If your organisation builds, deploys, or relies on AI in hiring, credit scoring, critical infrastructure, or border and law enforcement contexts, August 2, 2026 was a deadline you couldn't miss. That's the date the EU AI Act's obligations for high-risk AI systems became fully enforceable โ€” and it means GDPR is no longer the only data law that can end a bad year for your compliance budget.

For the first time, two separate EU penalty regimes now apply, in parallel, to the same underlying activity: processing personal data through an AI system. Understanding where they overlap, where they diverge, and where they can both hit you at once is the compliance question of the second half of 2026.

What Changed on August 2

High-risk AI systems โ€” as defined in Annex III of the AI Act, covering use cases like recruitment, creditworthiness assessment, critical digital infrastructure management, and border control โ€” must now have, among other things:

Providers were expected to have conformity assessments completed, technical documentation finalised, CE marking affixed, and EU database registration done by the deadline.

If several of those obligations sound familiar, that's because they should. GDPR already required data protection impact assessments, documented risk analysis, transparency to data subjects, and safeguards around automated decision-making. The AI Act doesn't replace any of that โ€” it sits on top of it, with its own separate legal basis, its own documentation requirements, and its own fines.

Where the Two Laws Actually Overlap

The clearest collision points:

Data governance. The AI Act's Article 10 requires governance over training and validation datasets โ€” relevance, representativeness, bias detection. GDPR's data minimisation and accuracy principles (Article 5) already govern the personal data inside those same datasets. A flawed training set can now be a violation under both frameworks simultaneously, assessed by two different tests.

Impact assessments. GDPR requires a Data Protection Impact Assessment (DPIA) for high-risk processing. The AI Act requires a Fundamental Rights Impact Assessment (FRIA) for certain high-risk deployments, particularly by public bodies and in sensitive sectors. These aren't the same document, but they draw on much of the same underlying risk analysis โ€” meaning a poorly scoped DPIA now has a second law waiting to catch what it misses.

Transparency. GDPR Articles 12โ€“14 require clear information to data subjects about processing. The AI Act separately requires providers to give deployers instructions for safe use and information about system accuracy and limitations, and requires that people be told when they're interacting with an AI system. Two transparency regimes, two audiences, two sets of disclosure obligations.

Human oversight and automated decision-making. GDPR Article 22 restricts solely automated decisions with legal or similarly significant effects. The AI Act's human oversight requirement is broader and applies regardless of whether a decision is "solely" automated โ€” meaning a system that clears the GDPR Article 22 bar because a human technically reviews outputs can still fail the AI Act's higher bar for what effective oversight looks like.

The Penalty Math

This is where it gets sharper. The AI Act's Article 99 sets a three-tier structure:

Two penalty regimes, one AI system Two penalty regimes, one AI system Maximum fine ceilings ยท bar length = % of global annual turnover AI Act โ€” prohibited practices (Art. 5) โ‚ฌ35M / 7% GDPR โ€” most serious infringements (Art. 83(5)) โ‚ฌ20M / 4% AI Act โ€” high-risk system violations โ‚ฌ15M / 3% AI Act โ€” misleading info to regulators โ‚ฌ7.5M / 1% EU AI Act (Art. 99) GDPR (Art. 83) Whichever is higher applies โ€” the euro ceiling or the percentage. Turnover means global annual turnover for the preceding financial year.
The AI Act's top tier now sits above GDPR's own maximum, making it the more punitive of the two regimes at its ceiling. The tier that will matter most to ordinary businesses, though, is the middle one โ€” high-risk system violations at โ‚ฌ15M or 3%.

The top tier now exceeds GDPR's own maximum of โ‚ฌ20 million or 4% of global turnover, making the AI Act the more punitive of the two regimes at its ceiling.

Crucially, Article 99(8) includes a "same conduct, one penalty" rule: if a single factual violation breaches both the AI Act and another EU law like GDPR, regulators impose only the higher of the two applicable fines. But that protection is narrower than it sounds. If an AI system violates the AI Act's data governance rules through a biased training set, and separately violates GDPR's accuracy or minimisation principles through how that same data was collected or retained, those are treated as distinct violations โ€” and can be penalised separately.

Legally, this isn't "double jeopardy" in the way many compliance teams assume. It's a determination made violation-by-violation โ€” and the more entangled your AI system's data practices are with GDPR-governed personal data, the more surface area you have for that separation to work against you.

What This Means Practically

The instinct to treat the AI Act and GDPR as two checklists to run in sequence is the most expensive mistake available right now. A few things worth doing instead:

  1. Map your DPIAs and FRIAs against each other rather than commissioning them separately. If a system needs both, the underlying risk analysis should be a shared foundation, not two disconnected exercises that quietly contradict each other. If you don't have a DPIA process at all yet, start there โ€” the FRIA is much harder to build on nothing.
  2. Audit your existing GDPR transparency notices against the AI Act's disclosure requirements. They cover different information, but a notice built only for GDPR compliance is likely to be missing what the AI Act now separately demands โ€” and this arrives at the same time the EDPB has made Articles 12โ€“14 transparency its 2026 coordinated enforcement priority. Both regulators are looking at the same notices this year, for different reasons.
  3. Treat human oversight as a design requirement, not a policy statement. Regulators under both regimes are going to ask for evidence that a human can meaningfully intervene, not just that a human is nominally in the loop. Our AI oversight checklist covers what that evidence looks like in practice.
  4. Get legal and technical documentation teams talking to each other now. The AI Act's technical documentation and logging requirements will increasingly be the evidence base regulators use to evaluate GDPR compliance too, since both hinge on being able to show โ€” not just assert โ€” how a system actually processes personal data.

The Enforcement Backdrop Makes This Urgent, Not Theoretical

This isn't landing in a quiet enforcement environment.

โ‚ฌ7.1B
Cumulative GDPR fines to date
โ‚ฌ600M+
Issued in H1 2026 alone
443
Breach notifications per day
+22%
Year-over-year increase

GDPR fines have already crossed โ‚ฌ7.1 billion cumulatively, with more than โ‚ฌ600 million issued in the first half of 2026 alone. Daily breach notifications have climbed 22% year over year to 443 per day โ€” the first time that figure has topped 400 since GDPR took effect in 2018. And enforcement has moved decisively past Big Tech: more fines have been issued against small and mid-sized businesses since January 2023 than in the previous five years combined.

Layer a second, higher-ceiling penalty regime onto that trajectory, and the message for compliance teams is straightforward: the AI Act didn't just add a new law to track. It added a second regulator with its own theory of what your AI system owes the people whose data it touches โ€” running at the same time, on the same systems, often over the same facts.

If you're not sure which side of the high-risk line your systems fall on, that's the question to answer first โ€” the obligations above only bite once you're inside Annex III, but the classification itself is something you're expected to have documented. Book a free consultation with GDPRGard โ†’

Sources

Also read:

โš ๏ธ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance โ€” verify current obligations with your legal adviser.