Artificial Intelligence
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.AI systems and their implications for data protection
Overview
25 sources · Sep 25, 2026Legal Framework
The AI Act establishes the primary regulatory architecture for artificial intelligence systems in the EU, with data protection obligations layered across both the AI Act itself and the GDPR. The AI Act's definition of an "AI system" is anchored in the system's inferential capability, distinguishing it from simpler software. Recital 12 emphasizes that:
"A key characteristic of AI systems is their capability to infer. This capability to infer refers to the process of obtaining the outputs, such as predictions, content, recommendations, or decisions, which can influence physical and virtual environments"
— AI Act Recital 12
For high-risk AI systems embedded as safety components in products covered by Union harmonisation legislation, manufacturers assume provider obligations under the AI Act, ensuring the embedded system complies with all applicable requirements (AI Act Recital 87). General-purpose AI systems are brought within scope when a general-purpose model is integrated such that the resulting system can serve a variety of purposes (AI Act Recital 100). Cybersecurity obligations for high-risk systems require providers to implement measures against attacks exploiting AI-specific vulnerabilities, including data poisoning and adversarial attacks (AI Act Recital 76).
Where AI systems process personal data, GDPR obligations apply in parallel — including the Article 6 legal basis requirement, Article 35 DPIA obligations, and Article 22 restrictions on solely automated decisions. The EDPB has stressed that a provider's initial risk assessment under the AI Act does not displace the deployer's obligation to conduct a context-specific DPIA under Article 35 GDPR.
Key Developments
The Court of Justice's ruling in Ligue des droits humains established a critical threshold: self-learning AI systems that modify assessment criteria without human intervention are incompatible with the PNR Directive's requirement for "pre-determined" criteria. The Court held that:
The Court further warned that AI opacity may render individual review redundant and deprive data subjects of their right to an effective judicial remedy under Article 47 of the Charter, given that "it might be impossible to understand the reason why a given program arrived at a positive match" (Ligue des droits humains ¶195).
On the enforcement front, the Italian DPA's action against Luka Inc. (Replika chatbot) demonstrates that generative AI systems processing personal data without a valid legal basis face immediate sanction. The Garante found the company could not demonstrate a valid legal basis for processing and imposed a substantial fine (Luka Inc. §1). Dutch courts have also signalled awareness of AI-generated legal submissions, with the Rechtbank Midden-Nederland noting in a 2026 ruling that it could not escape the impression that artificial intelligence had been used in drafting the applicants' filings (Rechtbank Midden-Nederland ¶6).
Status of the Debate
This topic is actively contested. The AI Act's framework is new and its interaction with GDPR obligations — particularly around legal bases for training data, DPIA triggers, and Article 22 automated decision-making — remains unresolved. Courts have begun drawing lines (as in Ligue des droits humains on self-learning systems), but no comprehensive judicial interpretation of the AI Act itself exists yet. DPA enforcement is filling gaps incrementally, as the Luka Inc. decision illustrates. The EDPB's joint opinions advocate for robust registration and transparency obligations, but the scope of provider-versus-deployer responsibility is still being negotiated. Resolution will likely come through CJEU preliminary references on AI Act provisions and further DPA enforcement establishing concrete thresholds.
Practical Guidance
- Establish a valid legal basis before deploying AI: The Luka Inc. enforcement confirms that generative AI systems processing personal data without a demonstrable legal basis face immediate fines. Assess consent validity, legitimate interests balancing, or other GDPR Article 6 grounds before processing begins.
- Conduct a context-specific DPIA for each deployment: Even where the AI Act provider's risk assessment does not classify a system as high-risk, deployers must perform their own GDPR Article 35 DPIA considering the specific use context and data categories involved.
- Maintain human review of AI-generated decisions: Ligue des droits humains establishes that self-learning systems modifying criteria without human intervention violate data protection principles. Implement meaningful human-in-the-loop review for any AI system producing decisions affecting individuals.
- Address AI-specific cybersecurity risks: For high-risk systems, implement measures against data poisoning, adversarial attacks, and membership inference as required by AI Act Recital 76, aligned with GDPR Article 32 security obligations.
- Document transparency and explainability: Given the opacity concerns raised by the CJEU, ensure that AI system outputs can be explained to data subjects exercising their rights under GDPR Articles 15–22, particularly the right to meaningful information about automated decision-making logic.
why this is here
Often, FRT uses components of artificial intelligence (AI) or machine learning (ML).
The document directly discusses AI and ML as components of facial recognition technology, making it a primary source for AI implications.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the bank used an artificial intelligence-driven software solution to automate the evaluation of customers' emotional state
The document explicitly describes the use of AI software in the processing, making this topic central to the case.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 31 Guidance · all 72 Laws · all 81 Literature · all 70 News