Artificial Intelligence
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.AI systems and their implications for data protection
Overview
22 sources · Jul 23, 2026Legal Framework
The AI Act (Regulation (EU) 2024/1689) establishes the primary regulatory architecture for artificial intelligence in the Union. Article 1 sets out the Regulation's dual mandate: fostering innovation while safeguarding fundamental rights. As the provision states:
"improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter"
— AI Act Art. 1(1)
The Regulation's material scope is broad. Article 2 applies to providers placing AI systems on the market, deployers established in the Union, and even third-country providers whose output is used within the Union. It distinguishes between prohibited practices, high-risk systems subject to detailed requirements (Chapter III, Section 2), and systems subject to transparency obligations. Article 108 integrates AI Act requirements into sectoral legislation such as Regulation (EU) 2018/1139, ensuring that AI systems functioning as safety components in aviation are assessed against both frameworks. Article 100 empowers the European Data Protection Supervisor to impose administrative fines on Union institutions, with criteria including the nature and gravity of the infringement, the purpose of the AI system, and the number of affected persons.
Where AI processes personal data, the GDPR remains the baseline. The AI Act does not displace GDPR obligations but layers additional requirements on top, particularly for high-risk systems involving profiling, automated decision-making, and large-scale data collection.
Key Developments
The Court of Justice has begun delineating the boundaries of AI use in data-processing contexts. In Ligue des droits humains (C-817/19), the Grand Chamber addressed whether self-learning AI could be used under the PNR Directive for assessing passenger data. The Court held that the requirement for "pre-determined" criteria:
The Court further warned that AI opacity undermines effective judicial remedies:
"given the opacity which characterises the way in which artificial intelligence technology works, it might be impossible to understand the reason why a given program arrived at a positive match"
— Ligue des droits humains, ¶195
In Latombe v Commission (T-553/23), the General Court examined whether rapid AI development rendered an earlier adequacy study obsolete. The Court found the applicant had adduced no evidence that organisations had adopted wholly automated decisions post-study, nor explained why AI development made the study irrelevant — signalling that litigants must substantiate claims about AI's impact with concrete evidence rather than general assertions about technological progress.
At enforcement level, the Italian Garante has already acted against AI systems: a €158,000 fine against Character.AI (a generative AI platform) and a €55,000 fine against the Agency for Digital Italy for an AI-related processing failure. These signal that DPAs are not waiting for full AI Act implementation to act under existing GDPR powers.
Status of the Debate
This topic is actively contested in court. The boundaries between permissible automated processing and prohibited AI-driven decision-making are being fought over in real cases. Latombe shows courts demanding evidentiary rigour from challengers, while Ligue des droits humains establishes firm limits on self-learning systems in regulated contexts. The AI Act's high-risk classification thresholds and their interplay with GDPR Article 22 have not yet been tested before the CJEU. Resolution will likely come through preliminary references on whether AI Act conformity creates a presumption of GDPR compliance for automated decisions — or whether the two regimes impose independent, cumulative obligations.
Practical Guidance
Classify before deploying. Determine whether your AI system qualifies as high-risk under Article 6 of the AI Act; high-risk classification triggers conformity assessments, risk management systems, and human oversight obligations that overlap with GDPR accountability requirements.
Maintain human review of automated decisions. Ligue des droits humains establishes that self-learning systems operating without human intervention may violate both the PNR Directive and, by analogy, GDPR Article 22. Ensure that assessment criteria remain fixed and reviewable.
Document the rationale of AI outputs. The Court's concern about opacity means controllers must be able to explain why an AI system produced a given result. Technical documentation and logging are not merely AI Act formalities — they are the evidentiary basis for defending GDPR lawfulness.
Substantiate AI-related claims with evidence. Latombe demonstrates that courts will not accept general assertions about AI's rapid development as substitutes for proof. When arguing that AI changes the risk landscape, produce specific evidence of actual processing practices.
Monitor DPA enforcement trends. The Italian Garante's actions against Character.AI and AgID confirm that regulators will enforce under existing data protection law before AI Act provisions fully apply. Conduct GDPR DPIAs for any AI deployment now.