EU AI Act Compliance Must Integrate GDPR Framework
Firms developing or deploying artificial intelligence in Europe should build on existing GDPR data governance programs to address EU AI Act obligations, as the new regulation defers to and incorporates core data-protection principles.
Providers and deployers of AI systems must understand that compliance with the EU's Artificial Intelligence Act is inseparable from the General Data Protection Regulation (GDPR). The AI Act was drafted to complement, not supplant, existing data protection law, expressly deferring to the GDPR in cases of conflict and incorporating its core concepts. Key terms such as 'personal data,' 'profiling,' and 'biometric data' are defined by reference to the GDPR.
Sophisticated clients and counsel care because bifurcating compliance programs for these two laws creates significant risk. An AI-driven data processing activity, such as employee performance profiling, might be permissible as a 'high-risk' system under the AI Act but could be illegal under the GDPR if there is no lawful basis for the processing. This could expose an organization to enforcement by data protection authorities. To mitigate this, firms should integrate AI Act compliance into their existing GDPR-compliant data governance programs. This includes conducting the AI Act’s Fundamental Rights Impact Assessments (FRIA) as a complement to the GDPR’s required Data Protection Impact Assessments (DPIA). The immediate action is to ensure that legal and compliance teams analyze AI use cases through the lens of the GDPR first.