The AI Act — formally Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence — is the world's first horizontal regulation on artificial intelligence. Published in the Official Journal of the European Union on 12 July 2024 and in force since 1 August 2024, it sets out a common framework for the development, placing on the market and use of AI systems across the 27 Member States.
As a regulation, it is directly applicable: no national transposition is required. Its application, however, is phased in until August 2027, with three earlier phases that are already in progress or imminent.
This guide condenses its 13 chapters, 113 articles, 180 recitals and 13 annexes into a practical format so that any business decision-maker can understand what the AI Act demands, how it interacts with the GDPR and what steps to take today to prepare their organisation.
AI Act and GDPR: how they interact
The AI Act does not replace the GDPR. Art. 2.7 of the Regulation makes this explicit: the AI Act applies without prejudice to Regulations (EU) 2016/679 and (EU) 2018/1725 and to Directives 2002/58/EC and (EU) 2016/680. When an AI system processes personal data — which is the case in the vast majority of practical scenarios — two overlapping regulatory frameworks coexist: the AI Act governs the system; the GDPR governs the data processing.
| Feature | AI Act (EU 2024/1689) | GDPR (EU 2016/679) |
|---|---|---|
| Nature | European Regulation (directly applicable) | European Regulation (directly applicable) |
| Subject matter | AI systems and models | Processing of personal data |
| Obliged parties | Provider, deployer, importer, distributor, product manufacturer, authorised representative | Controller and processor |
| Approach | Risk-based (4 tiers) | Principles- and data-subject-rights-based |
| Maximum penalty | EUR 35M or 7% of worldwide turnover (prohibited practices, art. 99.3) | EUR 20M or 4% of worldwide turnover (art. 83.5) |
| National authority (ES) | AESIA, with AEPD competences in specific high-risk sectors (art. 74(8)): law enforcement, border control, justice and democratic processes | AEPD (Spanish Data Protection Agency) |
Practical interaction: art. 26.11 of the AI Act expressly allows the deployer of a high-risk system to use the information supplied by the provider (art. 13) to comply with its data protection impact assessment obligation under art. 35 GDPR. They are not interchangeable assessments, but they must be coordinated.
Structure of the AI Act: 13 chapters, 113 articles, 180 recitals and 13 annexes
The AI Act is one of the most extensive European pieces of legislation of the past decade. Its preamble contains 180 recitals that guide interpretation. The operative part comprises 113 articles spread across 13 chapters. It is rounded off by 13 technical annexes.
| Chapter | Content | Key articles |
|---|---|---|
| Ch. I | General provisions | Arts. 1–4 · Subject matter, scope, definitions, AI literacy |
| Ch. II | Prohibited AI practices | Art. 5 · The 8 unacceptable practices |
| Ch. III | High-risk AI systems | Arts. 6–49 · Classification, requirements, provider and deployer obligations, conformity assessment, registration |
| Ch. IV | Transparency obligations | Art. 50 · Chatbots, synthetic content, deepfakes, emotion recognition |
| Ch. V | General-purpose AI models (GPAI) | Arts. 51–56 · Classification, general and reinforced obligations, codes of practice |
| Ch. VI | Measures in support of innovation | Arts. 57–63 · Regulatory sandboxes, real-world testing, SMEs |
| Ch. VII | Governance | Arts. 64–70 · AI Office, AI Board, advisory forum, national authorities |
| Ch. VIII | EU database for high-risk systems | Art. 71 · Public registry managed by the Commission |
| Ch. IX | Post-market monitoring and serious incidents | Arts. 72–94 · Monitoring, incident reporting, market surveillance |
| Ch. X | Codes of conduct and guidelines | Arts. 95–96 · Voluntary application to non-high-risk systems |
| Ch. XI | Delegation of powers and committee procedure | Arts. 97–98 |
| Ch. XII | Penalties | Arts. 99–101 · Three tiers of administrative fines |
| Ch. XIII | Final provisions | Arts. 102–113 · Amendments to other acts, application timeline, entry into force |
Scope of application: who is bound by the AI Act?
Art. 2 of the Regulation sets out a broad personal scope. The following are included:
- Providers placing on the market or putting into service AI systems or general-purpose AI models in the Union, regardless of whether they are established in the EU or in a third country.
- Deployers established or located in the Union.
- Providers and deployers from third countries, where the system's output is used in the Union.
- Importers and distributors of AI systems.
- Product manufacturers integrating an AI system under their own brand.
- Authorised representatives of providers not established in the EU.
- Affected persons located in the Union.
The following are excluded (under the relevant paragraphs of art. 2): areas falling outside Union law, national security competences, systems used exclusively for military or defence purposes, scientific research and development, testing activities prior to market placement and, with significant caveats, systems released under free and open-source licences (unless they are high-risk, fall within art. 5 or are subject to art. 50). Art. 2(7) itself contains a safeguard clause: the AI Act applies without prejudice to the GDPR, the ePrivacy Directive and other applicable EU law.
Key definitions (art. 3)
Art. 3 contains 68 definitions. These are the ones any business decision-maker should know:
| Concept | Definition (summary of art. 3) |
|---|---|
| AI system (art. 3.1) | Machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment; it infers, from the input it receives, how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. |
| General-purpose AI model (art. 3.63) | AI model — typically trained on a large amount of data using self-supervision at scale — displaying significant generality and capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream systems or applications. |
| Provider (art. 3.3) | Natural or legal person, public authority or body that develops an AI system or model — or has one developed — and places it on the market or puts it into service under its own name or trade mark, whether for payment or free of charge. |
| Deployer (art. 3.4) | Natural or legal person, or public authority, that uses an AI system under its own authority, except where the use takes place in the course of a personal non-professional activity. Any organisation that uses AI in its operations is a deployer. |
| Biometric data (art. 3.34) | Personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics of a natural person (facial images, dactyloscopic data). |
| Biometric categorisation (art. 3.40) | AI system designed to assign natural persons to specific categories on the basis of their biometric data, except where ancillary to another commercial service and strictly necessary for objective technical reasons. |
| Emotion recognition (art. 3.39) | AI system designed to identify or infer emotions or intentions of natural persons on the basis of their biometric data. |
| Remote biometric identification (art. 3.41) | AI system designed to identify natural persons without their active involvement and generally at a distance, by comparing their biometric data against a reference database. |
| Deepfake (art. 3.60) | AI-generated or AI-manipulated image, audio or video content that resembles existing persons, objects, places or events and would falsely appear to be authentic. |
| Systemic risk (art. 3.65) | Risk specific to the high-impact capabilities of general-purpose AI models, with significant impact on the Union market by reason of their reach or their negative effects on public health, safety, fundamental rights or society. |
Application timeline (art. 113)
Art. 113 sets out a phased timeline. The date specified in each article is binding: the prohibitions apply long before the high-risk obligations.
| Date | What starts to apply |
|---|---|
| 12 July 2024 | Publication in the OJEU. |
| 1 August 2024 | Entry into force (20 days after publication, art. 113). |
| 2 February 2025 | Chapters I and II become applicable: general provisions (including AI literacy under art. 4) and prohibited AI practices (art. 5). |
| 2 August 2025 | Ch. III Section 4 (notified bodies), Ch. V (general-purpose AI models), Ch. VII (governance), Ch. XII (penalties, except art. 101) and art. 78 become applicable. Obligations for GPAI become enforceable. |
| 2 August 2026 | General application of the Regulation. Full effect of the obligations for high-risk systems under Annex III and of the remaining provisions (including the operation of national regulatory sandboxes). |
| 2 August 2027 | Application of art. 6.1 and related obligations: high-risk systems that are safety components of products regulated by the Union harmonisation legislation listed in Annex I. |
The risk-based approach: four tiers
The regulatory philosophy of the AI Act is proportionate to risk. It does not regulate AI for what it is, but for what it does and the potential harm it can cause. The Regulation establishes four tiers of obligations:
| Tier | Treatment | Examples |
|---|---|---|
| Unacceptable risk | Prohibited (art. 5). | Subliminal manipulation, social scoring, mass scraping of facial images, emotion recognition at work and in educational settings… |
| High risk | Permitted subject to strict requirements (Ch. III) and conformity assessment before placing on the market. | Systems used in HR for recruitment, credit scoring, AI-enabled medical devices, AI in education for exam grading, AI in justice, critical infrastructure… |
| Limited risk | Permitted subject to transparency obligations (art. 50). | Chatbots, synthetic content generation (text, audio, image, video), deepfakes, permitted biometric categorisation systems. |
| Minimal or no risk | Permitted without specific obligations under the Regulation. Voluntary codes of conduct may apply (art. 95). | Spam filters, basic recommenders, AI embedded in video games… |
Prohibited AI practices (art. 5)
Art. 5.1 lists the practices that are entirely prohibited in the European Union, regardless of the consent of the affected person. This is the full list, closely tracking the official wording:
| Letter | Prohibited practice | Real-world example |
|---|---|---|
| 5.1.a | Systems using subliminal, deliberately manipulative or deceptive techniques, with the object or effect of materially distorting a person's behaviour, impairing their ability to take an informed decision and causing significant harm. | Interfaces hiding audiovisual cues below conscious awareness to induce purchases or harmful decisions. |
| 5.1.b | Systems that exploit vulnerabilities due to age, disability or a specific social or economic situation, distorting behaviour in a way that causes significant harm. | Platforms targeted at minors or people with addictions designed to encourage harmful behaviour. |
| 5.1.c | Social scoring of natural persons: systems evaluating or classifying people on the basis of their social behaviour or personal characteristics, leading to detrimental treatment outside the original context or disproportionate to the behaviour. | 'Social scoring' systems that penalise individuals with a given rating in their interactions with the public administration or private sector. |
| 5.1.d | Predictive policing of natural persons: systems making risk assessments of the likelihood of an individual committing a criminal offence solely on the basis of profiling or personality traits. Systems that support a human assessment based on objective facts directly linked to criminal activity are not prohibited. | Law-enforcement applications assigning an individual risk of offending based on demographic or psychological profiles. |
| 5.1.e | Creation or expansion of facial-recognition databases through untargeted scraping of facial images from the internet or CCTV footage. | Clearview-style services that mass-crawl the web to build a universal biometric identifier. |
| 5.1.f | Inferring emotions in the workplace and in educational settings, except where the system is intended for medical or safety reasons. | Software assessing the attention or emotional state of employees or pupils through cameras or microphones. |
| 5.1.g | Biometric categorisation that individually categorises persons to deduce race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation. Lawful labelling or filtering of biometric datasets is not covered. | Systems that, from a facial photograph, infer political orientation or religion. |
| 5.1.h | 'Real-time' remote biometric identification in publicly accessible spaces for law-enforcement purposes, save in narrowly defined cases (search for victims of abduction/trafficking, imminent threat, locating suspects of serious offences under Annex II). Requires prior judicial or administrative authorisation, a fundamental-rights impact assessment and registration. | Live facial recognition in stations or streets for general identification. |
These prohibitions are applicable from 2 February 2025 (art. 113.a).
High-risk AI systems (Chapter III)
When a system is high-risk
Art. 6 sets out two routes for a system to be classified as high-risk:
- Route 1 (art. 6.1): the system is a safety component of a product regulated by the EU harmonisation legislation listed in Annex I (machinery, toys, lifts, personal protective equipment, medical devices, automotive, aviation, etc.) and that product requires a third-party conformity assessment.
- Route 2 (art. 6.2): the system falls within one of the areas listed in Annex III.
Art. 6.3 provides an exception: even where it falls within Annex III, a system will not be classified as high-risk if it 'does not pose a significant risk' because (a) it performs a narrow procedural task, (b) it improves the result of a previously completed human activity, (c) it detects decision-making patterns without replacing human assessment, or (d) it performs a preparatory task. This exception must be justified and documented.
The 8 areas of Annex III
| # | Area | Typical use cases |
|---|---|---|
| 1 | Biometrics (where permitted) | Remote biometric identification, biometric categorisation based on sensitive attributes, emotion recognition. |
| 2 | Critical infrastructure | AI used as a safety component in critical digital infrastructure, road traffic, the supply of water, gas, heating or electricity. |
| 3 | Education and vocational training | Admission to educational institutions, evaluation of learning outcomes, assignment to educational levels, detection of prohibited behaviour in exams. |
| 4 | Employment, worker management and self-employment | Recruitment (posting job adverts, CV screening, candidate evaluation); decisions on working conditions, promotion, termination, task allocation and performance monitoring. |
| 5 | Access to essential services | Eligibility assessment for public benefits and health services, credit scoring (except fraud detection), risk and pricing assessment in life and health insurance, emergency-call and patient triage. |
| 6 | Law enforcement | Risk assessment of being a victim or perpetrator of a crime, polygraphs, evaluation of the reliability of evidence, profiling in criminal investigations. |
| 7 | Migration, asylum and border control | Polygraphs, irregular-entry risk assessment, examination of asylum/visa applications, identification of persons in border-control settings. |
| 8 | Administration of justice and democratic processes | Support to judicial authorities in researching and interpreting facts and the law; systems intended to influence the outcome of elections or referendums or electoral behaviour. |
Requirements for high-risk systems (arts. 8–15)
Section 2 of Chapter III sets out the seven core requirements any high-risk system must meet:
| Article | Requirement |
|---|---|
| Art. 9 | Risk management system that is documented, iterative and continuous throughout the entire lifecycle. |
| Art. 10 | Data and data governance: quality of training, validation and testing datasets; bias and representativeness analysis; data provenance traceability. |
| Art. 11 | Technical documentation in line with Annex IV (description of the system, logic, architecture, data, metrics, cybersecurity). |
| Art. 12 | Record-keeping (logs) automatically generated by the system. |
| Art. 13 | Transparency and information to the deployer: clear and sufficient instructions for use. |
| Art. 14 | Effective human oversight throughout the period in which the system is in use. |
| Art. 15 | Accuracy, robustness and cybersecurity appropriate to the intended purpose. |
Provider obligations (arts. 16–21)
- Art. 16: ensure that the system complies with the requirements of Section 2, indicate name and contact details, have a quality management system in place, retain documentation, keep the logs where they are under their control and subject the system to the relevant conformity assessment.
- Art. 17: put in place a documented quality management system.
- Art. 18: retention of documentation for 10 years after placing on the market or putting into service.
- Art. 19: retention of automatically generated logs, to the extent that they are under the provider's control.
- Art. 20: corrective measures and duty to inform where the system is not compliant.
- Art. 21: duty of cooperation with the competent authorities.
Deployer obligations (art. 26)
Any organisation using a high-risk AI system in its professional operations — even where it has not developed it — takes on the obligations under art. 26:
- Adopt appropriate technical and organisational measures to use the system in accordance with the instructions for use.
- Assign human oversight to persons with the necessary competence, training and authority.
- Ensure that input data is relevant and representative, where the deployer exercises control over it.
- Monitor the operation of the system, inform the provider and suspend use where a serious risk or a serious incident is detected (art. 79 and art. 73).
- Keep the logs automatically generated for at least 6 months, unless a different period is set by other legislation.
- Before putting a high-risk system into service at the workplace, inform workers' representatives and the affected workers.
- Where the deployer is a public authority, register the use in the EU database (art. 49).
- Use the information under art. 13 to comply with the DPIA under art. 35 GDPR, where applicable.
Fundamental rights impact assessment — FRIA (art. 27)
Before first use, deployers that are bodies governed by public law, private providers of public services and deployers of Annex III systems in areas 5.b (credit scoring) and 5.c (life and health insurance) must carry out a fundamental rights impact assessment: description of processes, period and frequency of use, categories of affected persons, specific risks to fundamental rights, human oversight measures and measures to be taken should those risks materialise.
General-purpose AI models (GPAI): Chapter V
The general-purpose AI models (GPAI) — those behind services such as GPT, Claude, Gemini or Llama — are regulated in Chapter V. The Regulation draws a distinction between two categories:
| Category | Criterion | Main obligations |
|---|---|---|
| General GPAI (art. 53) | General-purpose AI model that does not present systemic risk. | Technical documentation of the model (Annex XI); information for providers integrating the model (Annex XII); copyright compliance policy; sufficiently detailed public summary of the content used for training, following the template provided by the AI Office. |
| GPAI with systemic risk (art. 55) | Presumed where the cumulative amount of compute used for training, measured in floating-point operations, is greater than 10²⁵ FLOPS (art. 51.2). It may also be designated by the Commission. | In addition to the obligations under art. 53: state-of-the-art model evaluation (including red-teaming); assessment and mitigation of systemic risks at Union level; serious incident reporting to the AI Office; an appropriate level of cybersecurity for the model and its infrastructure. |
Art. 56 provides that the AI Office is to encourage the drawing-up of codes of practice as a means of demonstrating compliance with arts. 53 and 55. If the codes are not finalised or are deemed inadequate, the Commission may lay down common rules by means of implementing acts.
Providers of GPAI established in third countries must appoint an authorised representative in the Union (art. 54).
Transparency obligations (art. 50)
Certain AI systems, whether or not they are high-risk, are subject to specific transparency obligations. The underlying logic is the same: the person exposed must know that they are facing an AI system, not a human.
- Systems interacting with natural persons (chatbots, conversational agents — art. 50.1): providers must design them in such a way that persons are aware that they are interacting with an AI system, unless this is obvious to a reasonably well-informed person.
- Generation of synthetic content (text, audio, image, video — art. 50.2): providers — including those of general-purpose AI systems — must mark the outputs in a machine-readable format and make it detectable that they have been artificially generated or manipulated.
- Emotion recognition and biometric categorisation (art. 50.3): the deployer must inform the exposed persons about the operation of the system and process their personal data in accordance with the GDPR.
- Deepfakes (art. 50.4): the deployer must disclose that the image, audio or video has been artificially generated or manipulated. Where the content is part of a manifestly creative, satirical or fictional work, the obligation is limited to disclosing the existence of the synthetic content in a way that does not hamper the enjoyment of the work. For text published on matters of public interest, disclosure is also required, unless the content has been subject to human review or editorial control with an identified responsible party.
The information must be provided in a clear and distinguishable manner at the latest at the time of the first interaction (art. 50.5).
AI regulatory sandboxes (arts. 57–61)
Each Member State must ensure the existence of at least one national AI regulatory sandbox that is operational by 2 August 2026 at the latest (art. 57.1). It is a controlled environment supervised by the competent authority in which providers and prospective providers may develop, train, test and validate innovative AI systems before placing them on the market, with regulatory guidance and the possibility of testing in real-world conditions.
Sandboxes are designed in particular for SMEs and start-ups, which may access them on a priority basis and free of charge (art. 62).
Governance: AI Office, AI Board and national authorities
Chapter VII organises governance across three levels:
- European AI Office (art. 64): a function within the European Commission, set up by the Commission Decision of 24 January 2024. It concentrates technical expertise and supervises, among other things, general-purpose AI models with systemic risk.
- European Artificial Intelligence Board — AI Board (art. 65): composed of one representative per Member State, with the EDPS as observer. It coordinates the consistent application of the Regulation, issues recommendations and sets up standing sub-groups (including one on administrative cooperation, ADCO).
- Advisory forum (art. 67) and scientific panel of independent experts (art. 68): independent technical advice.
- National competent authorities (art. 70): each Member State must designate one or more notifying authorities and market surveillance authorities.
In Spain, the national supervisory authority generally designated is the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), established by Royal Decree 729/2023 of 22 August, based in A Coruña. Spain was the first Member State to set up a dedicated AI supervisory authority.
It is worth clarifying that the AEPD retains its own competences under the AI Act. Art. 74(8) designates national data protection authorities as the market surveillance authorities competent for high-risk AI systems used in law enforcement, border management, the administration of justice and democratic processes. In those areas, the AEPD does not only apply the GDPR: it also supervises and, where applicable, sanctions compliance with the AI Act. The AEPD also retains all its competences on personal data protection over any processing linked to AI systems.
Serious incident reporting (art. 73)
Providers of high-risk AI systems must notify the market surveillance authorities of any serious incident (as defined in art. 3.49):
- General rule: immediate notification once a causal link has been established and, at the latest, within 15 days.
- Widespread infringement or serious incident under art. 3.49.b: at the latest within 2 days.
- Death of a person: at the latest within 10 days.
Penalty regime (arts. 99–101)
Art. 99 sets out a regime of administrative fines in three tiers, alongside any non-pecuniary measures (warnings) that each Member State may add. The amount is determined by whichever is the higher: the fixed amount or the percentage (except for SMEs and start-ups, see below).
| Tier | Maximum amount | Infringements |
|---|---|---|
| Art. 99.3 | EUR 35,000,000 or 7% of total worldwide annual turnover | Non-compliance with the prohibited practices under art. 5. |
| Art. 99.4 | EUR 15,000,000 or 3% of total worldwide annual turnover | Non-compliance with the obligations of providers (art. 16), authorised representatives (art. 22), importers (art. 23), distributors (art. 24), deployers (art. 26), notified bodies (arts. 31, 33, 34) and the transparency obligations (art. 50). |
| Art. 99.5 | EUR 7,500,000 or 1% of total worldwide annual turnover | Supply of incorrect, incomplete or misleading information to notified bodies or national authorities. |
SMEs and start-ups (art. 99.6): for this category, each fine is the lower of the percentage or the fixed amount. This is a deliberately proportionate approach which the Regulation's own preamble underlines (recitals on support for innovation).
Art. 101 sets out a specific regime for providers of general-purpose AI models, with fines of up to EUR 15 million or 3% of their total worldwide annual turnover.
The tiers under art. 99 apply from 2 August 2025 (art. 113.b), with the exception of art. 101 (which applies from the general date).
"El AI Act no sustituye al RGPD: se suma. Quien hoy implanta un sistema de IA y solo mira la protección de datos está leyendo media partitura. La otra media es el riesgo del propio sistema, la supervisión humana y la documentación técnica. La empresa que entienda que son dos marcos articulados, no dos paralelos, llegará a 2026 sin sobresaltos."
Mario P. Talamillo · Managing Partner, Certix®
Interaction with other legislation
The AI Act fits into a broad European regulatory ecosystem. These are the most relevant interactions:
- GDPR (Regulation EU 2016/679) and Regulation EU 2018/1725: art. 2.7 expressly states that the AI Act does not affect their application. The DPIA under art. 35 GDPR and the FRIA under art. 27 of the AI Act coexist and must be coordinated.
- Directive (EU) 2016/680 (Organic Law 7/2021 in Spain): data protection in the criminal-law context. Applies to most uses under art. 5.1.h.
- NIS2 Directive (EU 2022/2555): cybersecurity of essential and important entities. Overlaps with the cybersecurity requirement under arts. 15 and 55.1.d of the AI Act.
- Data Act (EU 2023/2854) and Data Governance Regulation (EU 2022/868): govern access, sharing and reuse of data that feeds AI systems.
- Digital Services Act (DSA — EU 2022/2065): regulation of online platforms. Art. 2.5 of the AI Act preserves its application to providers of intermediary services.
- Directive (EU) 2019/790 on copyright: GPAI providers must respect the rights reservation under art. 4.3 of that Directive (art. 53.1.c AI Act).
- Sector-specific regulations listed in Annex I: medical devices (EU 2017/745 and EU 2017/746), automotive, aviation, toys, machinery, etc. AI systems that are safety components of these products follow 'Route 1' of art. 6.
Good practice: what to do today in your organisation
Although general application of the AI Act starts in August 2026, there are decisions to be taken now. These are the priorities for 2025–2026:
| ✓ | Action | Reference |
|---|---|---|
| □ | Inventory of AI systems in use (in-house, embedded in SaaS, GPAI via API). | Art. 3.1 and art. 3.4 (deployer) |
| □ | Classification of each system by risk tier (prohibited, high, limited, minimal). | Arts. 5, 6 and Annex III |
| □ | Review of prohibited practices: emotion recognition at work or in classrooms, biometric categorisation, facial scraping. | Art. 5 (applicable from 2 Feb 2025) |
| □ | Internal generative AI use policy: scope, data that may or may not be entered into prompts, person responsible for review. | Art. 4 (literacy) and art. 50 |
| □ | Contractual clauses with GPAI and AI-enabled SaaS providers: information rights (Annex XII), data processing, intellectual property. | Art. 53 + art. 28 GDPR |
| □ | Dedicated entry for AI systems in the GDPR record of processing activities: purpose, legal basis, data processed, human oversight, automated decisions (art. 22 GDPR). | Art. 30 GDPR + art. 13 AI Act |
| □ | Staff training in AI literacy, tailored to their role and to the type of system they use. | Art. 4 (applicable from 2 Feb 2025) |
| □ | Information to workers before deploying high-risk AI systems in the workplace. | Art. 26.7 |
| □ | Labelling of synthetic content generated by the organisation (text, audio, image, video) and of deepfakes. | Art. 50.2 and 50.4 |
| □ | Serious-incident management protocol coordinated with the GDPR breach protocol. | Art. 73 AI Act + arts. 33–34 GDPR |
The AI Act is not a paperwork exercise: it is an operational transformation that affects procurement, HR, product, marketing and security. The sooner it is approached as a cross-cutting project — and not merely as an appendix to the GDPR compliance plan — the more efficient the road to August 2026 will be.
At Certix we support technology companies and organisations across all sectors in articulating the AI Act with their existing data protection programme. You can review our approach for the tech sector at data protection consulting for technology companies.
This content is provided for information and educational purposes only; it does not constitute specialised legal advice. The application of Regulation (EU) 2024/1689 to any specific case requires an individual analysis of the AI system, of the organisation's role (provider, deployer, importer, distributor) and of the interplay with other rules, in particular the GDPR and the LOPDGDD. The figures for the penalties are cited for technical and informational purposes only and not as a decision-making criterion. The authoritative interpretation lies with the European Commission, the European AI Office, the European AI Board and, in Spain, AESIA, without prejudice to the AEPD's competences in matters of personal data protection. Regional sector-specific legislation may amend or supplement these requirements.