The GDPR and AI do not conflict with the AI Act. The two frameworks apply together. The GDPR applies as soon as an AI system processes personal data, both during training and use. The AI Act regulates the system itself according to its risk level and the organisation’s role, whether provider or deployer. For data teams, this means maintaining two separate sets of documentation, a record of processing activities and an inventory of AI systems.
The issue of GDPR and AI is therefore not limited to choosing a secure tool. For IT Departments, data managers and DPOs, the challenge is to connect the two perspectives. Teams need to know which data is used, at which stage, with which AI provider and for which business decision.
Why the GDPR still applies to AI projects
The GDPR applies to the collection, preparation, training and use of personal data by an AI system. The CNIL includes training data, models that may memorise information and data submitted through prompts within this scope.
A data team must define the purpose and legal basis of the project, assess whether the data is relevant, apply data minimisation and inform the people concerned. The CNIL’s guidance on artificial intelligence also recommends reviewing the source of the data and the risk of memorisation. Data that is accessible online is not automatically free to reuse, and a public dataset may still be covered by rights or by the GDPR.
These requirements are best addressed upstream, when the organisation structures its GDPR-compliant data governance, rather than at the time of production deployment.
What the AI Act adds to AI system governance
The AI Act distinguishes between prohibited practices, high-risk AI systems, uses subject to AI transparency obligations and minimal-risk systems. Tools used in employment, recruitment or workforce management may qualify as high risk depending on their actual function. Chatbots and certain AI-generated content are subject to transparency obligations.
The key issue for an IT Department is the classification of the organisation’s role. A company that integrates an existing model into its own product may become a provider under the regulation, even if it considers itself a simple user. This classification determines the scope of the required technical documentation, risk management system and human oversight. The method used to classify high-risk AI systems should therefore be defined before any budget decision.
What has recently changed regarding GDPR and AI
Regulatory developments require organisations to monitor the AI Act timetable. The CNIL regularly updates its resources on artificial intelligence. The 2026 amending regulation, set out in the text published on EUR-Lex, has also changed the timetable for certain obligations. The European Commission provides further information on the AI transparency obligations applicable from 2 August 2026.
Three other texts structure current practice and should be reviewed directly. The CNIL recommendations on AI cover legal basis, legitimate interest and information requirements for learning projects. The EDPB opinion on AI models and personal data addresses whether a trained model can genuinely be considered anonymous. The Code of Practice applicable to general-purpose AI models sets expectations for providers’ documentary transparency.
The applicable deadlines depend on the type of system, the organisation’s role and the transitional provisions. A quarterly regulatory watch shared by the DPO, Legal and IT Department should be considered the minimum operational standard.
What are the differences between the GDPR and the AI Act for data teams?
The GDPR record of processing activities and the AI systems inventory can be connected, but they do not answer the same question. The GDPR record starts with personal data, purposes and processing activities. The AI inventory describes AI systems, their providers, their functions and their risks.
The GDPR assesses whether processing is lawful, necessary and proportionate. The AI Act focuses on the system, its use, its risk level and the organisation’s role as provider or deployer of an AI solution.
The deliverables therefore differ. The GDPR may require a record, information for individuals, a data protection impact assessment, or DPIA, and contractual clauses. The AI Act adds system classification, technical documentation, traceability, AI transparency and demonstrable human oversight. For an IT Department, the GDPR record can therefore never serve as complete AI documentation on its own.
What should data teams do now?
Inventory systems and classify the data
List internally developed tools, AI components integrated into business software and services used spontaneously by employees. The AI systems inventory should specify the provider, purpose, input and output data and the system’s level of autonomy.
Then identify the personal data, sensitive data and confidential data involved. A text-generation tool does not present the same issues as a candidate-scoring tool.
Document the controls
AI documentation explains how data is selected, cleaned, retained and protected. It specifies the tests performed, the biases examined, the incidents monitored and the conditions for human oversight. This traceability facilitates discussions between IT, the DPO, business teams, Procurement and the provider, and it is the evidence that will be requested in the event of an audit. Details of the expected deliverables are developed in our guide on AI system documentation and human oversight.
Manage providers and deployment
Contracts must specify the roles, data flows, AI security measures, any use of data for training, subsequent subprocessors and reversibility. To scope a project or strengthen a team, companies can consult the Data Science & AI expertise available through LittleBig Connection.
Conclusion
The GDPR governs data and processing activities. The AI Act adds governance of AI systems based on their use and risk level. Data teams must therefore inventory tools, classify data, document controls and manage providers through a single AI governance approach.
When internal skills are not available, Data Science & AI expertise can help scope an audit or a compliance roadmap.
Applicable rules vary depending on the system, the organisation’s role and the project. Each situation should be reviewed with the relevant DPO, Legal, Procurement and Security teams.


