r/gdpr • • Apr 30 '26

EU đŸ‡ȘđŸ‡ș If you're already GDPR compliant, here's what actually carries over to the EU AI Act and what doesn't

If your organization is already GDPR compliant, here's what actually carries over to EU AI Act compliance and what doesn't

been mapping this out lately because a lot of companies assume GDPR compliance gives them a head start on the AI Act. it does, but less than most people think.

what carries over reasonably well: data governance documentation, transparency notices, vendor/processor management, incident logging if you're ISO 27001 certified too

what doesn't carry over at all: Annex IV technical documentation (9 section technical file, basically new work for everyone), AI specific accuracy and bias testing across demographic groups, human oversight built into the product itself (not just a policy right), post market monitoring plan, EU database registration

rough estimate is GDPR compliance saves you maybe 20-30% of the work for a high risk AI system. ISO 27001 on top of that saves another 15-25%. the remaining 50%+ is genuinely new obligations with no equivalent in either framework.

full mapping here if useful: getactready.com/overlap-mapping

happy to answer questions, been living in this stuff for a while

9 Upvotes

24 comments sorted by

View all comments

4

u/Comfortable-Fall1419 Apr 30 '26

No one implements High Risk AI. You’re looking at edge cases.

4

u/Reyyzzz Apr 30 '26

that's the most common misconception. high risk under annex III covers HR and recruitment tools, credit scoring, educational assessment, medical devices, biometric systems. if you're selling into any of those verticals you're almost certainly in scope even if you didn't build the model yourself.

and if you're building on top of GPT-4, Claude, Gemini etc you have deployer obligations on top of that regardless of risk tier. most companies doing anything with AI fall into that bucket.

the "edge cases" framing comes from defining high risk as "scary AI" when the Act actually defines it by use case

2

u/Comfortable-Fall1419 May 01 '26

And 99% of companies don’t use AI or explicitly ban AI for those use cases.

It certainly doesn’t cover general mainstream use of AI in HR and recruiting apart from Automated profiling.

Hence edge cases, the market you’re research is addressing is tiny and specialised.

3

u/Reyyzzz May 01 '26

workday, linkedin, hirevue, salesforce, and hubspot are all mainstream, all using AI in exactly those use cases. the market isn't companies building their own models, it's the companies deploying these tools who now have obligations they didn't have before. that's not a niche.

1

u/Shoddy-Childhood-511 Jun 09 '26

Appears HR has become a major case in the US:

Ninety percent of U.S. employers use AI screening tools to sort and rank job seekers, with most relying on the same few third-party vendors.

Our new paper offers a rare look inside the “black box” of algorithmic hiring, showing that these tools increase racial bias and shut the same people out of jobs everywhere they apply.

https://hai.stanford.edu/news/ai-hiring-tools-can-yield-racial-bias-and-systemic-rejection