# AI Act and GDPR: cross-obligations, synergies, and differences

> The AI Act and the GDPR apply in parallel and without hierarchy. This comparison details their common and specific obligations, documentary synergies, technical differences, and the role of the CNIL.

- Tags: AI Act RGPD comparaison, obligations croisées IA protection données, synergies AI Act RGPD, FRIA AIPD différences, conformité IA et données personnelles, CNIL AI Act RGPD
- Main keyword: AI Act RGPD comparaison

## Introduction

The AI Act and the GDPR constitute the regulatory foundation for artificial intelligence in Europe. According to Article 2(7) of the AI Act, this regulation applies "without prejudice" to the GDPR, meaning no hierarchy exists between them. As soon as an AI system processes personal data, both texts are applicable in parallel.

Recital 10 of the AI Act highlights the need for close cooperation between AI supervisory authorities and those responsible for data protection. This collaboration aims to avoid duplication, harmonize controls, and ensure the consistency of requirements. In France, the CNIL was designated as the competent authority for the AI Act in February 2026, strengthening the integration of the two regimes.

## Content

## AI Act and GDPR: two frameworks that apply together

For companies, it is relevant to adopt an integrated compliance approach. Maintaining separate processes for each regulation would lead to redundant efforts and additional costs, whereas intelligent pooling allows for optimizing overall compliance and limiting the risks of inconsistency.

## AI Act / GDPR Comparison: obligations, convergences, and divergences

The table below summarizes the main cross-obligations and points of divergence between the AI Act (EU Regulation 2024/1689) and the GDPR (EU Regulation 2016/679), organized by theme.

| Theme | AI Act | GDPR | Common points and differences |
|---|---|---|---|
| **Scope** | Applies to AI systems placed on the market or put into service in the EU, regardless of the provider's place of establishment (Art. 2). | Targets all personal data processing carried out in the EU, or by a controller/processor established in the EU (Art. 3). | An AI system processing personal data falls under both regulations. |
| **Roles and responsibilities** | **Provider**: develops the AI system (Art. 3(3)).<br>**Deployer**: operates the system (Art. 3(4)).<br>**Importer/distributor**: makes available in the EU (Art. 3(5-6)). | **Controller**: determines purposes and means (Art. 4(7)).<br>**Processor**: acts on behalf of the controller (Art. 4(8)). | An actor can be both an AI provider and a GDPR controller. The role depends on the use of data. |
| **Risk management** | **FRIA** mandatory for high-risk AI (Art. 27).<br>Risk assessment for safety, health, fundamental rights.<br>Continuous updating required. | **DPIA** mandatory in case of high risk to rights and freedoms (Art. 35).<br>Prior assessment and necessary updates. | For a high-risk AI processing personal data, the FRIA and DPIA can be merged. |
| **Transparency** | Enhanced transparency (Art. 50).<br>Watermarking for AI-generated/manipulated content (Art. 50(2)).<br>Clear information on interaction with AI (Art. 50(1)). | Right to information (Art. 13, Art. 14).<br>Transparency on automated processing (Art. 13(2)(f)). | Obligations can be grouped into information notices to avoid duplication. |
| **Data subject rights** | Right to an explanation for high-risk AI decisions (Art. 68).<br>Right to contest an automated decision (Art. 68(3)). | Rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection to automated decisions (Art. 22). | Rights complement each other: the AI Act right to explanation enriches the GDPR. |
| **Documentation and records** | Mandatory register for high-risk AI providers/deployers (Art. 49).<br>Detailed technical documentation (Annex IV). | Mandatory record of processing activities (Art. 30).<br>Documentation of breaches (Art. 33(5)). | Registers can be merged for AI processing personal data. |
| **Incidents and breaches** | Notification of serious incidents within 15 days (Art. 73).<br>Includes any impact on health, safety, or fundamental rights. | Notification of data breaches within 72h to the authority (Art. 33) and to individuals if high risk (Art. 34). | An incident can trigger both notifications. A complete AI Act notification can cover the GDPR. |
| **Sanctions** | Up to €35M or 7% of global turnover for prohibited practices (Art. 99(3)).<br>Up to €15M or 3% for other infringements (Art. 99(4)). | Up to €20M or 4% of global turnover for serious violations (Art. 83(5)), €10M or 2% for other infringements (Art. 83(4)). | Sanctions are cumulative: up to €55M or 11% of global turnover in case of double infringement. |

> "The convergence between the AI Act and the GDPR is not a coincidence, but a political will. Both regulations share a common philosophy: regulating technologies to preserve fundamental rights."  
> *Paul Nemitz, Principal Advisor at the European Commission*

## Documentary synergies: optimizing cross-compliance

To streamline compliance, it is possible to group certain documentary obligations between the AI Act and the GDPR. Four major synergies should be prioritized:

### 1. Data governance
Article 10 of the AI Act imposes high standards on training data quality, aligning with the principles of minimization (Art. 5(1)) and privacy by design (Art. 25) of the GDPR. A single documentation can meet both frameworks.

### 2. Risk assessments
FRIA (AI Act) and DPIA (GDPR) are based on similar methodologies. For high-risk AI using personal data, a single integrated assessment is possible, reducing administrative burden.

### 3. Activity registers
The register of AI systems (Art. 49) and the record of processing activities (Art. 30) can be merged. Information specific to AI (categorization, transparency) is added to the GDPR register entries.

### 4. Transparency and information
The transparency requirements of the AI Act (Art. 50) can be integrated into GDPR information notices (Art. 13, Art. 14), allowing for information on AI usage and personal data processing in the same document.

This pooling allows for lightening the compliance burden and ensuring documentary consistency between the two regulations.

## Technical requirements specific to the AI Act

The AI Act introduces technical obligations that have no equivalent in the GDPR. These specific requirements aim to strengthen the robustness, human oversight, and security of AI systems:

### Human oversight
High-risk AI must allow for effective human oversight (Art. 14), with interfaces and deactivation devices. The GDPR does not provide for such measures.

### Robustness and cybersecurity
The AI Act imposes stress tests and dedicated cybersecurity measures (Art. 15), beyond the general requirements of the GDPR (Art. 32).

### Precision and accuracy
AI systems must achieve an appropriate level of precision, robustness, and cybersecurity (Art. 15(1)). The GDPR does not address the technical performance of systems.

### Automatic logging
To ensure traceability, high-risk AI must integrate automatic logging (Art. 12), an obligation absent from the GDPR.

### AI content watermarking
Article 50(2) of the AI Act imposes the marking of content generated or modified by AI to ensure transparency and fight against disinformation, a point not addressed by the GDPR.

These specificities require particular attention during the development and deployment of AI, in addition to obligations related to data protection.

## CNIL: supervisory authority for AI Act and GDPR

In France, the CNIL ensures the supervision of both regulations. Designated as the competent authority for the AI Act in February 2026, it coordinates its actions with ARCOM and the DGCCRF for full coverage.

In March 2026, the CNIL published guidelines clarifying the articulation between the AI Act and the GDPR, including:
- Possibility to merge FRIA and DPIA
- Integration of AI Act transparency obligations into GDPR notices
- Harmonization of incident notifications

Companies can rely on these recommendations and use the tools provided by the CNIL. All resources are accessible at [www.cnil.fr/fr/intelligence-artificielle](https://www.cnil.fr/fr/intelligence-artificielle).

At the European level, coordination is also intensifying: the AI Office, created in 2025, works in conjunction with the European Data Protection Board (EDPB) to ensure homogeneous practices across the entire territory.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/ai-act-et-rgpd-tableau-comparatif-obligations-croisees)
