Three weeks ago the EU AI Act's rules for high-risk AI systems became fully enforceable, and most of the coverage — including ours — went to companies building AI for hiring, credit scoring or critical infrastructure. If you run a small or mid-sized European business, that probably isn't you. Something else landed on the same date, though, and it almost certainly is: the duties that attach to deploying AI somebody else built.
The support chatbot on your website. The "summarise this customer" button inside your CRM. The assistant drafting your review replies, or taking notes in your sales calls. Every one of those processes personal data, and every one of them usually rests on two assumptions that no longer survive contact with a regulator: that the vendor's compliance covers you, and that whatever the model does with the data counts as anonymous.
Your Vendor's Compliance Is Not Your Compliance
When you connect an AI tool to a workflow that touches customer data, you decide why that data is processed and what the tool is used for. That makes you the controller — the party a supervisory authority writes to first. The vendor is, in most configurations, your processor: it acts on your instructions under a data processing agreement, and its certifications cover its infrastructure and its security practices.
What those certifications don't cover is the part regulators actually ask about: your legal basis for putting the data into the tool at all, what you told the people whose data it is, how long it stays there, whether it leaves the EU, and whether anyone assessed the risk before the feature was switched on. None of that transfers to a supplier, whatever the vendor's trust page implies. If the split between the two roles is fuzzy in your organisation, our free Controller vs Processor guide works through it.
Watch for the second role. Some AI vendors process your data as a controller in their own right — for model improvement, abuse monitoring or product analytics — while acting as your processor for everything else. That split is usually disclosed in the general terms rather than in the DPA, and it changes both who is accountable and what you have to tell your customers.
Why "It's Anonymised" Usually Isn't
The most common defence for an unassessed AI deployment is that the model doesn't really keep anything: data goes in, an answer comes out, nothing personal persists. The European Data Protection Board took that argument apart in its December 2024 opinion on AI models. A model trained on personal data cannot simply be assumed to be anonymous. Anonymity has to be demonstrated case by case, and the test is demanding — both the likelihood of extracting personal data from the model itself and the likelihood of obtaining it from the model's outputs have to be insignificant.
For a business deploying somebody else's tool, the practical reading is narrower and rather simpler. You usually can't evaluate the vendor's model against that test, because you don't have the training details. What you can see is the part that matters more day to day: your inputs are personal data. A support transcript with a name, an order number and a complaint in it is personal data before the model ever sees it, and it stays personal data while it sits in the vendor's logs — in a retention window you probably didn't choose.
When a DPIA Stops Being Optional
Article 35 requires a Data Protection Impact Assessment wherever processing is "likely to result in a high risk" to people's rights and freedoms. The regulator guidance that fleshes that out sets nine criteria; meeting two of them normally means you run a DPIA. AI deployments hit several routinely: innovative use of a new technology, processing on a large scale, evaluation or scoring, matching or combining datasets, and data concerning vulnerable people — a category that includes your own employees, because of the imbalance in the employment relationship.
A chatbot handling inbound customer queries plausibly ticks two or three of those before anyone looks at what it's being asked. Several national authorities go further and name AI or "innovative technology" explicitly on their published lists of processing that always requires a DPIA.
The assessment itself is not a project. It's a short set of questions you have to be able to answer in writing:
| The question | Why it decides the outcome |
|---|---|
| What personal data actually goes in? | Free-text fields carry far more than the data you intended to send — health details, financial complaints, third parties' names. |
| Who receives it, and where? | Sub-processors and the transfer mechanism, not just the vendor's headquarters. |
| Are inputs used to train or improve the vendor's model? | Often a toggle, sometimes on by default. If it's on, you need a legal basis for it and you have to say so. |
| How long is it kept? | Vendor defaults range from days to indefinitely, and they're rarely the retention period in your own policy. |
| Can a person catch a wrong output before it affects someone? | Meaningful human oversight is where GDPR Article 22 and the AI Act's expectations meet. |
| What happens on an erasure request? | Deletion has to reach the tool and the logs, or the request isn't satisfied. |
Write the answers down, attach them to your record of processing, and you have both the DPIA and the Article 30 entry. The document isn't really the point. The point is that questions three, four and six turn out to have uncomfortable answers surprisingly often — and you only find that out by asking them.
Editable DPA pack, SAR response toolkit, and Article 30 RoPA register — the paperwork that turns "we use an AI tool" into something you can evidence. €39–€59 each or €99 for all three, instant download.
Two Transparency Regimes, One Chatbot
Every year the EDPB picks a single theme that all national supervisory authorities investigate in parallel. For 2026 it's transparency and information obligations under Articles 12–14: whether your privacy notice tells people, in plain language, what actually happens to their data. Notices written in 2018 for cookies and a newsletter tend not to mention the AI features added since.
Meanwhile, since 2 August 2026 the AI Act's own transparency rules apply too. People have to be told when they're interacting with an AI system rather than a person, unless that's obvious to a reasonably well-informed user. AI-generated content has to be machine-markable as such, deepfakes have to be disclosed, and deployers of emotion-recognition or biometric-categorisation systems have to inform the people exposed to them.
Two laws now point at the same widget. Whether the AI Act duty formally sits with you or with your vendor depends on who counts as the provider of the system — a line that blurs quickly once you white-label a chatbot under your own brand — but the disclosure a visitor sees appears on your site, and the GDPR transparency duty is unambiguously yours either way.
In practice, adequate disclosure looks like this: the bot says it's a bot in its opening message rather than in a footer; it doesn't present as a human first name with a stock photo avatar unless that's qualified; there's a link to the privacy notice inside the widget; and the notice itself names the AI processing, its purpose, the recipients, the retention period, and whether any decision is being taken automatically.
The Penalty Layer, Stated Accurately
You'll see "€35 million or 7% of turnover" quoted for AI Act breaches generally. That tier is narrower than the headline suggests, and the distinction matters, because the number that applies to most deployers is a different one.
For SMEs and start-ups, each cap is the lower of the fixed sum and the percentage — a deliberate proportionality valve for smaller businesses. It doesn't help as much as it sounds, because the exposure isn't one fine. The same failure can be assessed twice, by two authorities, under two laws: a chatbot that collects customer data without a valid basis and never says it's a bot is a GDPR problem and an AI Act problem at once.
That's landing in an enforcement climate that stopped being selective some time ago. Cumulative GDPR fines have passed €7.1 billion, and daily breach notifications across the EU are running above 400 — we went through those numbers here. Smaller companies are not flying under the radar the way they did in 2020.
A 30-Day Plan for the Tools You Already Run
- Inventory the AI, including the AI you didn't buy as AI. CRM summaries, email drafting assistants, meeting note-takers, review responders, translation features, spam and fraud scoring. Anything that sends customer or employee data to a model.
- Get the paperwork, per tool. A signed DPA, the current sub-processor list, the transfer mechanism if data leaves the EU, and the documented retention period.
- Check the training toggle. Find out whether your inputs improve the vendor's models. Switch it off, or write down the basis for leaving it on.
- Run the DPIA on the two or three tools touching the most sensitive data. Half a day each, using the questions above.
- Update the privacy notice. This is the 2026 coordinated enforcement theme; a notice that doesn't mention AI processing is the easiest finding a regulator can make.
- Fix the disclosure in the interface itself. If a visitor can't tell within a few seconds that they're talking to software, that's a compliance gap, not a design choice.
- Diarise a quarterly review. Vendors swap underlying models and change terms mid-contract, and your assessment ages the day they do.
The Bottom Line
GDPR compliance used to be the whole conversation for a European SMB. It's now roughly half of it — and the missing half isn't the exotic one. It's the chatbot that went live because it was a three-line embed, with no DPIA behind it, no line in the privacy notice, and no disclosure in the widget. None of that takes a quarter to fix. All of it takes longer than the notice period a supervisory authority gives you.
Run the free GDPRGard site audit → for the transparency and cookie side, or book a free consultation if you want a second pair of eyes on an AI deployment.
Sources
- EDPB — opinion on AI models: anonymity, legitimate interest and unlawfully processed data
- EU AI Act — Article 50, transparency obligations for providers and deployers
- EU AI Act — Article 99, penalties
- GDPR — Article 35, data protection impact assessment
- EDPB — news and the Coordinated Enforcement Framework
- Kiteworks — GDPR fines hit €7.1 billion: enforcement trends in 2026
Also read:
- AI Act high-risk rules are now live — and GDPR didn't go anywhere
- The DPIA you need before launching an AI feature
- AI is 2026's biggest GDPR compliance risk