Skip to content

Blog

EU AI Act and GDPR: Where the Two Laws Overlap

EU AI Act and GDPR shown as two interlocking rings sharing a common core inside a circle of EU stars

Teams often treat the EU AI Act as a brand new rulebook that lands on a clean desk. It does not. If your AI system touches personal data, GDPR was already on that desk, and the AI Act stacks on top of it.

That stacking is where most of the confusion lives. The same project can owe a Data Protection Impact Assessment under one law and a Fundamental Rights Impact Assessment under the other, and nobody wants to run two parallel compliance tracks if one mapped program will do.

EU AI Act Risk Categories: The 4 Levels Explained

EU AI Act risk categories shown as a four-level pyramid from minimal to unacceptable risk inside a circle of EU stars

The EU AI Act does not treat every AI system the same way. It uses a risk-based design, so the obligations on a spam filter look nothing like the obligations on a CV-screening tool or a credit-scoring model.

That single decision, which risk category your system falls into, drives almost everything else: the controls you owe, the documentation you keep, and the size of the fine if you get it wrong.

EU AI Act Timeline: Compliance Deadlines to 2028

EU AI Act compliance timeline showing the staged deadlines from 2024 to 2028, with the high-risk regime in December 2027, under a circle of EU stars

The EU AI Act does not arrive on a single date. It applies in stages between 2024 and 2028, and each stage switches on a different set of obligations for the organizations that build or use AI systems in Europe.

The schedule also moved. The Digital Omnibus on AI, in force since 27 July 2026, pushed the high-risk regime for Annex III systems back to 2 December 2027, which gives most compliance teams extra runway while the obligations themselves still arrive.

Remote Work Cybersecurity: A Practical Training Guide

Remote work cybersecurity training showing a home office protected against network and device threats

Your employees left the office network years ago. They open company data on home WiFi, sync it to personal phones, and connect through VPNs that attackers now probe first. The perimeter you used to defend moved into hundreds of living rooms.

That shift changed where breaches start. Exploitation of vulnerabilities was the initial access vector in 20% of breaches last year, a 34% jump, with attackers focusing on VPNs and perimeter devices, according to the Verizon 2025 Data Breach Investigations Report. The unpatched router and the always-on VPN are no longer edge cases.

Below, we break down the real risks of distributed work, the home-network and device habits that close them, and the exercises that turn those habits into reflex.

The 7 GDPR Data Protection Principles in Practice

The seven GDPR data protection principles from Article 5 arranged around a privacy shield

Most teams can name GDPR. Far fewer can name the seven principles that decide whether their daily data handling is lawful. Those principles live in Article 5, and regulators treat them as the test every processing activity has to pass.

The gap matters because the principles are where enforcement lands. Cumulative GDPR fines passed EUR 7.1 billion since May 2018, according to the DLA Piper GDPR Fines and Data Breach Survey (January 2026). Most of those penalties trace back to a broken principle: data kept too long, collected without need, or processed without a lawful basis.

This guide walks through all seven principles, shows the habits that break each one, and points to interactive exercises your team can run to practice the right behavior.