GDPR and the EU AI Act were written eight years apart, by different institutional processes, answering different questions. GDPR asks whether you had a lawful basis to process someone's personal data. The AI Act asks whether an AI system that touches someone's life — hiring, credit, biometric identification — is safe, transparent, and subject to human oversight. Most organisations now deploying AI have to satisfy both at once, and the overlap between them is where the real compliance difficulty sits.
Take a recruitment tool that screens CVs. Under GDPR, the employer needs a lawful basis to process each candidate's personal data, and if the tool makes a fully automated decision with legal or similarly significant effect, Article 22 gives the candidate a right to meaningful human review. Under the AI Act, the same tool is very likely classified as high-risk under Annex III, which brings a separate stack of obligations: a risk management system, technical documentation, human oversight measures, and post-market monitoring. Satisfying Article 22 does not automatically satisfy Annex III, and building AI Act technical documentation does not automatically produce a GDPR-compliant data processing record. They are parallel obligations that happen to attach to the same system.
The timeline adds another layer of difficulty. The AI Act's prohibited-practices provisions — bans on social scoring, certain biometric categorisation, and emotion recognition in the workplace — took effect in February 2025. High-risk system obligations were due to apply from August 2026, though the European Commission's Digital Omnibus proposal, still being negotiated through 2026, would push much of that back to December 2027. Meanwhile GDPR enforcement has not paused for any of this; DPAs are still fining companies for AI-adjacent processing under the existing rules while the AI Act's own enforcement infrastructure is still being built out.
For a compliance function, the practical response is to stop treating the two regimes as separate projects run by separate teams. A single AI system inventory that tags each tool against both frameworks — lawful basis and risk classification side by side — is the only way to see where the genuinely hard problems sit, rather than discovering the gap between them during a regulator's inquiry.