPIA (Art. 26(9))GDPRDPIA content: description, necessity, risks, measures (Art. 35(7))strong
- SecurityAI ActAccuracy, robustness and cybersecurity (Art. 15)GDPRSecurity of processing (Art. 32)strong
- A human in the loopAI ActHuman oversight by design and in use (Art. 14, 26(2))GDPRHuman intervention on request, for automated decisions (Art. 22(3))partial
- Explaining decisionsAI ActExplanation of the AI system’s role in a decision (Art. 86)GDPRMeaningful information about the logic involved (Art. 13(2)(f), 14(2)(g), 15(1)(h))partial
- Telling peopleAI ActDisclosure of AI and synthetic content (Art. 50); information for people subject to high-risk systems (Art. 26(11))GDPRPrivacy information (Art. 13, 14)partial
- Data quality and biasAI ActData governance (Art. 10); special categories for bias detection only under strict conditions (Art. 4a, new with the Digital Omnibus)GDPRAccuracy and data minimisation (Art. 5); special categories only under Art. 9tension
- Keeping recordsAI ActDeployers keep high-risk logs for at least six months (Art. 26(6))GDPRStorage limitation (Art. 5(1)(e)); logs about people are personal data tootension
Strong: one work product usually serves both. Partial: related, but each asks for its own detail. Tension: the two pull in different directions; document how you balance them. High-risk articles apply only to high-risk systems.
05 · Questions
Asked by
every DPO.
If we comply with the GDPR, are we done with the AI Act?
No. The Act adds duties that have nothing to do with personal data: risk classes, transparency for chatbots and synthetic content, technical documentation, AI literacy. And a system without any personal data can still be high-risk.
Can a FRIA replace our DPIA?
No, and the other way round neither. The Act lets you reference the parts of a DPIA that already cover the same ground (Art. 27(4)). One document with two clearly marked parts is a practical way to do both.
Is a deployer the same as a controller?
Often the same organisation, never the same concept. A deployer uses an AI system under its authority; a controller decides on the purposes and means of processing. A company using a vendor’s AI tool is typically both, while the vendor is provider and, for the company’s data, often processor.
Does Art. 22 GDPR ban AI decisions?
No. It covers decisions based solely on automated processing with legal or similarly significant effects, and allows them with a contract, a law or explicit consent, plus safeguards. In SCHUFA (C-634/21, December 2023) the CJEU held that a score can itself be such a decision if it plays a determining role.
Who supervises what in Germany?
For the AI Act, the Bundesnetzagentur as the central market surveillance authority under the KI-MIG, in force since 29 July 2026, with sector authorities such as BaFin keeping their areas. For the GDPR, the data protection authorities; for most companies, the one of their Land.
Did the Digital Omnibus change the GDPR?
Not yet. The AI part, Regulation (EU) 2026/1744, has applied since 27 July 2026 and moved the high-risk dates. The separate proposal that would amend the GDPR was still being negotiated in the Council in September 2026. This page reflects the GDPR as in force.
Two rulebooks
One
inventory.
Both start with the same list: which systems, which data, which people. Build it once and classify from there.