GDPR × AI
Most AI enforcement in Europe to date has come through GDPR, not the AI Act. Training-data legality, model 'personal data memorization' questions and automated-decision rights are actively litigated — a compliance surface that predates and outlasts AI-specific law.
What it is
The EU's data-protection regime remains a primary AI constraint: legal bases for training data, automated-decision rights (Art. 22), and DPIAs for high-risk processing. EDPB opinions and national DPA enforcement have targeted major model providers' training practices.
Who is affected
Most AI enforcement in Europe to date has come through GDPR, not the AI Act. Training-data legality, model 'personal data memorization' questions and automated-decision rights are actively litigated — a compliance surface that predates and outlasts AI-specific law.
Key obligations
- Lawful basis required for personal data in training and inference
- Rights around solely automated decisions with significant effects
- DPIAs for high-risk processing; privacy-by-design obligations
Recent signals
EU AI Act transparency obligations become applicable
Chatbot disclosure, machine-readable AI-content marking and deepfake labeling duties now apply EU-wide; the GPAI Code of Practice enforcement grace period ends the same day.
Digital Omnibus on AI enters into force, delaying high-risk deadlines
Regulation (EU) 2026/1744 pushes high-risk AI Act obligations to Dec 2027 (Annex III) and Aug 2028 (Annex I) and simplifies documentation duties — the EU's first formal AI Act correction.
EU AI Act GPAI model obligations become applicable
General-purpose model providers must maintain technical documentation, publish training-content summaries and comply with EU copyright law; systemic-risk models face safety duties.
EU publishes General-Purpose AI Code of Practice; major labs sign
The voluntary code operationalizes GPAI duties across transparency, copyright and safety — with a one-year enforcement grace period for signatories.
Related instruments
- EUEU AI ActThe world's first comprehensive, risk-based AI law. It bans a set of unacceptable practices (social scoring, manipulative AI, most…
- EUEU Digital OmnibusThe first formal simplification of the AI Act. Adopted July 2026, it delays high-risk obligations to December 2027 (standalone Ann…
- EUGPAI Code of PracticeA voluntary code operationalizing the AI Act's GPAI chapter across transparency, copyright and safety/security. Major model provid…
- EUAI Liability DirectiveThe Commission withdrew its proposed AI Liability Directive in February 2025, citing no foreseeable agreement. Civil liability for…
- USTAKE IT DOWN ActRare bipartisan federal AI statute criminalizing publication of non-consensual intimate images, including AI-generated deepfakes, …
Related reading
- Issue 10The clause is the policyThe world's largest buyer of AI cannot show that its own contracts carry the provisions its own policy requires. That is not an audit failure. It is a diagnosis.
- Issue 05The sovereign-AI trilemmaEvery state pursuing AI sovereignty in 2026 is making the same trade-off — usually without admitting it.