How does the EU AI Act differ from the GDPR?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

The EU AI Act and the GDPR are two fundamentally different laws with different purposes. While the GDPR protects the privacy of personal data, the EU AI Act regulates the risks posed by AI systems themselves, regardless of whether those systems process personal data. The two laws complement each other and overlap in specific areas, but they do not replace one another. In this article, we answer the most frequently asked questions about the difference between the two laws and what that means for your organization.

What does the EU AI Act address that the GDPR does not cover?

The EU AI Act regulates the safety, transparency, and reliability of AI systems throughout their entire lifecycle. The GDPR focuses exclusively on the processing of personal data. The AI Act goes further: it applies to every AI system, even if it does not process personal data, and sets requirements for the design, operation, and risk management of those systems.

Specifically, the EU AI Act addresses matters that fall outside the scope of the GDPR, such as:

  • The ban on manipulative AI techniques that influence behavior without a person’s awareness
  • Mandatory technical documentation for AI systems in accordance with specific annexes
  • Requirements for the quality of training data, including the mitigation of bias
  • Mandatory CE marking and registration in an EU database for high-risk systems
  • Human oversight as a design requirement, including protection against automation bias
  • Rules for General-Purpose AI (GPAI) models, such as large language models

The GDPR sets requirements for how personal data is handled. The EU AI Act sets requirements for how an AI system is built, tested, and deployed, regardless of the type of data it processes. That is a fundamentally different starting point.

To which organizations does the EU AI Act apply?

The EU AI Act applies to any organization that develops, places on the market, imports, distributes, or uses AI systems within the European Union. This also applies to organizations outside the EU that offer AI systems to users within the EU. The law distinguishes between different roles, each with its own obligations.

The main roles are:

  • Providers: organizations that develop and market AI systems. They bear the heaviest obligations.
  • Deployers (data controllers): organizations that deploy an AI system under their own authority. They have less stringent but specific obligations, such as assigning human oversight and retaining logs for at least six months.
  • Importers and distributors: They must verify that conformity assessments have been conducted and retain the related documentation for ten years.

An important point to note: a deployer, importer, or distributor becomes a provider—with all the associated obligations—if they put their name on a system, make a substantial change to it, or modify its intended purpose in such a way that the system falls into the high-risk category. Providers outside the EU must also appoint an authorized representative within the EU.

What are the risk categories in the EU AI Act, and how do they work?

The EU AI Act uses four risk levels: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (minimal transparency requirements), and minimal or no risk (unregulated). Most current AI applications fall into the lowest category and are exempt from specific requirements.

Prohibited AI Applications

Applications that pose an unacceptable risk are completely prohibited, and these prohibitions will take effect on February 2, 2025. These include, among other things, AI that uses subliminal manipulation techniques, government social scoring systems, emotion recognition in the workplace or in educational institutions (except for medical or safety exceptions), and real-time biometric identification in public spaces for law enforcement purposes, except in strictly defined cases.

High-Risk AI Systems

High-risk AI is defined in two ways. First: systems that constitute a safety component of a product subject to EU harmonization legislation. Second: systems that fall within one of the eight domains listed in Annex III, including biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice. Systems that perform profiling of natural persons are always considered high-risk, even if they otherwise have a limited function.

Which obligations overlap between the AI Act and the GDPR?

The EU AI Act and the GDPR overlap in the area of data protection for high-risk AI systems. Deployers of high-risk systems must, where applicable, conduct a data protection impact assessment (DPIA), a requirement that already applies under the GDPR for high-risk data processing. Furthermore, both laws require transparency toward data subjects and emphasize human oversight.

Other overlapping elements include:

  • Rights of data subjects: Individuals who are subject to a decision made by a high-risk AI system may, pursuant to Article 86 of the AI Act, request an explanation of the determining factors. The GDPR provides for a similar right in the context of automated decision-making (Article 22 of the GDPR).
  • Logging and documentation: Both laws require the recording of processing activities and decisions, albeit with different specifications and retention periods.
  • Data Quality: The AI Act sets requirements for training data (relevant, representative, and as free as possible from errors and bias). The GDPR sets requirements for the accuracy of personal data. For AI systems trained on personal data, both sets of requirements therefore apply simultaneously.

In practice, this means that organizations must assess their AI-driven processes against both legal frameworks, because compliance with one law does not automatically guarantee compliance with the other.

What are the fines and enforcement measures under the EU AI Act compared to the GDPR?

Both laws impose substantial fines, but the systems differ. The GDPR imposes fines of up to 20 million euros or 4% of global annual revenue. The EU AI Act has three categories of fines depending on the severity of the violation: up to 35 million euros or 7% of global annual revenue for violations of prohibited practices, up to 15 million euros or 3% for other violations, and up to 7.5 million euros or 1.5% for providing incorrect information.

In terms of enforcement, the EU AI Act introduces a new regulatory landscape. The European Commission’s AI Office oversees GPAI models and models posing systemic risk. National supervisory authorities are responsible for enforcing the remaining provisions. In the Netherlands, the Dutch Data Protection Authority is expected to play a role in enforcement at the intersection of AI and data protection, but the exact division of responsibilities among supervisory authorities will be further elaborated in 2026.

One key difference is that the GDPR is already fully in effect, while the EU AI Act will be implemented in phases. The prohibited practices will take effect on February 2, 2025; the obligations for GPAI model providers will take effect on August 2, 2025; and the full set of high-risk obligations will take effect later during the implementation period.

How are Dutch organizations preparing for both laws at the same time?

Dutch organizations can best prepare by first conducting an AI assessment, determining the risk category of each system, and then identifying the overlap between GDPR obligations and AI Act obligations. By combining compliance efforts, you can avoid duplication of work and build a cohesive governance framework.

A practical step-by-step approach:

  1. Make an inventory of all AI systems that your organization uses or develops, including tools purchased from third-party vendors.
  2. Classify each system by risk level in accordance with the AI Act. Systems listed in Annex III or that involve the profiling of individuals are high-risk.
  3. Assess your organization’s role: Are you a provider, deployer, importer, or distributor? Each role entails different obligations.
  4. Align existing GDPR processes with the new AI Act requirements. Existing DPIA procedures, processing records, and incident reporting processes can serve as a foundation.
  5. Establish human oversight for high-risk systems and ensure that the employees involved are trained and qualified for that role.
  6. Retain logs and documentation in accordance with the required retention periods: deployers must retain logs for at least six months, and importers must retain compliance documentation for ten years.

For organizations that use AI in customer interactions or process automation, it is also important to inform employees about AI systems prior to their implementation, as required by Article 26(7) of the AI Act.

How Pegamento Helps with AI Compliance and Responsible AI Use

We understand that the combination of the EU AI Act and the GDPR can feel complex for many organizations—especially when you’re simultaneously working to improve your customer interactions, automate processes, and modernize your systems. At Pegamento, we develop AI solutions for customer service that are designed from the ground up with human oversight, transparency, and responsible use as our guiding principles. Our Agentic AI represents an evolution from task-oriented bots to self-thinking assistants that not only follow instructions but also take the initiative and act independently—always within clear parameters and under human oversight.

What we can do for your organization:

  • Understanding which AI applications within your customer engagement environment fall under which risk category
  • Implementation of AI systems in which logging, documentation, and human oversight are built in as standard features
  • A single point of contact for development, implementation, management, and support, so you don’t have to manage a complex supplier structure
  • Customized solutions using standard building blocks, certified in accordance with ISO 27001 (information security), ISO 9001, and ISO 26000

Would you like to know how to make your AI implementation both future-proof and compliant? Contact us, and we’d be happy to help you figure it out.

Frequently Asked Questions

Geldt de EU AI Act ook als mijn organisatie alleen gebruikmaakt van AI-tools van externe leveranciers, zoals ChatGPT of Microsoft Copilot?

Ja, ook als je uitsluitend AI-tools van derden inzet, val je als deployer onder de EU AI Act. Je bent dan verantwoordelijk voor het toewijzen van menselijk toezicht, het bewaren van logs gedurende minimaal zes maanden en het informeren van medewerkers vóór ingebruikname. Controleer bovendien of de leverancier voldoet aan zijn verplichtingen als aanbieder, want jij bent als deployer mede verantwoordelijk voor de naleving binnen jouw organisatiecontext.

Wat gebeurt er als een AI-systeem dat we nu gebruiken achteraf toch als hoog-risico wordt geclassificeerd?

Als een systeem alsnog in de hoog-risicocategorie blijkt te vallen, moet je organisatie alsnog voldoen aan alle bijbehorende verplichtingen, zoals het inrichten van menselijk toezicht, het opstellen van technische documentatie en het uitvoeren van een DPIA. Hoe eerder je een correcte classificatie uitvoert, hoe meer tijd je hebt om compliant te worden vóór de handhavingsdeadlines. Een proactieve AI-inventarisatie is dan ook geen eenmalige exercitie, maar iets dat je periodiek moet herhalen, zeker wanneer een systeem van functie of scope verandert.

Moeten we onze bestaande DPIA's aanpassen nu de EU AI Act van kracht is?

Niet per se aanpassen, maar wel uitbreiden en aanvullen. Een bestaande DPIA onder de AVG dekt de risico’s voor persoonsgegevens, maar de EU AI Act vereist dat deployers van hoog-risico AI-systemen ook de bredere AI-specifieke risico’s meenemen, zoals automatiseringsbias, robuustheid en de kwaliteit van trainingsdata. Praktisch gezien kun je een AI-specifiek addendum aan bestaande DPIA’s toevoegen, zodat je één geïntegreerd beoordelingsdocument hebt dat aan beide wettelijke kaders voldoet.

Hoe informeer ik medewerkers correct over het gebruik van AI-systemen, zoals vereist door de AI Act?

Artikel 26(7) van de EU AI Act verplicht deployers om werknemers vóór ingebruikname te informeren over de AI-systemen waarmee zij werken. In de praktijk betekent dit dat je minimaal uitlegt welk systeem wordt ingezet, wat het doet, welke beslissingen het ondersteunt of neemt, en hoe medewerkers hun toezichthoudende rol kunnen uitoefenen. Dit kan via een intern beleidsdocument, een gerichte training of een onboardingsmodule — zorg in elk geval dat je kunt aantonen dat de informatie daadwerkelijk is verstrekt vóór de livegang.

Wat is het risico als we niets doen en afwachten tot de handhaving volledig op gang komt?

Afwachten is riskant om meerdere redenen. De verboden op bepaalde AI-toepassingen zijn al per 2 februari 2025 van kracht, wat betekent dat je bij gebruik van verboden systemen nu al boetes kunt oplopen van tot 35 miljoen euro of 7% van je wereldwijde jaaromzet. Bovendien kost het opbouwen van een compliant AI-governance raamwerk aanzienlijk meer tijd dan organisaties doorgaans inschatten, zeker als je ook AVG-processen moet integreren. Vroeg beginnen geeft je de ruimte om stapsgewijs en zonder tijdsdruk te werken.

Geldt de EU AI Act ook voor AI-systemen die we intern gebruiken en niet aan klanten aanbieden?

Ja, de EU AI Act is ook van toepassing op intern ingezette AI-systemen, mits ze binnen de EU worden gebruikt. Denk aan systemen voor HR-beslissingen, prestatiebeoordeling of werving en selectie — dit zijn expliciet genoemde hoog-risicotoepassingen in Annex III. Het feit dat een systeem niet publiek toegankelijk is of geen klantgerichte functie heeft, ontslaat je organisatie niet van de verplichtingen die gelden voor de risicocategorie waarin het systeem valt.

Hoe weet ik of een AI-leverancier echt compliant is met de EU AI Act, en wat moet ik contractueel vastleggen?

Vraag leveranciers om aantoonbare documentatie: technische documentatie conform de AI Act-bijlagen, een conformiteitsverklaring (bij hoog-risicosystemen), en informatie over hoe zij omgaan met datakwaliteit, bias-mitigatie en menselijk toezicht. Contractueel is het verstandig om afspraken te maken over wie welke verplichtingen draagt, wat er gebeurt bij een substantiële wijziging van het systeem, en hoe de leverancier jou informeert bij wijzigingen die de risicocategorie kunnen beïnvloeden. Nalatigheid van een leverancier ontslaat jou als deployer namelijk niet van je eigen verantwoordelijkheid.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.