← AI Terminology

GDPR / AI Act

GDPR (General Data Protection Regulation) is the EU's data privacy law (2018) governing how personal data is collected, processed, and used; the EU AI Act (2024) is the world's first comprehensive AI-specific regulation, classifying AI systems by risk and imposing requirements accordingly.

Together they form the EU's regulatory framework that every AI system operating in Europe must comply with.
Why It Matters in AI
GDPR already constrains AI training and deployment: Article 22 limits fully automated decisions affecting individuals; consent requirements limit scraping personal data for training. The AI Act adds AI-specific obligations: banning certain uses (real-time biometric surveillance), imposing conformity assessments on high-risk systems (hiring, credit, healthcare), and transparency requirements for foundation models. Non-compliance: fines up to €35M or 7% of global revenue.
Key Points
Aspect Description
Timeline AI Act in force Aug 2024; banned uses: Feb 2025; high-risk AI Act: Aug 2026
GDPR Art. 22 Right to human review of purely automated decisions — limits algorithmic credit/hiring decisions
AI Act risk tiers Unacceptable (banned), High-risk (conformity assessment), Limited (transparency), Minimal
Foundation models GPAI systems must publish technical documentation, copyright compliance, safety evaluations
High-risk examples Healthcare AI, hiring tools, credit scoring, law enforcement, critical infrastructure
Extraterritoriality Applies to any system deployed in the EU, regardless of where the developer is located
Simple Analogy
GDPR is like building codes for how you collect and store materials (data) — you can't use certain materials (personal data) without permits (consent) and must give tenants (individuals) rights to inspect. The AI Act adds safety codes for the finished building (AI system) itself — how risky it is determines how much certification it needs before it can open to the public.
Common Usage Examples
  • GDPR DSAR: individuals can request deletion of their data from training sets — a growing AI litigation front
  • AI Act conformity assessment: high-risk AI systems must register in EU database and pass technical audit
  • Foundation model transparency: providers must publish training data sources, compute used, energy consumption
  • Google/Meta GDPR fines: €1.2B and €1.3B respectively for data transfer violations
  • GDPR Article 17 (right to erasure): "right to be forgotten" requests challenging AI models trained on personal data
Summary
In short: GDPR governs the data AI is trained on; the EU AI Act governs what the AI can do — together they are the most comprehensive AI regulatory framework in the world and set the de-facto global compliance bar.