If your organisation builds, deploys, or relies on AI in hiring, credit scoring, critical infrastructure, or border and law enforcement contexts, August 2, 2026 was a deadline you couldn't miss. That's the date the EU AI Act's obligations for high-risk AI systems became fully enforceable โ and it means GDPR is no longer the only data law that can end a bad year for your compliance budget.
For the first time, two separate EU penalty regimes now apply, in parallel, to the same underlying activity: processing personal data through an AI system. Understanding where they overlap, where they diverge, and where they can both hit you at once is the compliance question of the second half of 2026.
What Changed on August 2
High-risk AI systems โ as defined in Annex III of the AI Act, covering use cases like recruitment, creditworthiness assessment, critical digital infrastructure management, and border control โ must now have, among other things:
- A risk management system maintained across the system's full lifecycle
- Data governance standards for training and validation datasets, including bias detection
- Technical documentation thorough enough to survive a regulatory audit
- Automatic logging of system operations
- Transparency provisions that let deployers and affected people understand what the system is doing
- Human oversight mechanisms that let a person intervene or halt the system at any point
- Accuracy, robustness, and cybersecurity standards appropriate to the system's purpose
Providers were expected to have conformity assessments completed, technical documentation finalised, CE marking affixed, and EU database registration done by the deadline.
If several of those obligations sound familiar, that's because they should. GDPR already required data protection impact assessments, documented risk analysis, transparency to data subjects, and safeguards around automated decision-making. The AI Act doesn't replace any of that โ it sits on top of it, with its own separate legal basis, its own documentation requirements, and its own fines.
Where the Two Laws Actually Overlap
The clearest collision points:
Data governance. The AI Act's Article 10 requires governance over training and validation datasets โ relevance, representativeness, bias detection. GDPR's data minimisation and accuracy principles (Article 5) already govern the personal data inside those same datasets. A flawed training set can now be a violation under both frameworks simultaneously, assessed by two different tests.
Impact assessments. GDPR requires a Data Protection Impact Assessment (DPIA) for high-risk processing. The AI Act requires a Fundamental Rights Impact Assessment (FRIA) for certain high-risk deployments, particularly by public bodies and in sensitive sectors. These aren't the same document, but they draw on much of the same underlying risk analysis โ meaning a poorly scoped DPIA now has a second law waiting to catch what it misses.
Transparency. GDPR Articles 12โ14 require clear information to data subjects about processing. The AI Act separately requires providers to give deployers instructions for safe use and information about system accuracy and limitations, and requires that people be told when they're interacting with an AI system. Two transparency regimes, two audiences, two sets of disclosure obligations.
Human oversight and automated decision-making. GDPR Article 22 restricts solely automated decisions with legal or similarly significant effects. The AI Act's human oversight requirement is broader and applies regardless of whether a decision is "solely" automated โ meaning a system that clears the GDPR Article 22 bar because a human technically reviews outputs can still fail the AI Act's higher bar for what effective oversight looks like.
The Penalty Math
This is where it gets sharper. The AI Act's Article 99 sets a three-tier structure:
- Up to โฌ35 million or 7% of global annual turnover for violations of prohibited practices (Article 5)
- Up to โฌ15 million or 3% of turnover for high-risk system violations
- Up to โฌ7.5 million or 1% of turnover for supplying incorrect or misleading information to regulators
The top tier now exceeds GDPR's own maximum of โฌ20 million or 4% of global turnover, making the AI Act the more punitive of the two regimes at its ceiling.
Crucially, Article 99(8) includes a "same conduct, one penalty" rule: if a single factual violation breaches both the AI Act and another EU law like GDPR, regulators impose only the higher of the two applicable fines. But that protection is narrower than it sounds. If an AI system violates the AI Act's data governance rules through a biased training set, and separately violates GDPR's accuracy or minimisation principles through how that same data was collected or retained, those are treated as distinct violations โ and can be penalised separately.
Legally, this isn't "double jeopardy" in the way many compliance teams assume. It's a determination made violation-by-violation โ and the more entangled your AI system's data practices are with GDPR-governed personal data, the more surface area you have for that separation to work against you.
What This Means Practically
The instinct to treat the AI Act and GDPR as two checklists to run in sequence is the most expensive mistake available right now. A few things worth doing instead:
- Map your DPIAs and FRIAs against each other rather than commissioning them separately. If a system needs both, the underlying risk analysis should be a shared foundation, not two disconnected exercises that quietly contradict each other. If you don't have a DPIA process at all yet, start there โ the FRIA is much harder to build on nothing.
- Audit your existing GDPR transparency notices against the AI Act's disclosure requirements. They cover different information, but a notice built only for GDPR compliance is likely to be missing what the AI Act now separately demands โ and this arrives at the same time the EDPB has made Articles 12โ14 transparency its 2026 coordinated enforcement priority. Both regulators are looking at the same notices this year, for different reasons.
- Treat human oversight as a design requirement, not a policy statement. Regulators under both regimes are going to ask for evidence that a human can meaningfully intervene, not just that a human is nominally in the loop. Our AI oversight checklist covers what that evidence looks like in practice.
- Get legal and technical documentation teams talking to each other now. The AI Act's technical documentation and logging requirements will increasingly be the evidence base regulators use to evaluate GDPR compliance too, since both hinge on being able to show โ not just assert โ how a system actually processes personal data.
The Enforcement Backdrop Makes This Urgent, Not Theoretical
This isn't landing in a quiet enforcement environment.
GDPR fines have already crossed โฌ7.1 billion cumulatively, with more than โฌ600 million issued in the first half of 2026 alone. Daily breach notifications have climbed 22% year over year to 443 per day โ the first time that figure has topped 400 since GDPR took effect in 2018. And enforcement has moved decisively past Big Tech: more fines have been issued against small and mid-sized businesses since January 2023 than in the previous five years combined.
Layer a second, higher-ceiling penalty regime onto that trajectory, and the message for compliance teams is straightforward: the AI Act didn't just add a new law to track. It added a second regulator with its own theory of what your AI system owes the people whose data it touches โ running at the same time, on the same systems, often over the same facts.
If you're not sure which side of the high-risk line your systems fall on, that's the question to answer first โ the obligations above only bite once you're inside Annex III, but the classification itself is something you're expected to have documented. Book a free consultation with GDPRGard โ
Sources
- EU AI Act โ Article 99, Penalties
- EU AI Act โ Annex III, High-risk AI systems
- European Commission โ AI Act implementation timeline
- CMS GDPR Enforcement Tracker
- European Data Protection Board โ coordinated enforcement framework
Also read:
- The AI Act delay doesn't cover your chatbot
- Why every SaaS company needs a DPIA before launching AI features
- AI news and insights: what's actually driving AI-driven business growth