Two laws, two different questions

The GDPR asks how you handle personal data. The AI Act asks what the AI system does and how much harm it could cause. A document workflow that reads supplier invoices touches little personal data and is low risk under both. A tool that screens job applicants touches a lot of personal data and is high-risk under the AI Act.

What the GDPR asks of an AI build

Question What a good answer looks like Required by the GDPR?
Why may we use this data? A legal basis for each purpose, written down Yes
Who else handles it? An Article 28 processor agreement with each provider Yes
Does it leave the EU? A transfer safeguard, such as the Data Privacy Framework or standard contractual clauses Yes, for transfers
How long is it kept? A retention period, enforced in the code Yes
Do automated decisions affect people? A person reviews decisions with legal or similar effects Yes, for those decisions
Where is the data stored? Your cloud account, in an EU region you chose Good practice
Is it used to train models? Training opt-out on the model accounts Good practice

What the AI Act asks of most business tools

Most internal tools, document workflows and assistants fall outside the high-risk list. One duty applies to every company that uses an AI system at work: the staff who use it need enough AI literacy, which has applied since February 2025. Transparency duties apply to specific systems. People must know when they are talking to an AI system, and AI-generated content must be marked where the Act requires it. An invoice workflow that nobody chats with has no transparency duty. The high-risk rules, with risk management, logging, human oversight and conformity checks, apply to the uses listed in the Act. The obligations phase in over several years, so check the current dates for your case.

What to check before the build

Name the personal data the system will see. Decide the region. List every provider that will process the data. Ask whether the use is on the AI Act’s high-risk list. Your data protection officer or lawyer signs off; the build follows their answers.

How this applies to us

The system runs on your cloud account in the region you choose, and we sign a data processing agreement with you as your processor. Model accounts are in your name with training opt-out, and the evaluation sets we build stay in your repository. We build GDPR-aware systems; the certification and the legal assessment stay with you, and we say that plainly.