CSOAI - regulation explainer

EU AI Act vs GDPR

Two EU regimes, two different jobs - and a real overlap on automated decisions. Here is how they differ, where they meet, and why GDPR compliance is not enough on its own.

Dimension
EU AI Act
GDPR
What it regulates
AI systems and models by risk
Processing of personal data
In force
Phasing: transparency + GPAI 2 Aug 2026; high-risk Dec 2027 (Annex III) / Aug 2028 (Annex I)
Since May 2018
Trigger
Building, providing, or deploying AI in the EU market
Handling personal data of people in the EU
Structure
Risk tiers: prohibited / high-risk / limited / minimal
Principles + lawful bases + data-subject rights
Max penalty
EUR 35m or 7% of global turnover
EUR 20m or 4% of global turnover
Overlap
Automated decisions, profiling, data governance
Art. 22 automated decisions; data minimisation
The CSOAI bridge: reuse your GDPR data-governance and automated-decision evidence, then crosswalk it onto the AI Act's risk classification and transparency duties - one program, both regimes.