Skip to main content
Data Protection / GDPR

EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) is Europe's horizontal rulebook for artificial intelligence; it classifies AI systems by risk and attaches graduated obligations to providers and deployers that apply alongside the GDPR.

The AI Act – Regulation (EU) 2024/1689 – entered into force on 1 August 2024 and applies directly in every Member State. It follows a risk-based logic. Practices posing an unacceptable risk are prohibited under Article 5, including social scoring, the untargeted scraping of facial images from the internet to build facial recognition databases and, apart from narrow exceptions, emotion recognition in the workplace. High-risk systems under Article 6 in conjunction with Annex III – a category that captures many everyday business uses such as CV screening, employee evaluation, creditworthiness assessment or access to essential services – face a comprehensive compliance programme. Systems that interact with people or generate content are subject to the transparency duties of Article 50, and general-purpose AI models follow their own regime in Chapter V.

Obligations are allocated along the value chain. Providers, who develop an AI system and place it on the market under their own name, carry the heaviest load: a risk management system (Article 9), data governance and quality requirements for training, validation and testing data (Article 10), technical documentation (Article 11), automatic logging (Article 12), transparency towards deployers (Article 13), human oversight (Article 14), accuracy, robustness and cybersecurity (Article 15), plus quality management, conformity assessment and CE marking. Deployers – organisations that use a system under their own authority – must, under Article 26, operate it in line with the instructions for use, choose appropriate input data, monitor operation, retain logs and inform affected workers; public bodies and certain private deployers additionally carry out a fundamental rights impact assessment under Article 27. Article 4 obliges providers and deployers alike to ensure a sufficient level of AI literacy among their staff. Penalties under Article 99 reach up to EUR 35 million or 7 % of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3 % for breaches of the remaining obligations.

The AI Act does not displace data protection law; it sits next to it. Anyone processing personal data in or with an AI system still needs a legal basis under Article 6 GDPR, must respect purpose limitation and data minimisation, honour data subject rights and, in many cases, run a data protection impact assessment under Article 35 GDPR – Article 26(9) of the AI Act expressly allows the provider's information to be used for that assessment. Where the use results in an automated decision producing legal or similarly significant effects, Article 22 GDPR applies on top. Application dates are staggered: the prohibitions and the AI literacy duty have applied since 2 February 2025, the rules for general-purpose AI models since 2 August 2025, and the bulk of the regulation since 2 August 2026, with a later date foreseen for high-risk systems embedded as safety components in regulated products. Parts of the high-risk timeline remain politically contested and are the subject of the Commission's Digital Omnibus proposals, so organisations should track the state of the legislative process rather than rely on a single fixed date.

Legal Basis

Regulation (EU) 2024/1689 (AI Act), in particular Articles 4, 5, 6, 9–15, 26, 27, 50 and 99; supplemented by Articles 6, 22 and 35 GDPR

Practical Example

A mechanical engineering company wants to use AI-supported software in recruiting that pre-sorts and ranks incoming applications. Together with HR and IT, the data protection coordinator first settles the role question: the company buys the system in and runs it unchanged under the vendor's name, so it acts as a deployer, not a provider – although rebranding the tool or substantially modifying it could shift it into the provider role under Article 25 of the AI Act. Because CV screening falls under Annex III, she asks the vendor for the declaration of conformity, the instructions for use required by Article 13 and figures on accuracy and known bias. In parallel she documents the data protection side: the legal basis for employee data processing under Section 26 BDSG or Article 6 GDPR, a data protection impact assessment that builds on the vendor's documentation, and the assurance that no rejection is made by the system alone – a recruiter reviews and can override every pre-selection. Operating logs are retained, the works council is involved, applicants and staff are informed, and the people working with the tool are trained as required by Article 4.

FAQ

Providers develop an AI system and place it on the market under their own name or trademark; they owe the duties on risk management, data governance, documentation, conformity assessment and CE marking. Deployers use a system under their own authority and must follow the instructions for use, ensure suitable input data, monitor operation, keep logs and inform affected people. A company that rebrands a purchased system or substantially modifies it can itself become a provider under Article 25.
No. The two regimes apply in parallel. The AI Act governs the safety and trustworthiness of the system as a product, while the GDPR governs whether the underlying processing of personal data is lawful. Anyone using AI on personal data still needs a legal basis, must serve data subject rights and, depending on the risk, must carry out a data protection impact assessment under Article 35 GDPR.
The regulation has been in force since 1 August 2024 and becomes applicable in stages: prohibitions and the AI literacy duty since 2 February 2025, obligations for general-purpose AI models since 2 August 2025, and most of the remaining provisions since 2 August 2026. A later date is foreseen for high-risk systems embedded in regulated products. Parts of the schedule are under discussion in the Digital Omnibus package, so the current status of the legislative process should be checked.

How preeco supports you

Learn how our software supports you with this topic.

Learn more