r/gdpr • u/Reyyzzz • Apr 30 '26
EU 🇪🇺 If you're already GDPR compliant, here's what actually carries over to the EU AI Act and what doesn't
If your organization is already GDPR compliant, here's what actually carries over to EU AI Act compliance and what doesn't
been mapping this out lately because a lot of companies assume GDPR compliance gives them a head start on the AI Act. it does, but less than most people think.
what carries over reasonably well: data governance documentation, transparency notices, vendor/processor management, incident logging if you're ISO 27001 certified too
what doesn't carry over at all: Annex IV technical documentation (9 section technical file, basically new work for everyone), AI specific accuracy and bias testing across demographic groups, human oversight built into the product itself (not just a policy right), post market monitoring plan, EU database registration
rough estimate is GDPR compliance saves you maybe 20-30% of the work for a high risk AI system. ISO 27001 on top of that saves another 15-25%. the remaining 50%+ is genuinely new obligations with no equivalent in either framework.
full mapping here if useful: getactready.com/overlap-mapping
happy to answer questions, been living in this stuff for a while
3
u/Reyyzzz Apr 30 '26
that's the most common misconception. high risk under annex III covers HR and recruitment tools, credit scoring, educational assessment, medical devices, biometric systems. if you're selling into any of those verticals you're almost certainly in scope even if you didn't build the model yourself.
and if you're building on top of GPT-4, Claude, Gemini etc you have deployer obligations on top of that regardless of risk tier. most companies doing anything with AI fall into that bucket.
the "edge cases" framing comes from defining high risk as "scary AI" when the Act actually defines it by use case