GDPR vs the EU AI Act: Why Compliance With One Doesn't Mean Compliance With the Other 

If your business has already put the work into becoming GDPR compliant, it is natural to assume that using AI responsibly is simply an extension of that work. Many businesses we speak to are surprised to learn this isn't quite right. GDPR and the EU AI Act are two separate pieces of legislation with different aims, and meeting the requirements of one does not automatically satisfy the other. 

This guide walks through what each law actually does, where they overlap, and what that means for your business in practice.

What Is the Difference Between GDPR and the EU AI Act?

GDPR exists to protect personal data, regardless of the technology used to process it. The EU AI Act, by contrast, regulates AI systems themselves, based on the level of risk they pose to people's safety, rights and wellbeing, sorting them into four categories: unacceptable risk, which is banned outright, high risk, which faces strict requirements, limited or specific transparency risk, and minimal risk, which covers most everyday AI tools and carries no specific obligation.

An AI system does not need to process personal data at all to fall within scope of the AI Act. A quality control system on a manufacturing line, for example, might never touch personal data, yet could still be classed as high risk under the Act depending on its use case. This means a business can be fully GDPR compliant and still fall short of its AI Act obligations, and vice versa. Treating the two as interchangeable is one of the most common mistakes we see businesses make when they start using AI tools.

Does the EU AI Act Replace GDPR?

No, the EU AI Act does not replace GDPR. The CNIL, France's data protection regulator, has been explicit on this point in its own published guidance: the AI Act does not replace GDPR, it complements it. A provider of an AI system is generally treated as a data controller under GDPR during development, and a deployer or user of that system is generally treated as a controller during actual use, wherever personal data is involved. The AI Act sits alongside GDPR rather than on top of it.

How Do I Know Which Law Applies to My Business?

There are effectively four scenarios worth checking your business against. Only the AI Act applies if you use a high-risk AI system that involves no personal data at all, such as an AI system managing industrial equipment. Only GDPR applies if you process personal data through a tool that is not itself regulated by the AI Act, such as a system built purely for internal scientific research. Both apply where a high-risk AI system also processes personal data, which is common for tools like automated CV screening. Neither applies where an AI system is both minimal risk and involves no personal data, such as certain AI features in a video game.

Where Do the Two Genuinely Overlap?

In practice, a large proportion of AI systems fall into that "both apply" category, which is where GDPR and the AI Act genuinely intersect. Take a customer service chatbot. Under GDPR, you need a lawful basis for processing any personal data the chatbot collects, and you may need to carry out a Data Protection Impact Assessment if the processing is high risk. Under the AI Act, you separately need to meet transparency obligations, including making clear to the customer that they are interacting with an AI system rather than a person.

These are not the same requirement but they sit alongside each other, and both need to be addressed. A DPIA that satisfies your GDPR obligations will not, on its own, demonstrate compliance with the AI Act's risk classification and conformity requirements for a high-risk system.

Do I Need a DPIA, a Fundamental Rights Impact Assessment, or Both?

If your AI system is high risk under the AI Act and also processes personal data, you may need both. A DPIA, required under GDPR, focuses specifically on risks to individuals arising from how their personal data is processed. A Fundamental Rights Impact Assessment, required under the AI Act for certain deployers of high-risk systems, looks more broadly at the AI system's impact on people's fundamental rights generally such as privacy and access to justice, not just their data. The two are designed to work together, and regulators have indicated that in some cases these assessments can be combined into a single document rather than duplicated, so this need not mean double the paperwork if you approach it sensibly from the start.

Who Actually Enforces Each Law?

GDPR is enforced by each country's data protection authority, which in the UK is the ICO and in France it is CNIL, for example. The AI Act has a more layered structure, involving national market surveillance authorities, the EU AI Office for general-purpose AI models, and the European AI Board coordinating consistency across member states. Where an AI system also processes personal data, data protection authorities frequently play a role in AI Act enforcement too, since they are named in the Act as a market surveillance authority for many high-risk systems. In practice, this means the same regulator may end up asking you about both your data protection compliance and your AI Act compliance, so it is worth being able to answer both sets of questions separately.

Why Are the Rules Still Settling?

The EU AI Act itself has recently changed. The Digital Omnibus on AI entered into force on 27 July 2026, amending several of the Act's timelines and administrative requirements, including when obligations for high-risk AI systems will start to apply. The European Commission and the European Data Protection Board have both acknowledged that further joint guidance on how GDPR and the AI Act interact is still being developed.

If I Am Already GDPR Compliant, Does That Help With the AI Act?

Being GDPR compliant does not automatically satisfy your AI Act obligations, but it puts you in a considerably stronger starting position. Your existing DPIA documentation, lawful basis assessments and transparency notices can often be built upon rather than started from scratch, since the AI Act's own documentation and transparency requirements deliberately echo the GDPR's approach in several places. The AI Act and the GDPR are separate legal frameworks with different requirements. While there is some overlap, for example, both may require organisations to assess and manage risk, complying with one does not automatically mean complying with the other. Each creates its own obligations, which need to be considered separately.

What Should My Business Do Next?

The most reliable way to approach this is to treat GDPR and AI Act compliance as related but distinct exercises that need to run in parallel. Start by mapping where AI is actually used across your business, not just where you assume it is. For each use case, ask two separate questions: does this process personal data, and what level of risk does this AI system pose under the AI Act's risk categories. The ICO's guidance on AI and data protection is a useful starting point for the GDPR side of this, the European Commission's AI Act pages set out the current risk-based framework and implementation timeline, and the European Commission's AI Act Service Desk FAQ is regularly updated with answers based on real questions from businesses.

If your business is developing or deploying AI systems that touch EU customers or UK personal data, it is worth treating this as a compliance project in its own right rather than folding it into your existing data protection work. Where your situation involves higher-risk AI use, cross-border data flows, or systems that make decisions about individuals, taking specific legal advice will help you understand exactly which obligations apply to you and when. Getting ahead of this now, while the detailed guidance is still developing, puts you in a far stronger position than trying to catch up later.

How Can Gerrish Legal Help?

Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property. 

We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements. 

We are here to help you, get in contact with us today for more information.

Next
Next

CNIL Warns Businesses About the Privacy Risks of AI Smart Glasses