Skip to main content
Category: Legal Framework & Instruments

AI Act

Also known as: AI Act, Artificial Intelligence Act, EU AI Act, EU Artificial Intelligence Act
Simply put

The AI Act is a European Union law that regulates artificial intelligence based on the level of risk an AI system may pose. It is generally described as the first comprehensive legal framework for AI adopted by a major regulator, and it aims to address the potential harms of AI while supporting Europe's role in the field. It applies within the EU context and should be read alongside, rather than as a substitute for, data protection law such as the GDPR.

Formal definition

The AI Act is an EU regulation establishing a common regulatory framework for artificial intelligence, adopted in 2024, that assigns obligations according to a risk-based approach (including categories such as prohibited practices and higher-risk uses). It is a distinct instrument from the GDPR and does not replace data protection requirements; where an AI system processes personal data, GDPR obligations continue to apply in parallel and must be assessed separately. Practitioners should verify specific article numbers, risk classifications, obligations, and applicability or transition dates against the current official text of the Regulation, as detailed provisions and implementing guidance continue to evolve and are not fully established by the evidence available here.

Why it matters

The AI Act is generally described as the first comprehensive legal framework for artificial intelligence adopted by a major regulator, which makes it a reference point for organisations developing or deploying AI systems that touch the EU market. It regulates AI according to the level of risk a system may pose, meaning that the obligations attaching to a given use case depend on how that use is classified. For privacy and compliance professionals, this signals a shift toward AI-specific regulatory expectations that sit alongside existing data protection duties rather than displacing them.

A central point for practitioners is that the AI Act is a distinct instrument from the GDPR. Where an AI system processes personal data, GDPR obligations continue to apply in parallel and must be assessed on their own terms; compliance with one framework does not establish compliance with the other. Treating the AI Act as a replacement for data protection analysis, or vice versa, risks leaving material obligations unaddressed. Organisations should map where the two frameworks overlap and where each imposes separate requirements.

Because detailed provisions, risk classifications, and applicability or transition timelines continue to evolve and are supported by implementing guidance that is not fully settled, the practical impact of the AI Act should be treated as developing rather than fixed. Readers should verify specific obligations and dates against the current official text of the Regulation before relying on them in a compliance program.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy teams need to understand where the AI Act and the GDPR interact, since an AI system processing personal data remains subject to data protection obligations that must be assessed separately from any AI Act risk classification. This group should treat the two frameworks as complementary and confirm specific requirements against the current official texts.
Compliance and legal teams
Compliance leads and lawyers advising on AI deployment within the EU context should account for the AI Act's risk-based structure when scoping obligations, while recognising that detailed provisions, classifications, and transition dates continue to evolve and should be verified against the Regulation as adopted rather than relied upon from summaries.
Engineers and product teams building AI systems
Teams designing or deploying AI systems should be aware that obligations may vary according to how a system's use is classified under the risk-based approach, and that where personal data is involved, GDPR requirements apply in parallel. Early engagement with legal and privacy functions helps identify which obligations attach to a specific use case.

Inside AI Act

Risk-based classification
The AI Act generally structures obligations according to the level of risk an AI system presents, typically distinguishing prohibited practices, high-risk systems, limited-risk systems subject to transparency duties, and minimal-risk systems. The precise categories and thresholds should be verified against the current official text.
Prohibited AI practices
Certain AI uses are, in most cases, banned as presenting unacceptable risk. The exact scope and any exceptions are defined in the Regulation and may be subject to interpretive guidance.
High-risk system obligations
Systems classified as high-risk are typically subject to requirements that may include risk management, data governance, technical documentation, human oversight, and conformity assessment. The specific obligations should be confirmed against the operative provisions.
Transparency obligations
Some systems, such as those interacting with individuals or generating synthetic content, generally attract transparency duties requiring users to be informed in certain circumstances.
Actor roles
The AI Act allocates duties across distinct roles, commonly including providers and deployers, among others. These roles are separate and should not be conflated; obligations differ by role.
Relationship to data protection law
The AI Act is distinct from the GDPR. Where an AI system processes personal data, GDPR obligations continue to apply in parallel, and neither instrument displaces the other. The interaction between the two frameworks is an area where regulatory guidance continues to develop.

Common questions

Answers to the questions practitioners most commonly ask about AI Act.

Does the AI Act replace or override the GDPR for AI systems that process personal data?
No. The AI Act and the GDPR are separate instruments that apply in parallel. The AI Act addresses the safety, risk classification, and governance of AI systems, while the GDPR continues to govern any processing of personal data those systems carry out. Where an AI system processes personal data, an organisation generally must satisfy both frameworks, including identifying a valid Article 6 legal basis under the GDPR and, for special category data, an additional Article 9 condition. Neither instrument displaces the other, and obligations should be assessed cumulatively.
Are all AI systems subject to the same strict obligations under the AI Act?
No. The AI Act generally takes a risk-based approach, meaning obligations vary according to the risk category into which a given system falls. Systems classified as higher risk are typically subject to more extensive requirements than those posing lower risk, and certain practices may be restricted or prohibited. Because classification drives the applicable obligations, organisations should assess each system individually rather than assume a single uniform standard applies. The precise categories, thresholds, and requirements should be verified against the current official text, as interpretation and guidance continue to develop.
How should an organisation determine which obligations apply to a particular AI system?
The starting point is generally to classify the system according to the AI Act's risk-based framework, since the applicable obligations depend on that classification. Organisations typically document the system's intended purpose, functionality, and context of use to support that assessment. Where the system also processes personal data, a parallel GDPR analysis is usually needed, and in some cases a Data Protection Impact Assessment under Article 35 of the GDPR may be relevant. Because classification questions can involve uncertainty, organisations should verify their conclusions against the current official text and any regulator guidance.
How does compliance with the AI Act interact with existing GDPR documentation and processes?
The two frameworks can involve overlapping but distinct documentation. GDPR compliance typically covers records of processing, legal bases, and, where required, a Data Protection Impact Assessment under Article 35, whereas the AI Act focuses on system-level risk and governance obligations. In practice organisations often coordinate these workstreams so that personal data considerations are reflected in both, but the instruments should not be treated as interchangeable. A Data Protection Impact Assessment does not by itself discharge AI Act obligations, and vice versa; each should be addressed on its own terms.
What roles and responsibilities should organisations map when implementing the AI Act?
Organisations generally need to identify their role in relation to a given AI system, as obligations differ depending on the capacity in which an entity acts. This is distinct from the GDPR's controller and processor roles, which continue to apply separately to any personal data processing. An organisation may hold different roles under the two frameworks for the same system, so mapping responsibilities under each instrument independently is typically advisable. The specific defined roles and their obligations should be confirmed against the current official text.
How should organisations approach the phased or evolving nature of AI Act obligations?
Because the applicable requirements and timelines can evolve, organisations are generally advised to treat implementation as an ongoing process rather than a one-time exercise. This typically includes monitoring for updated guidance, tracking how obligations apply to each system over its lifecycle, and revisiting classifications and documentation as systems or their uses change. Specific effective dates and transitional arrangements should be verified against the current official text and relevant guidance, as these details are subject to change and may be interpreted differently across authorities.

Common misconceptions

The AI Act replaces or overrides the GDPR for AI systems.
The AI Act and the GDPR are separate instruments that generally apply concurrently. Processing of personal data by an AI system remains subject to GDPR requirements, including identifying an appropriate Article 6 legal basis and, for special category data, an additional Article 9 condition.
All AI systems face the same obligations under the AI Act.
Obligations are generally allocated on a risk-based basis, so requirements typically differ substantially between prohibited, high-risk, limited-risk, and minimal-risk systems. The applicable duties depend on classification and on the actor's role.
Complying with the AI Act automatically ensures full compliance across the board.
Compliance is context and risk dependent. Meeting AI Act requirements does not discharge separate obligations, such as those under the GDPR, and the boundaries of many concepts remain subject to evolving guidance and potential regulator divergence.

Best practices

Determine your role for each AI system, distinguishing provider from deployer and other actors, since obligations differ by role and should not be conflated.
Classify each AI system by its risk level early, and document the reasoning, as the applicable obligations generally flow from that classification.
Where an AI system processes personal data, run GDPR analysis in parallel, confirming an appropriate legal basis and, for special category data, an additional condition, rather than assuming the AI Act covers those requirements.
Maintain technical documentation and records proportionate to the risk classification, and revisit them as guidance and interpretation continue to develop.
Implement human oversight and transparency measures where the relevant category requires them, and confirm the specific triggers against the current official text.
Verify article references, thresholds, and any exceptions against the operative Regulation text and current regulatory guidance before relying on them in a compliance program.