01 AI Consulting 02 Software Development 03 About 04 Blog
DE EN
Arrange a call
← All posts

AI & Law

EU AI Act & GDPR — What Companies Must Do Now in 2026

The AI Act is no longer a distant threat. The first obligations are already in force, the August 2026 milestone has arrived — and the amendment package that pushes the high-risk deadlines back has been in force since late July 2026. Companies that set things up cleanly now, rather than letting the time they gained slip away, are on the safe side. This article situates the legal position and names concrete next steps. (This is general information, not legal advice.)

Updated in September 2026: This article was published in May 2026, when the “Digital Omnibus” was still a provisional agreement. Amending Regulation (EU) 2026/1744 has since entered into force — Official Journal of July 24, 2026, applicable since July 27, 2026. The high-risk obligations under Annex III now apply only from December 2, 2027, those under Annex I from August 2, 2028; what did become applicable on August 2, 2026 are above all the transparency obligations under Art. 50. The deadlines and assessments below have been corrected accordingly. For what the Omnibus changed in detail, see The AI Act, Cut in Half.

What Already Applies — and What Only Appears to Be Waiting

The AI Regulation — formally Regulation (EU) 2024/1689 — entered into force on August 1, 2024. As a regulation, it applies directly in all Member States; no national transposition, as would be needed for a directive, is required. Its obligations, however, do not take effect all at once but in phases (Art. 113, in the version applicable since July 27, 2026):

  • February 2, 2025: The prohibited AI practices (Art. 5) are live. So is the obligation to ensure AI literacy (Art. 4).
  • August 2, 2025: Obligations for general-purpose AI models (GPAI), the governance structure, and the penalty regime take effect.
  • August 2, 2026: General application of the remaining provisions — in particular the transparency obligations (Art. 50) and Art. 6(5).
  • December 2, 2026: Two further prohibitions in Art. 5, plus the marking obligation for legacy generative systems (new Art. 111(4)).
  • December 2, 2027: High-risk obligations under Annex III (Chapter III, Sections 1 to 3, including the deployer obligations in Art. 26 and the fundamental rights impact assessment under Art. 27).
  • August 2, 2028: High-risk systems under Annex I (AI as a safety component of regulated products).

A practical point worth stressing: two of these obligations apply to every company, including pure users. The prohibited practices (e.g. social scoring) are off limits in any case. And the AI-literacy obligation under Art. 4 applies regardless of risk class and is already in force — though the Omnibus has softened it: what is required are measures to support the development of AI literacy; no one has to guarantee any specific level of literacy for any individual. How to implement it concretely, without lapsing into training theater, I cover separately in Implementing the AI-literacy obligation (Art. 4).

The Risk-Class Principle in One Sentence

The AI Act classifies AI systems by their risk and ties the obligations to it: unacceptable risk is prohibited, high-risk systems carry full obligations, limited risk only transparency duties, minimal risk none. GPAI models form their own cross-cutting category.

The AI Act follows a simple logic: the higher a system’s risk, the stricter the obligations. Four tiers plus one cross-cutting category:

  • Unacceptable risk — prohibited (Art. 5).
  • High risk — e.g. AI used in hiring, in creditworthiness assessment, or in critical infrastructure (Annex III), as well as AI as a safety component of regulated products (Annex I). Full obligations for providers and deployers.
  • Limited risk — e.g. chatbots, AI-generated content. Here the transparency obligations (Art. 50) apply: people must be able to recognize that they are talking to an AI or that content is AI-generated.
  • Minimal risk — the bulk of applications, with no mandatory requirements.
  • GPAI models cut across the rest: universally deployable models with their own obligation track. Transparency and copyright obligations apply to all of them, with additional safety requirements where there is systemic risk (one indicator being a training compute above 10²⁵ FLOP).

For most mid-sized companies, the decisive question is not “Are we the provider of a high-risk system?” but “Do we deploy such a system?” Companies that merely purchase and use AI are usually deployers and therefore carry a lighter burden than the provider — but not zero. Note: anyone who substantially modifies a system or markets it under their own name can themselves become a provider (the common interpretation; to be assessed case by case).

The August 2026 Deadline and the “Digital Omnibus”

This was the most important pitfall of the year — and it has since been cleared. The provisional agreement of May 2026 has become law: Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”), the legal act of July 8, 2026, was published in the Official Journal on July 24, 2026 and has been in force and applicable since July 27, 2026. It pushes the high-risk deadline for Annex III systems from August 2, 2026 to December 2, 2027, and the Annex I deadline to August 2, 2028.

What matters is what was deferred: Chapter III, Sections 1 to 3 — classification, the requirements for high-risk systems, and the deployer obligations, including the fundamental rights impact assessment under Art. 27. A company running applicant screening or employee evaluation (Annex III) therefore has until December 2, 2027. What was not deferred is Art. 5 and Art. 50: what became applicable on August 2, 2026 are above all the transparency obligations under Art. 50, plus Art. 6(5). And on December 2, 2026, two further prohibitions in Art. 5 take effect, along with the marking obligation for legacy generative systems (new Art. 111(4)).

The Omnibus also brings relief: Art. 4 now only requires measures to support the development of AI literacy, the new Art. 6(1a) to (1c) take a good deal of industrial AI out of Annex I, and under the new Art. 99(6a) the fine cap at the lower of the two values now also applies to mid-sized companies. The sober recommendation nonetheless stands: plan according to the law as it stands. The time gained concerns only the high-risk regime — Art. 5 and Art. 50 apply today.

The Fines — and Why SMEs Sometimes Come Off Better

The penalty regime (Art. 99) is tiered; in each case the higher of the two values applies:

  • Prohibited practices (Art. 5): up to EUR 35 million or 7% of worldwide annual turnover.
  • Other breaches of obligations: up to EUR 15 million or 3%.
  • Incorrect information supplied to authorities: up to EUR 7.5 million or 1%.

This means the AI Act’s maximum even exceeds the GDPR ceiling (EUR 20 million / 4%, Art. 83 GDPR). One important relief for smaller players: for SMEs and start-ups, the lower value applies in each case (percentage or fixed amount) — not, as otherwise, the higher one (Art. 99(6)). The Omnibus has extended this cap to mid-sized companies via the new Art. 99(6a).

Schematic illustration of the parallel application of the EU AI Act as product safety law and the GDPR as data protection law to a single AI system

Two rulebooks, one system: the AI Act regulates the AI system as a product, the GDPR the personal data processed within it. As soon as both coincide, both tracks apply at the same time.

The Interface with the GDPR: Two Regimes, Not One

The most common conceptual error is to treat the AI Act and the GDPR as alternatives. They apply cumulatively. The AI Act is primarily product safety law — it regulates the system. The GDPR protects the fundamental right to data protection — it regulates the processing of personal data. As soon as an AI system processes personal data, both apply at the same time.

This gives rise to concrete overlaps:

  • Legal basis first. Every processing of personal data in an AI tool requires a legal basis under Art. 6 GDPR — in practice usually performance of a contract (point (b)), legitimate interest (point (f), with a documented balancing test) or consent (point (a)). Special categories (health, biometrics, etc.) additionally require Art. 9 GDPR.
  • Processing on behalf. If an external AI provider processes data on your behalf, a data processing agreement under Art. 28 GDPR is mandatory. Free consumer tools usually offer none — and partly use inputs for training, which can flip the provider’s role from processor to independent controller.
  • Third-country transfer. Most AI providers are based in the US. Any transfer there requires a basis under Art. 44 et seq. GDPR — either certification of the provider under the EU-US Data Privacy Framework or standard contractual clauses. The DPF currently applies (the General Court dismissed the action against the adequacy decision on September 3, 2025), but that ruling is not yet final — double-securing via SCCs as a fallback is a common precaution. When an EU-hosted model or on-premise deployment is worth it instead, I compare in EU-hosted vs. US LLMs.
  • Impact assessments. This is where the regimes interlock: the GDPR’s DPIA (data protection impact assessment, Art. 35) and the AI Act’s data-governance requirements (Art. 10) are separate but related instruments. For high-risk systems involving personal data, both often arise together — when a DPIA for AI systems actually becomes mandatory, and how to run it cleanly, is a topic of its own.

It is precisely this dual nature that makes AI compliance neither a pure tech question nor a pure legal one. Anyone wearing both lenses avoids the typical gap: a technically clean system whose data flows were never assessed under the GDPR — or, conversely, watertight data-protection documentation for a system whose AI Act classification no one has carried out.

Action Checklist for 2026

  1. Inventory. Which AI systems do you use, plan, or tolerate — including unofficial “shadow AI” run by employees?
  2. Classify. Which AI Act risk class does each system fall into, and are you the provider or the deployer?
  3. Establish a legal basis per use case (Art. 6, and where relevant Art. 9 GDPR) and document it.
  4. Review contracts. A data processing agreement under Art. 28 with every provider that processes personal data; business/enterprise plans rather than consumer versions. What needs to go into an AI contract beyond the DPA — performance, liability, IP, SLA — is a separate checkpoint.
  5. Secure third-country transfers — check DPF status, use SCCs as a fallback.
  6. Create transparency. Label AI interactions and AI-generated content (Art. 50).
  7. Build AI literacy. Art. 4 requires measures to support the development of AI literacy — training is the obvious route, and it simultaneously defuses the shadow-AI risk.
  8. Carry out a DPIA wherever there is a high data-protection risk (Art. 35 GDPR).
  9. Put an internal AI policy in writing: permitted tools, prohibitions, the duty to check outputs, reporting channels.
  10. Monitor the legal landscape — the Digital Omnibus is done; what remains on the watchlist are the Commission’s still-outstanding guidelines on high-risk classification, and the DPF.

Conclusion

The AI Act is manageable once you take it for what it is: a phased program of obligations with a clear logic. The obligations already in force today — prohibited practices, AI literacy, and, since August 2026, the transparency obligations — cost little and are quickly handled. The bigger task, the high-risk classification and the interlocking with the GDPR, should be tackled now — the Digital Omnibus bought time until December 2027, but it did not do the work. A company that knows, classifies, and has legally underpinned its systems can face both regimes with composure.

This dual perspective — the legal classification and the technical implementation in one head — is exactly how I work. If you want to classify your AI systems or structure your compliance homework, get in touch.

Frequently Asked Questions (FAQ)

Does the AI Act apply to my company even if we only purchase AI?

Yes. Anyone who deploys an AI system is regularly a deployer within the meaning of the regulation and carries its own obligations — for high-risk systems, for example, human oversight and monitoring. Regardless of risk class, you are also bound by the prohibition of certain practices (Art. 5) and the AI-literacy obligation (Art. 4). “Just a user” does not mean “not affected”.

Does the “Digital Omnibus” push the August 2026 deadline back bindingly?

Yes, it now does. Amending Regulation (EU) 2026/1744 was published in the Official Journal on July 24, 2026 and has been in force since July 27, 2026. The high-risk regime under Annex III therefore applies only from December 2, 2027, and Annex I from August 2, 2028. What did become applicable on August 2, 2026 are above all the transparency obligations under Art. 50.

Is complying with the GDPR enough when I deploy AI?

No. The AI Act and the GDPR are cumulative: the GDPR governs the processing of personal data, the AI Act the system as a product. A GDPR-compliant tool can still breach AI Act obligations — and vice versa. As soon as personal data is involved, you must serve both regimes.

As an SME, what should I do first?

Pragmatically, in this order: inventory your AI systems (including shadow AI), determine each system’s risk class and role, document the legal basis and data processing agreements, write an internal AI policy, and ensure your staff’s AI literacy. These five steps cover the bulk of the acute risk.

Are the fines really existential for small companies?

The maximum (up to EUR 35 million / 7% of turnover for prohibited practices) targets large players. For SMEs and start-ups, Art. 99(6) applies the lower of the two values in each case. That puts the headline figures into perspective — but does not exempt you from the obligations.


Sources — as of 26.09.2026
Leon Lotz

Leon Lotz

Leon Lotz is a business lawyer and founder of MusketierSoftware. He combines legal depth with real software craft.

AI-assisted, editorially reviewed and under editorial responsibility. AI transparency