AI Act meets GDPR: who does what when you buy an AI system
4 min read
When a company adopts an AI system, two pieces of European legislation switch on at once: the GDPR, if personal data are involved (and they almost always are), and the EU AI Act, which has been coming into force in stages since 2025. The most frequent confusion we encounter is not about principles — it is about who must do what: what falls to whoever builds the system and what falls to whoever uses it. Let us bring some order, because this is where liabilities get bought unknowingly.
The two roles under the AI Act: provider and deployer
The AI Act distinguishes the provider (whoever develops the system and places it on the market) from the deployer (whoever uses it under their own authority: you). The distinction matters because the heavy obligations attached to high-risk systems — technical documentation, risk management, CE marking — rest with the provider. But the deployer is no bystander: it must use the system according to the instructions, ensure human oversight by competent personnel, check that input data are relevant, keep logs, and inform the people affected.
And there is the classic trap: if you substantially modify a system, or use it for a high-risk purpose other than the one declared by the manufacturer, or rebrand it under your own name, you become the provider — with all the obligations that entails. Heavily customising a system you have bought is not legally neutral: it is a question to put in writing beforehand, not afterwards.
The two impact assessments: DPIA and FRIA
The GDPR requires a DPIA (data protection impact assessment) when processing poses high risks to individuals — and an AI system that assesses, profiles or decides on people falls within that almost by definition. The AI Act adds, for certain deployers of high-risk systems (public bodies and private entities providing essential services), the FRIA: the fundamental rights impact assessment — not privacy alone, but discrimination, access to services, safeguards.
The operational point that saves you months: the two assessments overlap for the most part, and the legislation itself allows them to be combined. Those who treat them as two separate exercises, handed to two different consultants, pay twice for documents that contradict each other. Those who start from a single inventory — what data, what decisions, on whom, with what human control — produce both from a single analysis.
The timeline: no panic, but no discounts either
As of today (spring 2026), the following are already in force and enforceable: the bans on unacceptable practices and the obligation to provide AI literacy training for staff (since February 2025), and the obligations on general-purpose models (since August 2025). The deadlines for high-risk systems are under discussion in Brussels as part of the simplification package — the practical advice does not change: the preparatory work (mapping systems, roles, registers, training) needs doing regardless, because it is the same whatever the final date turns out to be. Anyone who also falls within the scope of the NIS2 Directive already knows this: the inventory is always the first step.
The savvy deployer’s checklist
- Classify every system: is there AI inside it? Is it high-risk? Who is the provider? (A lot of AI arrives hidden inside vertical software.)
- Get the instructions for use and the declarations of conformity handed over — and read what the provider states you are required to do.
- Appoint human oversight: specific, trained people with real authority to stop the system — not just a name on an org chart.
- Integrate the DPIA and FRIA into a single analysis, starting from the data.
- Document the training: it is the obligation already in force that costs least to fulfil and most to ignore.
Compliance done this way is not a dead cost: it is the same work of putting data and processes in order from which the projects that actually work take off.
Do you need to classify the systems you already have, or the ones you are about to buy? Half an hour with one of our experts for a first map of roles and obligations.