
The General Data Protection Regulation (GDPR) reshaped how organizations approach personal data and remains a core obligation for data teams. The EU AI Act adds another regulatory layer covering the development, deployment, and use of artificial intelligence systems.
The AI Act entered into force in 2024 and applies in stages. Prohibited AI practices and AI-literacy obligations began applying in February 2025. Governance rules and obligations for general-purpose AI models followed in August 2025, while transparency requirements took effect in August 2026. Following the AI Omnibus amendments, requirements for high-risk use cases listed in Annex III apply from 2 December 2027, while requirements for high-risk systems embedded in regulated products under Annex I apply from 2 August 2028.
Together, GDPR and the AI Act create overlapping obligations across data collection, processing, model development, deployment, and automated decision-making. Data teams should treat them as connected architectural and governance requirements rather than isolated compliance projects