ai governance

EU AI Act, data protection and information security in AI projects

The AI Act, GDPR and information security ask different but complementary questions about purpose, data, role, risk and operation of an AI system.

Illustrative decision scene: leaders review an AI recommendation and approve the critical step
Human in the loopAI prepares. People review and decide.Illustrative visual

The actual use matters more than the label

Whether and which duties apply depends on factors including the organisation's role, the system's purpose, people affected and the effects of outcomes or actions. Not every AI system is automatically a high-risk AI system.

Providers, deployers, importers and other parties may have different responsibilities. The classification needs to be documented for the actual system and context of use.

Application status of the EU AI Act on 11 August 2026

The EU AI Act applies in stages. Prohibitions on specified practices have applied since 2 February 2025. The Digital Omnibus (EU) 2026/1744, in force since 27 July 2026, amended Article 4: providers and deployers must take measures to support the development of AI literacy among staff and others operating or using AI systems on their behalf, but need not guarantee any specific individual level. Governance and GPAI provisions have applied since 2 August 2025; other provisions apply from 2 August 2026 or under the amended transitional dates.

The Digital Omnibus moved application of the high-risk rules to 2 December 2027 for high-risk AI systems listed in Annex III and to 2 August 2028 for high-risk AI systems that are components of regulated products. The current consolidated official text is always decisive for an assessment.

  • status date: 11 August 2026
  • identify role and purpose
  • justify risk category
  • check current transitional rule
  • document evidence and ownership

High-risk duties cover the lifecycle

For high-risk AI systems, the AI Act addresses areas including risk management, data and quality requirements, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity. Deployers may have additional duties depending on the case.

This list does not classify a particular project. Similar controls may still be sound technical and organisational practice before any formal high-risk classification.

The GDPR examines purpose and personal-data processing

Where personal data is processed, principles including purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability remain relevant. Data protection by design and by default belong in solution design.

Legal basis, information duties, data-subject rights, processors, transfers and a possible data protection impact assessment require case-specific review by qualified specialists.

Information security protects the system, data and knowledge base

Risk analysis considers confidentiality, integrity and availability of input, knowledge sources, tools and outcomes. Least privilege, separated roles, reviewed sources, secure interfaces, change evidence, recovery and stop procedures can limit harm.

Generative AI adds risks such as manipulated input or knowledge collections, unintended disclosure and unreliable output. BSI recommends a use-case and lifecycle assessment rather than a blanket security claim.

Questions for the project decision

Before a pilot or expansion, purpose, participants, data categories, permitted actions, possible effects and necessary human controls are considered together. Open legal or security-critical questions are not replaced by technical assumptions.

  • What role does the organisation have?
  • Which data and people are affected?
  • Which outcomes or actions have an effect?
  • Who may review, approve and stop?
  • Which evidence, tests and ongoing controls are necessary?
  • Which qualified legal or security review is still missing?

Source note

Status: 11 August 2026. General guidance based on the official EU AI Act and GDPR texts, amending Regulation (EU) 2026/1744, current European Commission guidance and BSI risk analysis. This is not legal advice and does not classify or claim conformity for a specific system.

Primary sources

Official sources, editorially checked on 11 August 2026.

Which process should work better in your organisation?

We begin with the work, the people and the current process — then assess which form of AI genuinely makes sense.

Discuss your process