AI Act vs GDPR: what they share and how they differ
AI Act and GDPR share 9 of 24 control themes and 9 checks. 70% of GDPR requirements can be proven with checks AI Act already uses, 21% the other way round.
Phasing in
AI Act
How to make an AI system compliant with the EU AI Act
33 requirementsNext Aug 2, 2027
In force
GDPR
How to make AI compliant with the GDPR
10 requirementsNext Jan 2027
9/24shared control themes
9shared checks
70%of GDPR requirements covered by AI Act evidence
21%of AI Act requirements covered by GDPR evidence
At a glance
| AI Act | GDPR | |
|---|---|---|
| Jurisdiction | European Union same | European Union same |
| Kind | Regulation same | Regulation same |
| Status | Phasing in | In force |
| Binding | Yes same | Yes same |
| Object analysed | AI system | Data processing |
| Scope | Providers, deployers, importers and distributors of AI systems; providers of GPAI models. | Controllers and processors. |
| Territorial reach | Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU. | EU establishment, or targeting / monitoring people in the EU. |
| Penalties | Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information). | Up to €20M or 4% of worldwide turnover. |
| Qualification axes | AI Act risk level, Organisation role, General-purpose model | Automated decision (Art. 22), DPIA required (Art. 35) |
| Roles | Provider, Deployer, GPAI provider | Controller, Processor |
| Requirements | 33 | 10 |
| Next milestone | Aug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025 | Jan 2027, Possible adoption of the Omnibus amendments |
Theme by theme
requirements per theme
AI ActGDPR
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
9
| Code | Check | Requirements AI Act | Requirements GDPR |
|---|---|---|---|
| VER-004-01 | Documented data governance (collection process, bias, quality) | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | ||
| VER-009-01 | Cybersecurity of the hosting environment | ||
| VER-009-03 | Cybersecurity of the AI system verified | ||
| VER-022-D-01 | Serious incident reporting procedure | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | ||
| VER-029-D-01 | Affected persons informed of the use of the AI system | ||
| VER-033-D-01 | Decision explanation procedure documented | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
AI Act
26
EX-001
AI literacy Art. 4
EX-002
Prohibited practices Art. 5
EX-003
Risk management Art. 9
EX-005
Technical documentation Art. 11 + Annexe IV
EX-006
Record-keeping / logging Art. 12
EX-007
Transparency to deployers Art. 13
EX-010
QMS Art. 17
EX-011
10-year retention Art. 18
EX-012
Automatically generated logs Art. 19
EX-013
Corrective actions Art. 20
EX-014
Cooperation with authorities Art. 21 + Art. 26§12
EX-015
EU declaration of conformity Art. 47
EX-016
CE marking Art. 48
EX-017
EU database registration Art. 49
EX-018
Transparency for all systems Art. 50
EX-019
DPIA Art. 26§9
EX-020
FRIA Art. 27
EX-021
Post-market monitoring Art. 72
EX-023
Accessibility Art. 16(l)
EX-024
Conformity assessment Art. 43
EX-025
EX-027
Compliant use Art. 26§1
EX-028
Input data Art. 26§4
EX-030
Information to workers' representatives Art. 26§7
EX-031
GPAI obligations Art. 53
EX-032
GDPR
3
GDPR-01
GDPR-05
Record of processing activities Art. 30
GDPR-06
Impact assessment (DPIA) and prior consultation Art. 35, 36
Timelines
PastSet in the textPotentialTo verify
Apr 27, 2016GDPR · Adoption
May 25, 2018GDPR · Application date
Apr 21, 2021AI Act · Commission proposal
Jul 12, 2024AI Act · Published in the Official Journal
Aug 1, 2024AI Act · Entry into force
Dec 17, 2024GDPR · EDPB Opinion 28/2024 on AI models
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
Jul 10, 2025AI Act · GPAI Code of Practice published
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Nov 19, 2025GDPR · Digital Omnibus: legitimate interest for AI training, personal data definition
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
Jan 2027GDPR · Possible adoption of the Omnibus amendments
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.