# Artificial Intelligence — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/ai
> Sources are cited per item. Verify against the official texts before relying on them.

AI systems and their implications for data protection

## Overview

## Legal Framework

The AI Act (Regulation (EU) 2024/1689) establishes the primary regulatory architecture for artificial intelligence in the Union. [Article 1](/laws/ai-act/art-1) sets out the Regulation's dual mandate: fostering innovation while safeguarding fundamental rights. As the provision states:

> "improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter"
> — [AI Act Art. 1(1)](/laws/ai-act/art-1#par-1)

The Regulation's material scope is broad. [Article 2](/laws/ai-act/art-2) applies to providers placing AI systems on the market, deployers established in the Union, and even third-country providers whose output is used within the Union. It distinguishes between prohibited practices, high-risk systems subject to detailed requirements (Chapter III, Section 2), and systems subject to transparency obligations. [Article 108](/laws/ai-act/art-108) integrates AI Act requirements into sectoral legislation such as Regulation (EU) 2018/1139, ensuring that AI systems functioning as safety components in aviation are assessed against both frameworks. [Article 100](/laws/ai-act/art-100) empowers the European Data Protection Supervisor to impose administrative fines on Union institutions, with criteria including the nature and gravity of the infringement, the purpose of the AI system, and the number of affected persons.

Where AI processes personal data, the GDPR remains the baseline. The AI Act does not displace GDPR obligations but layers additional requirements on top, particularly for high-risk systems involving profiling, automated decision-making, and large-scale data collection.

## Key Developments

The Court of Justice has begun delineating the boundaries of AI use in data-processing contexts. In *Ligue des droits humains* (C-817/19), the Grand Chamber addressed whether self-learning AI could be used under the PNR Directive for assessing passenger data. The Court held that the requirement for "pre-determined" criteria:

The Court further warned that AI opacity undermines effective judicial remedies:

> "given the opacity which characterises the way in which artificial intelligence technology works, it might be impossible to understand the reason why a given program arrived at a positive match"
> — [Ligue des droits humains, ¶195](/posts/132311#seg-195)

In *Latombe v Commission* (T-553/23), the General Court examined whether rapid AI development rendered an earlier adequacy study obsolete. The Court found the applicant had adduced no evidence that organisations had adopted wholly automated decisions post-study, nor explained why AI development made the study irrelevant — signalling that litigants must substantiate claims about AI's impact with concrete evidence rather than general assertions about technological progress.

At enforcement level, the Italian Garante has already acted against AI systems: a €158,000 fine against Character.AI (a generative AI platform) and a €55,000 fine against the Agency for Digital Italy for an AI-related processing failure. These signal that DPAs are not waiting for full AI Act implementation to act under existing GDPR powers.

## Status of the Debate

This topic is actively contested in court. The boundaries between permissible automated processing and prohibited AI-driven decision-making are being fought over in real cases. *Latombe* shows courts demanding evidentiary rigour from challengers, while *Ligue des droits humains* establishes firm limits on self-learning systems in regulated contexts. The AI Act's high-risk classification thresholds and their interplay with GDPR Article 22 have not yet been tested before the CJEU. Resolution will likely come through preliminary references on whether AI Act conformity creates a presumption of GDPR compliance for automated decisions — or whether the two regimes impose independent, cumulative obligations.

## Practical Guidance

- **Classify before deploying.** Determine whether your AI system qualifies as high-risk under [Article 6](/laws/ai-act/art-2) of the AI Act; high-risk classification triggers conformity assessments, risk management systems, and human oversight obligations that overlap with GDPR accountability requirements.

- **Maintain human review of automated decisions.** *Ligue des droits humains* establishes that self-learning systems operating without human intervention may violate both the PNR Directive and, by analogy, GDPR Article 22. Ensure that assessment criteria remain fixed and reviewable.

- **Document the rationale of AI outputs.** The Court's concern about opacity means controllers must be able to explain why an AI system produced a given result. Technical documentation and logging are not merely AI Act formalities — they are the evidentiary basis for defending GDPR lawfulness.

- **Substantiate AI-related claims with evidence.** *Latombe* demonstrates that courts will not accept general assertions about AI's rapid development as substitutes for proof. When arguing that AI changes the risk landscape, produce specific evidence of actual processing practices.

- **Monitor DPA enforcement trends.** The Italian Garante's actions against Character.AI and AgID confirm that regulators will enforce under existing data protection law before AI Act provisions fully apply. Conduct GDPR DPIAs for any AI deployment now.

## Legislation (full text of key provisions)

### Establishment and structure of the European Artificial Intelligence Board

*Source: AI Act, aiact-art-65-en, 2024-06-12 — https://overview.legal/posts/93036*

### Amendment to Regulation (EU) No 168/2013

*Source: AI Act, aiact-art-104-en, 2024-06-12 — https://overview.legal/posts/93611*

In Article 22(5) of Regulation (EU) No 168/2013, the following subparagraph is added:‘When adopting delegated acts pursuant to the first subparagraph concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Regulation (EC) No 300/2008

*Source: AI Act, aiact-art-102-en, 2024-06-12 — https://overview.legal/posts/93607*

In Article 4(3) of Regulation (EC) No 300/2008, the following subparagraph is added:‘When adopting detailed measures related to technical specifications and procedures for approval and use of security equipment concerning Artificial Intelligence systems within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Directive (EU) 2020/1828

*Source: AI Act, aiact-art-110-en, 2024-06-12 — https://overview.legal/posts/93629*

In Annex I to Directive (EU) 2020/1828 of the European Parliament and of the Council (58), the following point is added:‘(68)Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj).’.

### Amendment to Regulation (EU) 2019/2144

*Source: AI Act, aiact-art-109-en, 2024-06-12 — https://overview.legal/posts/93627*

In Article 11 of Regulation (EU) 2019/2144, the following paragraph is added:‘3. When adopting the implementing acts pursuant to paragraph 2, concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Regulation (EU) No 167/2013

*Source: AI Act, aiact-art-103-en, 2024-06-12 — https://overview.legal/posts/93609*

In Article 17(5) of Regulation (EU) No 167/2013, the following subparagraph is added:‘When adopting delegated acts pursuant to the first subparagraph concerning artificial intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Regulation (EU) 2018/858

*Source: AI Act, aiact-art-107-en, 2024-06-12 — https://overview.legal/posts/93617*

In Article 5 of Regulation (EU) 2018/858 the following paragraph is added:‘4. When adopting delegated acts pursuant to paragraph 3 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Directive (EU) 2016/797

*Source: AI Act, aiact-art-106-en, 2024-06-12 — https://overview.legal/posts/93615*

In Article 5 of Directive (EU) 2016/797, the following paragraph is added:‘12. When adopting delegated acts pursuant to paragraph 1 and implementing acts pursuant to paragraph 11 concerning Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Directive 2014/90/EU

*Source: AI Act, aiact-art-105-en, 2024-06-12 — https://overview.legal/posts/93613*

In Article 8 of Directive 2014/90/EU, the following paragraph is added:‘5. For Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), when carrying out its activities pursuant to paragraph 1 and when adopting technical specifications and testing standards in accordance with paragraphs 2 and 3, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation.

### Recital 12 — AI system definition and characteristics

*Source: AI Act, aiact-rec-12-en, 2024-06-12 — https://overview.legal/posts/93706*

The notion of ‘AI system’ in this Regulation should be clearly defined and should be closely aligned with the work of international organisations working on AI to ensure legal certainty, facilitate international convergence and wide acceptance, while providing the flexibility to accommodate the rapid technological developments in this field. Moreover, the definition should be based on key characteristics of AI systems that distinguish it from simpler traditional software systems or programming approaches and should not cover systems that are based on the rules defined solely by natural persons to automatically execute operations. A key characteristic of AI systems is their capability to infer. This capability to infer refers to the process of obtaining the outputs, such as predictions, content, recommendations, or decisions, which can influence physical and virtual environments, and to a capability of AI systems to derive models or algorithms, or both, from inputs or data. The techniques that enable inference while building an AI system include machine learning approaches that learn from data how to achieve certain objectives, and logic- and knowledge-based approaches that infer from encoded knowledge or symbolic representation of the task to be solved. The capacity of an AI system to infer transcends basic data processing by enabling learning, reasoning or modelling. The term ‘machine-based’ refers to the fact that AI systems run on machines. The reference to explicit or implicit objectives underscores that AI systems can operate according to explicit defined objectives or to implicit objectives. The objectives of the AI system may be different from the intended purpose of the AI system in a specific context. For the purposes of this Regulation, environments should be understood to be the contexts in which the AI systems operate, whereas outputs generated by the AI system reflect different functions performed by AI systems and include predictions, content, recommendations or decisions. AI systems are designed to operate with varying levels of autonomy, meaning that they have some degree of independence of actions from human involvement and of capabilities to operate without human intervention. The adaptiveness that an AI system could exhibit after deployment, refers to self-learning capabilities, allowing the system to change while in use. AI systems can be used on a stand-alone basis or as a component of a product, irrespective of whether the system is physically integrated into the product (embedded) or serves the functionality of the product without being integrated therein (non-embedded).

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

### Report of the work undertaken by the ChatGPT Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-chatgpt-taskforce-en, 2024-05-24 — https://overview.legal/posts/125752 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-chatgpt-taskforce_en*

Report of the work undertaken by the ChatGPT Taskforce 23 May 2024 Final 2 Final 3 D ISCLAIMER The positions presented in this document result from the coordination of the members of the ChatGPT taskforce with a view to handling investigations regarding the service ChatGPT provided by the US based company OpenAI OpCo, LLC . They reflect the common denominator agreed by the S upervisory A uthorities in their interpretation of the applicable provisions of the GDPR in relation to the matters that…

### SPE Programma - AI Privacy Risks & Mitigations Large Language Models (LLMs) (Isabel BARBERÁ)

*Source: EDPB, ai-privacy-risks-and-mitigations-in-llms, 2025-04-21 — https://overview.legal/posts/50754 — original: https://edpb.europa.eu/system/files/2025-04/ai-privacy-risks-and-mitigations-in-llms.pdf*

"The AI Privacy Risks & Mitigations Large Language Models (LLMs) report puts forward a comprehensive risk management methodology for LLM systems with a number of practical mitigation measures for common privacy risks in LLM systems. In addition, the report provides use cases examples on the appli...

### Statement on the Digital Services Package and Data Strategy

*Source: EDPB, statement-on-the-digital-services-package-and-data-en, 2021-11-18 — https://overview.legal/posts/125982 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-digital-services-package-and-data_en*

1 Adopted Statement on the D igital Services Package and Data Strategy Adopted on 18 November 2021 The European Data Protection Board has adopted the following statement: Since November 2020 , the European Commission has presented several legislative proposals as part of its digital and data strategies, most notably the Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Regulation on a European appr oach for A rtificial I ntelligence (AIR). A fifth…

### EDPB Annual Report 2021

*Source: EDPB, edpb-annual-report-2021-en, 2022-05-12 — https://overview.legal/posts/125941 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2021_en*

Enhancing the depth and breadth of data protection 2 EDPB Annual Report 2021 2 ENHANCING THE DEPTH AND BREADTH OF DATA PROTECTION An Executive Summary of this report, which provides an overview of key EDPB activities in 2021, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. 3 EDPB Annual Report 2021 3 GLOSSARY 7 FOREWORD 10 2021 - HIGHLIGHTS 13 3.1. STRATEGY 2021-2023 AND WORK PROGRAMME 2021-2022 13 3.2. EDPB OPINIONS ON DRAFT UK ADEQUACY…

### EDPB Strategy 2024-2027

*Source: EDPB, edpb-strategy-2024-2027-en, 2024-04-18 — https://overview.legal/posts/125760 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-strategy-2024-2027_en*

The mission and legal task of the European Data Protection Board (EDPB) is to ensure the consistent application of EU data protection rules and to promote effective cooperation among data protection authorities throughout the European Economic Area (EEA). Since their entries into application in 2018, the General Data Protection Regulation (GDPR) and the Law Enforcement Directive (LED) have strengthened, modernised and harmonised data protection across the European Economic Area (EEA). Awareness…

## Enforcement decisions

### Italian DPA finds GDPR applies to US-based Character.AI service

*Source: Garante per la protezione dei dati personali (Italy), 2026-07-03 — https://overview.legal/posts/108999 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_487/2026*

Facts — Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to create and interact through chat with virtual characters that already exist or are created at the moment. The controller made this available to data subjects in Italian, and had a specific version for children. The DPA initiated an ex-officio investigation in 2024. The DPA requested information related to the LLM models used by the controller, the provision of the service, and data transfers. The controller provided a DPIA, and stated that it introduced an age verification system that required data subjects to register their date of birth. In 2025, the controller announced it would prevent underage data subjects from accessing open chat rooms, and would begin processing personal data of data subjects in the EEA to post-train its generative AI systems. Holding — The DPA first clarified that the GDPR is applicable even if the controller was established outside of the EU, in accordance with Article 3(2) GDPR. The DPA took into account the fact that the service was available in Italy and in Italian, as well as the privacy policy also applying to EEA residents. Given that the controller did not have an establishment in the EU, the one-stop-shop mechanism did not apply and the DPA was competent. The DPA found a violation of Articles 12(1), 13(1) and (2), and 14(1) and (2) GDPR. The DPA considered that the controller had failed to meet its information obligations. In terms of the controller’s privacy policy, the DPA considered that the controller had not provided data subjects’ with clear information regarding its processing activities, data transfers, or data subjects’ right to object and opt out. In addition, the controller failed to designate a representative in the EU, and included misleading and inaccurate statements on the processing of personal data for purposes of post-training LLMs for the service. However, the DPA also took into consideration that the controller had updated its privacy policy to make its language clearer. In terms of its pre-training activities, the DPA stated that the controller had failed to provide adequate information and therefore violated Articles 14(1) and (2) GDPR. The DPA dismissed the controller’s argument that it did not have the obligation to provide this information due to the data being collected by third parties from open sources. The DPA stated that the controller had the obligation to verify whether personal data was present. In addition, the exemption under Article 14(5)(b) GDPR does not exempt the controller from having the obligation to implement appropriate measures to protect data subjects’ rights. However, the DPA did not find a violation of Articles 21(1) and (4). The DPA referred to the EDPB opinion on processing personal data in relation to AI systems. The EDPB recommended controllers to adopt measures for data subjects to exercise their rights, including providing the option to provide data subjects with the option to object unconditionally before the processing takes place. The DPA considered that this opinion went beyond the literal wording of Articles 14 and 21 GDPR. This interpretation could not, in the DPA’s view, be interpreted retroactively to the controller’s processing activities. The DPA found a violation of Articles 24(1) and 25(2) GDPR. The DPA considered that the controller had failed to implement adequate technical and organisational measures to verify data subjects’ age. During its investigations, the DPA found that the controller’s age verification systems were not effective, as they allowed data subjects’ to access the service even after self declaring to be younger than the minimum age limit set by the controller. The DPA also found that the accounts were set to public by default. Therefore, the controller had failed to implement appropriate measures to protect underage data subjects, even if the GDPR does not set a harmonised and binding standard in relation to age verification. The DPA also found a violation of Articles 5(2) and 35 GDPR. Under Article 5(2) GDPR, the controller has the obligation to proactively demonstrate compliance with the GDPR. The DPA stated that a key tool to do this is through data protection impact assessments (DPIAs). Controllers are obliged to carry out a DPIA under Article 35 GDPR if the processing is likely to result in a high to the rights and freedoms of data subjects. The controller failed to do a DPIA on time in relation to providing the service to underage data subjects, as well as in relation to its processing activities for the purpose of pre-training its LLM. The DPA stated that the controller should have done this before launching the service in 2022, as the processing activities had a presumed high risk to freedoms and rights of data subjects (e.g. the use of large scale processing or processing data of vulnerable data subjects). However, the DPA acknowledged that the controller progressively improved its compliance by doing a (late) DPIA and updating it. Finally, the DPA found a violation of Article 27(1) GDPR, as the controller belatedly designated a representative in the EU. The DPA stated that the exemption under Article 27(2) GDPR did not apply. The DPA fined the controller €158,000. The DPA also ordered the controller to bring its privacy policy and storage of personal data for purposes of pre-training its LLM into compliance with the GDPR. The DPA also ordered the controller to implement effective age verification mechanisms.

### EDPS finds Commission infringed purpose limitation and data transfer rules in Microsoft

*Source: EDPS, 2024-03-08 — https://overview.legal/posts/125645 — original: https://gdprhub.eu/index.php?title=EDPS_-_2021-0518*

Facts — Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA. The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by Microsoft include identity and contact data of users (when signing on to the service and when checking the licenses), data generated by the users while using the software and data generated by Microsoft based on the usage of the software. The EDPS found that the processing presents significant risks as it monitors the behaviour of users, combines datasets and uses artificial intelligence. Reference date is the 12th May 2021, the date when the investigation was launched. Some measures were taken meanwhile by the Commission, which were taken into account in the recommendations issued. Holding — The EDPS found infringements with regards to purpose limitation, transfers to a third country and further, unathorised disclosure of personal data. Purpose limitation: The EDPS found that it was not sufficiently defined in the International License Agreement (ILA) which types of personal data are to be processed for which purposes. Instead, there was only a list of purposes stating that Microsoft uses these data for: troubleshooting billing remunerating Microsoft staff, internal reporting and business modelling, financial reporting following the use of the system for own reasons (analytics) to improve the service security risk management protection of intellectual property These stated purposes were considered to be too vague and general pursuant to the Art 29 WP. The Commission and Microsoft could not demonstrate that all these data were necessary and that a less intrusive collection of data would be insufficient to achieve the purposes cited. In addition, some of these purposes were actually not in the interest of the Commission but for purposes of individual to Microsoft (like remuneration of their personnel). In this case, the processor acts as controller; thus, these purposes and the data used for this purposes should have been precisely defined. Also, if data were used for purposes other than for which they were collected, the compatibility of these new purposes with the original ones should have been assessed. As a processor, Microsoft should have processed the personal data on documented instructions by the Commission. This was not ensured as the Commission did not issue sufficiently clear documented instructions to Microsoft. For example, though the Commission gave instructions for analytics and improvement of the service, these instructions were not sufficiently detailed and precise and did not exclusively concern uses of data for the purposes of the controller. Some instructions were given orally, but this was not enabled by the ILA and the oral instructions were not documented. The Commission did not assess whether it is necessary and proportionate to transmit data to Microsoft Ireland and its sub-processors. Further details of this infringement are given under the part on further unauthorised disclosure or personal data. Transfer to third countries : The Commission transferred personal data to Microsoft, a company established in the US. This raises questions about adequacy for such transfers to a third country. After the reference date, the Commission adopted the Transatlantic Data Privacy Framework (TDPF), which is an adequacy decision in respect of recipients in the US who register under this framework. The EDPS found that even when the software and data storage is property of Microsoft, it is directly transferred to these subcontractors and cannot therefore be covered by the TDPF to Microsoft US and onward transfer from Microsoft US to other subcontractors under SCCs. The EDPS found that in was not clearly specified in the ILA what types of personal data can be transferred to which recipients in which third country. The Commission also did not appraise the transfers and therefore could not determine whether any supplementary measures are necessary. In addition, the Commission should have performed a data transfer impact assessment and (as there are no SCCs applicable by EUIs as exporters) should have submitted the DPAs with these processors or subprocessors in third countries to the EDPS for approval. Because it failed to do this, the Commission did not implement effective supplementary measures for these transfers. Another issue was that the “EU storage guarantee” offered by Microsoft did not cover all types of data. Some data may be accessible to recipients in third countries. The “EU Data Boundary” also has numerous exceptions and exclusions which cover customer data, service generated data, diagnostic data and professional services data. Further unauthorised disclosure or personal data: A specific reference was made to Article 9 Regulation (EU) 2018/1725, which concerns transmission of personal data by EU institutions to recipients established in the EU. According to the EDPS, this article is also applicable to transmission of personal data to processors of EUIs. Therefore all transmission of personal data should be in the public interest and if the data subject’s legitimate interests may be prejudiced, the controller has to weigh the competing interests and establish that it is proportionate to transmit the personal data. The purpose of management and functioning of the Commission, use of products the staff is familiar with etc. was not found to be the purpose of processing of the personal data by MS. As long as the purposes are not specified, specific and explicit, it is not possible to do this balancing. In addition, the EDPS found that the Commission did not ensure that transfers take place “solely to allow tasks within the competence of the controller to be carried out”. The EDPS determined that organisational and contractual measures to restrict/prevent access of third country authorities were not sufficient, and that further technical measures are thus necessary. The EDPS also found that the organisational measures applied are only limiting transfers but does not ensure that transfers are protected. Further, the encryption is only found to be an adequate measure if the controller is in control of the encryption key. In this case, customers control the keys, but Microsoft has access to the encryption key, and thus, even when law does not oblige it to decrypt the data on an authority request, it may do it voluntarily. Also, the ILA does not detail encryption of data other than “customer data”, i.e. diagnostic data, service generated data or professional services data. The contract also enabled the processor not to notify the Commission about a request of disclosure also when EU or Member State law did not prohibit this notification and enabled recipients in third countries not to notify requests for disclosure also when the law prohibiting it did not constitute a necessary and proportionate measure in a democratic society respecting the essence of the fundamental rights and freedoms recognised by the Charter.

### Luka Inc.: Non-compliance with general data processing principles

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/48726 — original: https://www.enforcementtracker.com/ETid-2611*

The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI system, specifically an LLM model, that is constantly fed and improved by user interactions. Replika is intended to be a 'virtual companion' that improves users' moods and emotional well-being by helping them understand their own psyche. Replika can be set up as a friend, therapist, romantic partner, or mentor. The controll

### Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful

*Source: Garante per la protezione dei dati personali (Italy), 2026-05-28 — https://overview.legal/posts/122875 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_419/2026*

Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the AI Act. The case revolves around two public online indexes of certified email addresses: the INI-PEC and the INAD. INI-PEC is the older of the two indexes and includes, among others, the email addressess of professionals (the data subjects). INAD was created by AgID in 2023 as provided by Italian law and functions as an index of “digital domiciles” (where data subjects are supposed to get certain important communications) for both professionals and other owners of a digital email address. Shortly after setting up the INAD index, AgID automatically included the addresses of professionals from the old INI-PEC index. As a result, the addresses automatically became the digital domicile for communications not related to the professional lives of the data subjects. Data subjects were given the option to opt-out of the inclusion in the INAD index. Some data subjects complained that this processing severely infringed on their privacy. As the DPA’s decision explains, it is not uncommon for professionals to give co-workers access to their professional email addresses, on the assumption that they will only be used for strictly professional communications. When the addressess became digital domiciles, third parties (such as public bodies) started using them for communications unrelated to the data subjects' personal lives - which occasionally led to unintended data disclosures. The data subjects also claimed that the controller had not informed them about the processing, which prevented them from opting out in a timely fashion. Holding — The investigation — On the duty of information — First of all, the DPA clarified that by including email addresses in the INAD index, the controller further processed personal data for a new purpose, incompatible with the original purpose of the processing (i.e.: the inclusion of email addresses in the older index). With regards to the duty of information, the controller pointed out that it contacted professional orders to inform them about the creation of the INAD index. In the context of these communications, the controller asked professional orders to inform the data subjects about this processing of personal data and about their right to opt out. The controller stated that it did not directly contact the data subjects via their email addresses, as it feared that its emails would have been mistaken as phishing or scams . The controller later launched a more effective information campaign with the help of other government bodies; however, this campaign only took place in 2025 - two years after addresses where included in the INAD index. On the controller’s identity — The DPA’s investigation also focused on a second issue, relative to the authentication procedure for digital domiciles: for a long time, a company (InfoCamere S.c.p.a.) was erroneously listed as a service provider for the INAD index. During the investigation, the controller confirmed that InfoCamere had no role in the processing of personal data. The controller also stated that it had contacted the actual service provider in order to correct the error and that the provider had done so with great delay. The DPA's conclusion — The DPA held that until 2025, the controller had failed to inform the data subjects about the inclusion of their email address in the INAD index, in violation of Articles 5(1)(a), 5(1)(b), 5(2), 12, 14 and 25 GDPR. On these grounds, the DPA fined the controller €55,000. With regards to the erroneous indication of the service provider in the authentication screen, the DPA found that the mistake was isolated and that overall, the information provided during the procedure was still sufficient to clarify that AgID was the controller. On these grounds, the DPA found that the mistake did not, in and of itself, constitute a violation of the GDPR.

### Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking.

*Source: Italian Data Protection Authority (Garante), 2025-04-10 — https://overview.legal/posts/52327*

De Italiaanse gegevensbeschermingsautoriteit heeft Luka Inc. een boete van 5.000.000 euro opgelegd. Het bedrijf heeft een chatbot genaamd Replika ontwikkeld, met een tekst- en spraakinterface. Deze chatbot is gebaseerd op een generatief AI-systeem, specifiek een LLM-model, dat voortdurend wordt aangevuld en verbeterd door interacties met gebruikers. Replika is bedoeld als een "virtuele metgezel" die de stemming en het emotionele welzijn van gebruikers verbetert door hen te helpen hun eigen psyche te begrijpen. Replika kan worden ingesteld als een vriend, therapeut, romantische partner of mentor. De controle...

### Budapest Bank Zrt.: Insufficient legal basis for data processing

*Source: Hungarian National Authority for Data Protection and the Freedom of Information (NAIH), 2022-02-08 — https://overview.legal/posts/47359 — original: https://www.enforcementtracker.com/ETid-1244*

The Hungarian DPA (NAIH) has fined Budapest Bank Zrt. EUR 634,000. NAIH reports that the bank used an artificial intelligence-driven software solution to automate the evaluation of customers' emotional state. The speech evaluation system determined which customers needed to be recalled based on the customer's mood. The bank operated the application to prevent complaints and to keep customers. The bank did not inform the data subjects, that the processing of their data serves, among other things,

### AEPD fines El Español for disclosing minor's identity in assault video

*Source: AEPD (Spain), 2026-07-27 — https://overview.legal/posts/184546 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_PS-00304-2024*

Facts — El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video showing both the victim and the assailant, who was a minor. Their image and voice were disclosed without applying techniques to prevent their direct or indirect identification. The controller also published the video through its accounts on two social media platforms. The DPA initiated preliminary investigations ex officio after becoming aware of the dissemination of the video. It ordered the controller, as a precautionary measure, to immediately remove the content from the relevant URLs. The controller subsequently informed the DPA that it had removed the article and prevented access through both external links and its internal search engine. The DPA verified that the video was no longer available through the identified web addresses. The DPA subsequently initiated disciplinary proceedings for a potential infringement of Article 5(1)(c) GDPR. The controller argued that the incident was newsworthy, the video had already gone viral and the publication was protected by freedom of information. It also claimed that the video was necessary to understand the news and that the assailant’s status as a minor should be assessed in light of his apparent maturity and awareness that he was being recorded. Holding — The DPA found that the controller violated the data minimisation principle under Article 5(1)(c) GDPR. The DPA clarified that the proceedings did not concern whether the incident was newsworthy or whether the controller could report on it. Instead, the relevant question was whether publishing the identifiable image and voice of the individuals was necessary and proportionate for that purpose. According to the DPA, freedom of information and the right to data protection are not absolute. Under Article 85 GDPR, they must be reconciled on a case-by-case basis. In this case, the controller could have informed the public about the incident while using technical measures, such as blurring the individuals’ faces or altering the audio, to prevent their identification. Showing the individuals in an identifiable manner was therefore not necessary to achieve the journalistic purpose. The DPA also rejected the argument that the previous virality of the video justified its republication. Each additional publication contributed to the further dissemination of the personal data and amplified the risks and adverse effects for the data subjects. Similarly, the fact that the affected individuals had not submitted a complaint did not prevent the DPA from exercising its supervisory powers ex officio. The DPA gave particular weight to the vulnerability of the victim and to the fact that the assailant was a minor. It held that the best interests and enhanced protection of minors had to be taken into account irrespective of the minor’s alleged maturity or awareness of being recorded. The age at which a minor may consent under Article 7 LOPDGDD did not reduce the controller’s obligation to assess whether the disclosure was necessary. The DPA further noted that, pursuant to Articles 5(2) and 25 GDPR, the controller was required to assess and document the risks of the processing and implement data protection by design and by default. As a professional media organisation regularly processing personal data, the controller was expected to apply a particularly high standard of diligence and to consider less intrusive methods of publication. When determining the sanction, the DPA considered the unrestricted online dissemination of the data, the potentially unlimited audience, the controller’s negligence, the sensitive circumstances surrounding the victim and the minor, and the impact of the infringement on the rights of a minor. It therefore imposed a €20,000 fine. Under Article 58(2)(d) GDPR, the DPA also ordered the controller to demonstrate, within three months after the decision became enforceable, that it had adopted measures to prevent the excessive publication or dissemination of personal data, particularly data concerning minors. It made the earlier precautionary measure definitive and required the permanent removal of the content, while allowing its restricted preservation where necessary as evidence for administrative, police or judicial proceedings.

## Recent developments

### De FRIA voor AI-systemen komt eraan: bereid u voor

*Source: Autoriteit Persoonsgegevens, 2026-08-17 — https://overview.legal/posts/291285 — original: https://autoriteitpersoonsgegevens.nl/actueel/de-fria-voor-ai-systemen-komt-eraan-bereid-u-voor*

Bent u een overheidsorganisatie of een private organisatie die publieke diensten levert? En bent u van plan een AI-systeem met een hoog risico te gaan gebruiken? Of gaat u als publieke of private organisatie een beoordelingssysteem voor financiële risico’s gebruiken? Dan moet u vanaf december 2027 vooraf beoordelen welke gevolgen dit AI-systeem kan hebben voor de grondrechten van mensen. Zo’n beoordeling heet een ‘fundamental rights impact assessment’ (FRIA), oftewel een ‘grondrechteneffectbeoor

### Vanaf 2 augustus wordt duidelijker of het AI is of echt

*Source: Autoriteit Persoonsgegevens, 2026-07-31 — https://overview.legal/posts/184688 — original: https://autoriteitpersoonsgegevens.nl/actueel/vanaf-2-augustus-wordt-duidelijker-of-het-ai-is-of-echt*

De chat met de klantenservice van de webwinkel, dat filmpje op sociale media, de foto op een nieuwssite: vanaf 2 augustus 2026 moet daar in veel gevallen bij staan dat artificiële intelligentie (AI) is gebruikt. Nieuwe Europese regels moeten u helpen om beter te herkennen wat echt is, wat door AI is gemaakt en wanneer u met een AI-systeem communiceert.

### AP helpt ontwikkelaars en organisaties met nieuwe AVG-richtlijnen voor generatieve AI

*Source: Autoriteit Persoonsgegevens, 2026-07-13 — https://overview.legal/posts/96822 — original: https://autoriteitpersoonsgegevens.nl/actueel/ap-helpt-ontwikkelaars-en-organisaties-met-nieuwe-avg-richtlijnen-voor-generatieve-ai*

De Autoriteit Persoonsgegevens (AP) publiceert vandaag 2 nieuwe documenten die organisaties helpen bij de verantwoorde ontwikkeling en inzet van generatieve artificiële intelligentie (AI). Het gaat om een AVG-handreiking voor ontwikkelaars van generatieve AI-modellen en een praktisch hulpmiddel voor organisaties die generatieve AI willen implementeren en gebruiken.

### EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

*Source: European Data Protection Board, 2026-07-08 — https://overview.legal/posts/53905 — original: https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en*

Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies.Understanding anonymous dataThe new EDPB guidelines bring clarity to the notion of anonymous data, taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB o

### noyb survey: only 7% of users want Meta to use their personal data for AI

*Source: noyb - European Center for Digital Rights, 2025-08-07 — https://overview.legal/posts/53144 — original: https://noyb.eu/en/noyb-survey-only-7-users-want-meta-use-their-personal-data-ai*

Artificial Intelligence Meta has recently started using the personal data of Europeans for AI training. Contrary to its GDPR obligations, Meta hasn’t asked for consent in advance. Instead, the company claims to have a ‘legitimate interest’ outweighing the fundamental right to privacy. A key argument in favour of such a ‘legitimate interest’ is the reasonable expectations of users. This begs the question: do people want this to happen? To find out more, noyb has commissioned the Gallup Institute

## Literature

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### The EU Artificial Intelligence (AI) Act: An Introduction

*Source: Global Privacy Law Review, 2024-03-01 — https://overview.legal/posts/132617 — original: https://doi.org/10.54648/gplr2024004*

As part of its digital strategy, the European Commission proposed the world’s first-ever comprehensive legal framework on AI in April 2021. In December 2023, the Council and the Parliament reached a political agreement on the EU’s new Artificial Intelligence Act (AI Act). The AI Act follows a risk-based approach and aims to ensure that AI systems placed on or used in the EU market are safe and respect fundamental rights. The AI Act is expected to become a model for AI governance worldwide in a s

### The challenge of defining artificial intelligence in the EU AI Act

*Source: Journal of Data Protection Privacy, 2023-12-01 — https://overview.legal/posts/132620 — original: https://doi.org/10.69554/qhay8067*

The EU Commission, the EU Council and the EU Parliament have each issued their own versions of the text of a new EU AI Act. Throughout the gestation of the EU AI Act a core and complex question has arisen: how should ‘AI system’ be defined in the EU AI Act? This paper examines the evolution of the definition of ‘AI system’ in the draft EU AI Act. This paper suggests that, in order to achieve the EU’s goals, a definition of ‘AI system’ which is clear and cannot be modified outside the EU legislat

### The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act

*Source: Studies in Law and Justice, 2023-09-01 — https://overview.legal/posts/132567 — original: https://doi.org/10.56397/slj.2023.09.09*

The European Commission released the proposed Regulation on Artificial Intelligence (the EU AI Act) on 21 April 2021, which reflects the EU’s leadership orientation in establishing norms and standards in emerging fields, and also reflects the urgent need for legal unity of the EU as a unified market entity. The Act sets out harmonized rules for the development, placing on the market, and use of AI in the European Union. The ideas of a risk-based approach and experimental governance are of great

## Tools

### EU AI Act Compliance Checker

*Source: Future of Life Institute, 2026-07-17 — https://overview.legal/posts/125619 — original: https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/*

Interactive self-assessment that walks providers, deployers and importers through the AI Act's scoping questions: whether a system is in scope, its risk classification (prohibited / high-risk / limited / minimal), and which obligations and deadlines follow from that classification.

### EU AI Act Explorer

*Source: Future of Life Institute, 2026-07-17 — https://overview.legal/posts/125635 — original: https://artificialintelligenceact.eu/ai-act-explorer/*

Browsable, hyperlinked edition of the AI Act: every article, recital and annex cross-linked, with a search function and plain-language section summaries. The most-used way to navigate the Act's structure while official consolidated versions lag behind.

## Related topics

- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des

---
Generated by overview.legal · https://overview.legal/topics/ai · 2026-08-22
