Skip to content
atlas

Don't confuse these

EU AI Act vs GDPR

Why they differ

GDPR protects personal data wherever it is used; the AI Act governs AI systems as products, whether or not they touch personal data. Both often apply at once.

EU AI Act

AI risk & governance

The EU law that sorts AI systems by how much harm they could cause and sets stricter rules the higher the risk.

Formal

An EU regulation, in force from 1 August 2024 and applying directly in every member state, that bans some uses of AI, sets duties for high-risk systems, requires openness about chat assistants and deepfakes, and places duties on makers of general-purpose AI models.

In plain English

Like food safety rules that barely touch a bakery selling bread but put a baby-food factory under close inspection - the rules grow with what could go wrong.

In practice

A Danish recruitment firm finds its CV-screening tool counts as high-risk, so before 2 December 2027 it must document the system, keep logs, test for unfairness and make sure a person can override it.

Why it matters

As the first broad AI law, it reaches organisations that build, sell or use AI in the EU, in stages - bans from February 2025, general-purpose model rules from August 2025, openness duties from August 2026, most high-risk rules from December 2027 (August 2028 for AI in products). Fines reach 7% of global turnover.

GDPR

Compliance & regulation

The EU law that protects personal data and gives people rights over how it is used.

Formal

Regulation (EU) 2016/679, applying directly in every member state since 25 May 2018, which sets principles, legal grounds, rights and security duties for processing data about identifiable people, with fines of up to 20 million euro or 4% of global turnover.

In plain English

Information about you is treated as yours - others may borrow it only for a fair reason, must look after it and must tell you what they do with it.

In practice

When a laptop holding customer lists is stolen from the owner's car, a Danish web shop has 72 hours to report the breach to Datatilsynet and must decide whether the customers themselves need to be told.

Why it matters

Before it, data protection rules differed from country to country and were weakly enforced; GDPR gave people the same rights across the EU and made breaking them costly.

Shared connections

Atlas is in beta.