COMPLIPATHDOC complipath.io/guides/eu-ai-act-vs-gdprRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Comparisons ·By Yobel Tzegai ·Updated 23 August 2026

EU AI Act vs GDPR: what's actually different?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

The EU AI Act and the GDPR are two different laws, and one company can be under both at the same time. They answer different questions. GDPR (Regulation (EU) 2016/679) governs the processing of personal data, whatever technology does it. The AI Act is product regulation for AI systems, tiered by risk and attached to supply-chain roles — and Article 2(7), as replaced in 2026, says GDPR is unaffected.

Quick answer

Does the AI Act replace GDPR for AI systems?

No. The AI Act says so itself. Article 2(7), as replaced by Regulation (EU) 2026/1744, confirms that Union data-protection law applies to personal data processed under the Act, then states: "Without prejudice to Articles 4a and 59 of this Regulation, this Regulation shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680."

Every GDPR duty you had, you still have. What moved is the first of the two named carve-outs. It used to read "Article 10(5) and Article 59"; Article 10(5) has been deleted, and the paragraph now points at the whole of Article 4a — its paragraph 1, which carries the old regime, and its paragraph 2, which has no predecessor. The carve-out is wider than it was, not narrower. Article 59, on sandbox processing of personal data, is unamended. Everything else stacks.

What triggers each regulation?

GDPR triggers on data: the processing of personal data, regardless of the technology involved. (GDPR-side statement — see the sources note.)

The AI Act triggers on the system. Article 3, point (1) defines an AI system as "a machine-based system that is designed to operate with varying levels of autonomy" and that "infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments". Personal data is irrelevant to the trigger — a system optimising industrial energy use is in scope with none.

Architecture differs too: the AI Act sorts systems into tiers first — prohibited, high-risk under Article 6(1) or Article 6(2), transparency-only, or none of these — and the tier determines whether you face the full Chapter III machinery or almost nothing — which tier your system lands in is the first question, not a refinement.

Who is bound by each?

GDPR allocates duties to controllers and to processors acting on their behalf. (GDPR-side statement — see the sources note.)

The AI Act instead follows a product through a supply chain. Article 2(1) applies the Regulation to providers placing AI systems on the market, deployers using them, and importers and distributors, among others. The roles do not map onto GDPR's pair — which GDPR role a company also holds is a GDPR question. A provider selling software it never operates may process no personal data at all: Article 16 obligations anyway, possibly none under GDPR. Which role you hold is covered in provider vs deployer and importer and distributor obligations.

Is a FRIA just a DPIA for AI?

No — but the Act expects you to build one on the other, and it now says so in different words. Under Article 27(1), certain deployers — bodies governed by public law, private entities providing public services, and all deployers of points 5 (b) and (c) of Annex III systems — must assess the fundamental-rights impact before first use. That duty is unamended.

Article 27(4) handles the overlap, and Regulation (EU) 2026/1744 replaced it. It used to say that where an Article 27 obligation was "already met through the data protection impact assessment", the FRIA "shall complement" it. It now says the deployer "may" — writing the FRIA — "include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment". Reuse became an express option rather than a duty to top up, but your DPIA is still no substitute: Article 27(1) obliges the assessment either way.

Article 27(5), also replaced, requires the AI Office to develop a questionnaire template carrying that same cross-referencing option. The Regulation sets no deadline for it.

Article 26(9) points the other way: deployers use the provider's Article 13 information to meet their DPIA obligation under Article 35 of Regulation (EU) 2016/679, where applicable. Article 26 is unamended.

The provider-side artifact has no GDPR counterpart at all: technical documentation under Article 11(1), drawn up before market placement and kept up to date. That first subparagraph is unamended; the second was replaced in 2026 to open the simplified Annex IV route to small mid-cap enterprises (SMCs) alongside SMEs, and to retarget the Commission's form at both.

Where does the AI Act lean on GDPR directly?

Sometimes the AI Act borrows GDPR's concepts. Article 3, point (52) defines profiling as "profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679" — unamended.

The place where the Act adds to data-protection law rather than deferring used to be Article 10(5). Regulation (EU) 2026/1744 deleted that paragraph and inserted a new Article 4a, "Processing of special categories of personal data for bias detection and correction". A policy that cites Article 10(5) now cites nothing.

Article 4a(1) carries the old permission almost word for word. Providers of high-risk systems "may exceptionally process special categories of personal data" where strictly necessary to ensure bias detection and correction in accordance with Article 10(2), points (f) and (g), "subject to appropriate safeguards" — and its six lettered conditions apply, in the Act's words, "In addition to the provisions set out in Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable". Still a tightly conditioned pathway on top of GDPR, not an exemption.

Article 4a(2) is new and has no counterpart in the deleted Article 10(5). It opens the same exceptional permission to "providers and deployers of other AI systems and models and deployers of high-risk AI systems" — so, for the first time, to deployers and to non-high-risk systems. The price is two cumulative conditions: the processing must be strictly necessary against biases "likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited pursuant to Union law", and every condition and safeguard in Article 4a(1) must be applied. Its closing sentence forecloses the obvious misreading: "This paragraph does not create any obligation to conduct such bias detection and correction."

How do the penalties compare?

The AI Act's ceilings are higher. Article 99(3) sets fines for prohibited practices at up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher; Article 99(4) sets up to €15,000,000 or 3% for breaches of provider, deployer, importer and distributor obligations. GDPR's top tier reaches 4% of worldwide annual turnover or €20 million, whichever is higher. (GDPR-side statement — see the sources note.) The regimes fine independently — one incident can draw both.

Company size inverts that arithmetic, and the two inversions differ in reach. Article 99(6), unamended, makes each fine "up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower" for SMEs, including start-ups. Regulation (EU) 2026/1744 inserted Article 99(6a) for SMCs: "In the case of SMCs, each fine referred to in paragraphs 4 and 5 shall be up to the percentages or amount referred therein, whichever is lower." Paragraphs 4 and 5 only — an SMC that breaches the Article 5 prohibitions is fined under paragraph 3, where the higher-of rule still stands. The full tier structure is in penalties under the EU AI Act.

What this means for you

If you're a provider: your GDPR programme covers almost none of your AI Act surface: provider duties — risk management, data governance, Article 11(1) technical documentation, conformity assessment — attach to the product, not to processing. What transfers is the discipline: an inventory, an owner per system, evidence on file. Start by classifying every system, since the tier decides everything downstream — Complipath's guided risk classification records each system's tier with the provisions and reasoning attached.

If you're a deployer: the same tool typically sits under both regimes at once; which GDPR role you hold is a GDPR question. Sequence: classify the system first, then the FRIA where Article 27(1) catches you — cross-referencing the DPIA under Article 27(4) rather than rewriting it — then the Article 26 operational duties. HR is the clearest case of full overlap — employee data plus an Annex III high-risk use — see the AI Act for HR tech.

Which of your systems answer to both?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

Does GDPR compliance mean we comply with the AI Act? No. GDPR compliance covers personal-data processing. The AI Act adds product obligations — classification, technical documentation, conformity assessment, oversight — that no GDPR programme produces. The reverse also holds: AI Act conformity does not make processing lawful. Article 2(7), as replaced in 2026, keeps both regimes in force without prejudice to Articles 4a and 59.

Can an AI system be outside GDPR but inside the AI Act? Yes. The AI Act's trigger is the Article 3, point (1) system definition plus risk tier, not personal data — a system processing only machine data can be high-risk with no GDPR exposure. Article 6(1a), inserted in 2026, narrowed the safety-component route; Article 6(1b) restores it wherever failure would endanger health and safety.

Do we need both a DPIA and a FRIA? Sometimes. The FRIA duty under Article 27(1) binds public-law bodies, private providers of public services, and deployers of points 5 (b) and (c) of Annex III systems. Where both apply, Article 27(4), as replaced in 2026, lets you cross-reference the relevant sections of the DPIA, or import parts of it, instead of restating them.

Which regime has the higher fines? The AI Act. Article 99(3) reaches €35 million or 7% of worldwide annual turnover for prohibited practices, and Article 99(4) reaches €15 million or 3% for operator breaches — against GDPR's 4% / €20 million top tier. For SMEs and SMCs those ceilings invert to the lower figure, on different scopes.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 2, 3, 4a, 6, 10, 11, 16, 26, 27, 59 and 99, as amended by Regulation (EU) 2026/1744 (EUR-Lex) — in force 27 July 2026. That Regulation replaced Article 2(7), deleted Article 10(5) and moved its regime to a new Article 4a with an added paragraph 2, replaced Article 27(4) and (5), replaced the second subparagraph of Article 11(1), inserted Article 6(1a), (1b) and (1c), and inserted Article 99(6a). Unamended and relied on as they stand: Article 2(1), Article 3, points (1) and (52), Article 6(1) and (2), Article 10(2), Article 11(1) first subparagraph, Articles 16, 26 and 59, Article 27(1), and Article 99(3), (4) and (6). This guide carries no application dates; those moved too, and the timeline guide has them. Two questions the amending text does not settle and this guide does not resolve: Article 4a sits in Chapter I while the Article 10(2) criteria it works from sit in Chapter III, whose Sections 1, 2 and 3 now apply later — so when Article 4a(1) starts to bite for a given provider is not stated; and Article 4a(2) permits deployer-side processing without saying which supervisory route polices it. GDPR-side limitation: this guide is sourced solely from the AI Act's text, including its GDPR references. The marked GDPR statements (what it governs, its roles, its fine ceiling) are high-level general knowledge — verify against Regulation (EU) 2016/679 before relying on them. No GDPR text is quoted here.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.