Skip to content

4.10 — Compliance: AI Act and GDPR landmarks

This lesson is a question framework, not legal advice. Classification depends on the system, its purpose, affected people and your organisation’s role.

  • Prohibited practices — certain manipulation, social scoring and emotion-recognition uses are banned, subject to the regulation’s details and exceptions.
  • High-risk systems — some uses in recruitment, education, credit or essential services may require risk management, documentation, logging and human oversight.
  • Transparency duties — depending on the case, people may need to know they are interacting with AI or viewing generated or manipulated content.
  • Other uses — these are not “law-free”: GDPR, labour, consumer, copyright, contract and sector rules may still apply.

As of July 19, 2026, the European Commission states that prohibited-practice and AI-literacy rules have applied since February 2025, while governance and general-purpose AI rules have applied since August 2025. Following the political agreement on the AI Omnibus, some high-risk rules are announced for December 2, 2027 and August 2, 2028, depending on category.

Always check the European Commission’s official AI regulatory framework.

Document the purpose and legal basis, data minimisation and retention, processors and transfers, security and rights, and whether a data-protection impact assessment is required. The practical rule is not “never send personal data to a model”, but minimise, authorise, protect, contract and document.

Summary

  • Classify a real use, not an “agent” or “chatbot” label.
  • AI Act and GDPR can apply together with sector rules.
  • Check official sources before each decision; this page is not legal advice.
How would you rate this lesson?
📝 My note

A training byBaxIA