← All articles · Partners
PLENDE

AI in compliance: how to deploy tools without conflicting with GDPR and the AI Act

17.07.2026 AIcomplianceGDPRAI Actdata-protection
This content was prepared with the help of AI.

Companies do not have to give up on AI, but they must implement it in a way that simultaneously meets the requirements of the GDPR and the AI Act. The GDPR protects personal data, while the AI Act regulates AI systems themselves - so every use of a chat, assistant, or analytical model must be assessed under both regimes.

1. Inventory first, then decisions

In practice, the biggest risk is not the model itself but the lack of control over where employees paste data. Therefore, the first step should be an inventory of all AI tools used in the company, including private accounts and test integrations.

It is useful to immediately separate uses into two levels: ordinary, such as text creation or document analysis, and sensitive, for example recruitment, employee evaluation, or decisions affecting customers. The latter require special attention because they may fall under high-risk areas indicated by the AI Act.

2. Personal data only with a legal basis and contract

If personal data are sent to a tool, the company must have a legal basis for processing and ensure data minimization, in accordance with the GDPR. In practice, this means not sending full customer databases, identification numbers, or employee data to public tools unless there is a clear need.

Contracts with providers are also key for business solutions. Sources emphasize using corporate accounts or APIs and accepting data processing agreements where the provider processes data on behalf of the company. This is especially important when AI supports customer service, sales, or HR.

3. The AI Act requires transparency and oversight

The AI Act imposes obligations regardless of whether the system processes personal data. Practical requirements include classifying the use, documentation, transparency toward users, and human oversight of the system.

For companies, this means simple procedures are needed: an approved tools policy, anonymization rules, designation of a responsible person, and incident reporting instructions. If an organization uses chatbots or generates synthetic content, a user notice or labeling of the material is also required where the use case demands it.

4. Benefits of well-executed compliance

The biggest business benefit is reducing legal and operational risk before an AI project goes into production. Well-prepared compliance shortens the time to approve new tools, streamlines cooperation with providers, and facilitates internal audits.

FAQ

1. Does every company using AI fall under the GDPR? Yes, if personal data of customers, employees, or contractors are involved in the process.

2. Can public chatbots be used? Yes, but you should not paste sensitive data or personal data into them without a legal basis and contractual controls.

3. Does the AI Act apply only to large companies? No, obligations depend on the use case and risk, not the size of the organization.

4. Where to start implementing AI compliance? Start with an inventory of tools, classification of uses, and checking where personal data go.