Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. AI Act
Course Guides Resources News
Français English Nederlands
Regulation (EU) 2024/1689 Doctrinal Column EUR-Lex Official Sources

EU AI Act: Anatomy of a Regulatory Misunderstanding — What You Really Need to Know and How It Works

Beyond media sensationalism and tech fantasies: a methodical breakdown of product safety legislation, its risk-based architecture, and its conflicting interplay with the GDPR

Prologue: The Birth of a Legal Myth

Few pieces of European legislation have generated as many misconceptions prior to their full application as Regulation (EU) 2024/1689 on Artificial Intelligence (commonly known as the EU AI Act). Portrayed by critics as the "graveyard of European innovation," yet hailed by political communicators as "the world's first code of algorithmic ethics," the text is fundamentally something else.

For legal practitioners in positive law, the AI Act is neither a philosophical manifesto nor a computer programmer's code of conduct: it is a classic internal market harmonisation regulation rooted in European product safety legislation (closely aligned with the CE marking regime for medical devices, industrial machinery, and consumer products). Its primary purpose is not to grant new subjective individual rights to citizens — a role constitutionally and structurally reserved for the GDPR —, but to impose strict technical conformity requirements on providers and deployers before market placement.

Understanding how the AI Act truly operates requires looking past broad political declarations to inspect its working mechanisms: the statutory definition of an AI system, the four-tier risk pyramid, the regime governing General Purpose AI (GPAI) models, and above all, its continuous legal friction with the GDPR.

1. The Scope: What Is an "AI System" Under Article 3?

The primary operational hurdle of any technology-specific regulation is avoiding rapid technological obsolescence. The drafters of the AI Act deliberately aligned their qualification with the revised OECD definition (December 2023) to preserve global consistency.

Under Article 3(1) of the Regulation, an "AI system" is defined as:

"a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments."

This drafting deliberately excludes purely "deterministic" software applications based solely on classic rule-based programming (traditional human-coded if-then-else branch logic). The decisive legal criterion is the capability of inference (machine learning, statistical inference, inductive reasoning), granting operational autonomy and adaptive capability in response to unforeseen inputs.

2. The Risk Pyramid: The Master Architecture

The AI Act is built upon a proportionate approach that scales regulatory burdens according to the severity of risks posed to health, safety, and fundamental rights. Four distinct tiers structure this framework:

🚫 Tier 1: Prohibited Practices (Article 5)

Applicable from 2 February 2025, these systems are deemed unacceptable violations of EU values and banned outright from the internal market:

  • Subliminal or purposefully manipulative techniques distorting behaviour and causing significant harm;
  • Exploitation of vulnerabilities based on age, disability, or socio-economic conditions;
  • Social scoring by public or private entities leading to detrimental treatment across unrelated contexts;
  • Predictive policing assessments of criminal recidivism risk based solely on personality profiling;
  • Untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases (e.g. Clearview AI model);
  • Emotion recognition systems in the workplace or educational institutions (save for strict medical/safety grounds);
  • Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (subject to narrow judicial exceptions: terrorism, targeted abduction searches).

⚠️ Tier 2: High-Risk AI Systems (Articles 6–49, Annexes I & III)

The regulatory core of the Act. Two main categories fall into this scope:

  1. AI systems used as safety components of products already governed by EU product legislation requiring CE marking (medical devices, aviation, motor vehicles, industrial machinery);
  2. Standalone systems explicitly listed in Annex III (biometrics, critical infrastructure, education and vocational training admission, employment and HR management, access to essential public and private services such as credit scoring, law enforcement, migration and border management, administration of justice).

Heavy compliance regime: continuous risk management systems (Art. 9), strict data governance for training sets (Art. 10), detailed technical documentation (Art. 11), automatic event logging (Art. 12), transparency and user instructions (Art. 13), effective human oversight (Art. 14), and high accuracy, robustness, and cybersecurity standards (Art. 15).

ℹ️ Tier 3: Specific Transparency Risk (Article 50)

Systems directly interacting with human users (conversational agents, chatbots) that must disclose their artificial nature, and systems generating synthetic media (deepfakes, synthetic text of public interest) that must incorporate robust, machine-readable watermarking.

✅ Tier 4: Minimal or No Risk

All other systems (spam filters, AI in video games, inventory optimisation, network load routing). Free from mandatory obligations under the AI Act, though encouraged to adhere to voluntary codes of conduct. Represents the broad majority of AI applications.

3. General Purpose AI (GPAI) Models

The European Commission's original 2021 proposal did not anticipate the sudden arrival of foundational multimodal large language models (LLMs). The AI Act addressed this gap in the late 2023 trilogues by introducing a targeted framework for General Purpose AI (GPAI) models under Articles 51 through 56.

The legislation establishes a two-tiered obligation structure for GPAI providers:

  • Baseline Tier (All GPAI Models): Technical documentation provided to downstream integrators, publication of a sufficiently detailed summary of training data, adherence to copyright opt-out rules (Directive (EU) 2019/790, Art. 4), and an established IP compliance policy.
  • Systemic Risk Tier: Models trained using cumulative computational power exceeding 1025 FLOPs (floating-point operations) or designated as systemic by the Commission. Additional obligations include model evaluations (adversarial red-teaming), systemic risk mitigation across the EU, prompt reporting of serious incidents to the European AI Office, and reinforced cybersecurity for hosting infrastructure.

4. AI Act and GDPR: The Illusion of Subsidiarity

Here lies the most perilous pitfall for organisations: assuming that complying with the AI Act absorbs, overrides, or discharges GDPR responsibilities.

Article 2(7) of the AI Act establishes an unequivocal principle: "This Regulation shall not affect the application of the Union law on personal data protection, in particular Regulation (EU) 2016/679 and Directive 2002/58/EC."

Legally, this creates cumulative application without derogation. An AI product may possess a flawless CE certificate under the AI Act while remaining entirely unlawful under the GDPR. Key friction points include:

Comparative Matrix: AI Act vs. GDPR Legal Clashes

Legal Dimension AI Act Mandate (EU 2024/1689) GDPR Mandate (EU 2016/679)
Data Quality vs. Minimisation Article 10 demands training datasets that are "statistically representative, complete, and free of errors" to mitigate bias. Article 5(1)(c) mandates strict data minimisation: processing must be limited to what is strictly necessary. Massive data harvesting is presumed suspect.
Right to Erasure (Art. 17) Does not address algorithmic unlearning; mandates reproducibility and model traceability. Data subjects enjoy an enforceable right to erasure. Removing individual parameters from neural network weights without retraining remains technically challenging.
Special Categories (Art. 9) Article 10(5) grants an exceptional gateway permitting processing of sensitive data strictly for bias detection and correction. Strict prohibition of principle subject only to 10 narrow exemptions (Art. 9(2)). Supervisory authorities scrutinise this AI Act gateway with high rigor.
Automated Decisions & Profiling Permits high-risk AI decision systems provided human oversight measures (Art. 14) are in place. Article 22 creates a right not to be subjected to solely automated decisions producing legal effects. Human intervention must be genuine, not rubber-stamping.

5. Application Timeline and Penalties: The Phased Reality

Published in the Official Journal on 12 July 2024 and in force since 2 August 2024, the AI Act rolls out across staggered enforcement milestones:

  • 2 February 2025 (M+6): Immediate ban on prohibited AI practices (Article 5) and general AI literacy obligations (Art. 4);
  • 2 August 2025 (M+12): Application of rules governing GPAI models, designation of national competent authorities, and governance structures;
  • 2 August 2026 (M+24): General application across all member states, including the complete regime for high-risk systems under Annex III;
  • 2 August 2027 (M+36): Deferred enforcement for high-risk systems integrated into products governed by existing Annex I Union legislation (medical devices, industrial machinery).

Administrative Fines Framework (Article 99)

The AI Act scales penalties beyond GDPR levels: up to €35 million or 7% of worldwide annual turnover for non-compliance with prohibited practices; up to €15 million or 3% for breaches of high-risk system obligations; and up to €7.5 million or 1.5% for supplying misleading information to authorities. Scaled, proportionate caps apply to SMEs and startups.

6. Operational Roadmap: 5-Step Compliance Checklist

In light of the dual AI Act / GDPR challenge, legal and technical teams should adopt a practical 5-step implementation process:

  1. Use-Case Mapping: Catalog every algorithmic and AI tool in use across the organisation (including "Shadow AI" — staff using unsanctioned external SaaS generative AI accounts).
  2. Article 5 Negative Screening: Immediately verify that no internal projects violate prohibited practices (employee biometric scoring, emotion recognition in meetings, indiscriminate facial scraping).
  3. Risk Tier Assessment: Classify remaining systems under Annex III (high-risk), Article 50 (transparency/chatbots), or minimal risk.
  4. GDPR Baseline Alignment: For any system touching personal data, formalise the lawful basis (Article 6(1)(f) legitimate interest requires a robust LIA test for web scraping), carry out or update DPIAs (Article 35 GDPR), and ensure valid DPA agreements (Article 28 GDPR) are executed with vendors.
  5. Human Oversight and Audit Trails: Implement structured "Human-in-the-loop" protocols empowering staff to intervene or override AI suggestions, and establish automated log retention for a minimum of 6 months pursuant to Article 12.

Controlled Official Sources and References

Regulation (EU) 2016/679, GDPR

Principles, lawful bases, rights, privacy by design, security and DPIA.

Access official source →
Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act)

European product safety framework for AI, risk classification and conformity requirements.

Access official source →
EDPB, Opinion 28/2024 on AI Models

Anonymisation, legitimate interest, memorisation, extraction and unlawful processing consequences.

Access official source →

See Also in the Reference Directory

Article 22, Automated Decision-Making

Human safeguards and oversight of algorithmic decision systems.

Read guide

Article 25, Data Protection by Design

Embedding principles into auditable system architectures.

Read guide

Article 35, Data Protection Impact Assessment

Systematic risk evaluation for individual rights and freedoms.

Read guide
⚡ Practical Summary Key Takeaways from the EU AI Act
⚡ Key Takeaway
The AI Act is product safety regulation (CE marking), not an ethics declaration. It never displaces the GDPR, which applies concurrently and strictly to all personal data processing.
⚠️ Common Pitfall
Assuming an AI system compliant with the AI Act is exempt from a DPIA (Art. 35 GDPR) or lawful basis. Regulators (CNIL, APD) sanction under the GDPR first.
🛠️ Practical Action
Audit and eliminate any use cases under Art. 5 immediately (bans active from Feb 2025). Screen recruitment, scoring, and biometric tools to prepare for Annex III obligations by Aug 2026.
⚖️ Official Sources
Regulation (EU) 2024/1689 (EUR-Lex) · Regulation (EU) 2016/679 (GDPR) · Joint EDPB-EDPS Opinion 5/2021 on the AI Act · EDPB Guidelines 03/2026 on Web Scraping.
Official legal sources · EUR-Lex CELEX 32024R1689 · EDPB · CJUE © 2026 RGPD.click · Independent legal documentation

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR) and Regulation (EU) 2024/1689 (AI Act).

Home · Resources Index · Privacy Policy · Legal Notice