The AI Act and the GDPR do not address the same thing: the GDPR protects personal data, while the AI Act governs artificial intelligence systems. Both apply at the same time as soon as your AI touches customer, employee or prospect data. For an SME, the real question is not which one to follow, but how to fit both into a single compliance effort.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
The AI Act and the GDPR do not address the same thing: the GDPR protects personal data, while the AI Act governs artificial intelligence systems. Both apply at the same time as soon as your AI touches customer, employee or prospect data. For an SME, the real question is not which one to follow, but how to fit both into a single compliance effort. This comparison covers the concrete differences, where they overlap, and what you actually need to do. For the full picture, start with our complete EU AI Act guide for SMEs.
The GDPR protects people through their data; the AI Act protects people through AI systems. The GDPR is Regulation (EU) 2016/679, in force since May 2018. It applies whenever data can identify someone, directly or indirectly: a name, an email, a customer number, an IP address. Its scope is the processing of personal data, whatever tool is involved.
The AI Act is Regulation (EU) 2024/1689, in force since 1 August 2024. It does not talk about data but about AI systems, which it classifies by risk level: prohibited, high risk, limited risk (transparency obligations), minimal risk. A system can fall under the AI Act even without personal data, for example a model that scores files using only anonymous technical inputs.
Put simply: the GDPR looks at what you do with data, the AI Act looks at what the system does and the danger it poses to people's rights.
As soon as an AI system processes personal data, the GDPR and the AI Act stack up. This is the most common case in an SME: a CV screening tool, a chatbot answering customers, a sales scoring system. You then have to meet both regimes, not choose between them.
A telling example: you want to train or fine tune a model on your customer exchanges. On the GDPR side, this training is processing, so you need a legal basis (legitimate interest, consent, contract), you must inform people, and you must set a retention period. On the AI Act side, you must check the system's risk category, document how it works, and provide human oversight where the use case calls for it. Both obligations coexist on the same project.
The same holds for consumer generative AI. Using ChatGPT or Claude with customer data triggers the GDPR (data transfer and processing), while the AI Act imposes its transparency obligations on generated content. To see exactly who carries which obligation across the chain, read our article on who is affected by the AI Act.
The table below sums up the gaps that matter for an SME.
| Criterion | GDPR (EU 2016/679) | AI Act (EU 2024/1689) |
|---|---|---|
| What it protects | Personal data | AI systems and their effects |
| Trigger | Processing identifying data | Developing, providing or using an AI system |
| Logic | One obligation, whatever the risk | Graduated obligations by risk level |
| Key document | Record of processing, DPIA | AI register, technical documentation |
| Authority in France | The CNIL | The CNIL (designated AI authority), with the EU AI Office |
| In force since | May 2018 | 1 August 2024, phased in through 2028 |
| Maximum fine | 20 M€ or 4 % of global turnover | 35 M€ or 7 % of global turnover |
Both texts share the same philosophy: document, keep records, keep a human in the loop. Many companies find that their GDPR work gives them a head start on the AI Act.
The most useful overlap is the impact assessment, which you can largely reuse. The GDPR requires a data protection impact assessment (DPIA, Article 35) when processing poses a high risk to people. The AI Act, in Article 27, provides for a fundamental rights impact assessment for certain high-risk systems.
These two exercises are not identical, but they feed each other. Data mapping, risk assessment and the description of safeguards are largely shared. A well-organised SME runs a single documentation effort covering both needs, rather than two parallel projects. You save time and avoid contradictions between documents.
Another shared area is human oversight. The GDPR frames fully automated decisions (Article 22), the AI Act requires human oversight of high-risk systems. In practice, you must be able to say who controls the machine, how, and at what point a human can step back in. If your use case is high risk, our article on high-risk AI systems details these obligations.
The GDPR already applies in full; the AI Act arrives in waves, some of which were pushed back in 2026. Here are the milestones to remember:
This high-risk deferral does not mean you can wait. Training has been due since 2025, and the GDPR never moved. For every date, our full AI Act timeline is kept up to date, as is the Article 4 training obligation.
The AI Act hits harder than the GDPR on the most serious breaches. The GDPR caps fines at 20 M€ or 4 % of annual global turnover, whichever is higher. The AI Act rises to 35 M€ or 7 % for using a prohibited practice, and sets 15 M€ or 3 % for other breaches.
A single incident can fall under both regimes. An illegal customer scoring system fed without a legal basis can expose you to a GDPR fine (the processing) and an AI Act fine (the system). The authorities do not use the same grid, but they can look at the same case. The amounts and cases are detailed in our article on AI Act sanctions.
Integrated compliance comes down to a few workstreams, run once for both texts. Here is the order that works best in practice:
This approach avoids the classic trap: treating the AI Act as a brand-new project when 60 % to 70 % of the work overlaps with what you already did for the GDPR.
Does the AI Act replace the GDPR? No. Both regulations coexist. The GDPR remains the reference for any personal data, the AI Act adds a layer specific to AI systems. When your AI processes data, both apply together.
Is my SME covered by the AI Act if it only uses ChatGPT? Yes, as a user (deployer) of an AI system. Your obligations are lighter than a provider's, but training your teams and being transparent with customers still apply, on top of the GDPR on the data you enter.
Can I reuse my DPIA for the AI Act? Largely. The Article 27 fundamental rights impact assessment shares a lot with the Article 35 GDPR DPIA. You do not start from scratch: you add the part specific to fundamental rights and to how the system works.
Which authority oversees what in France? The CNIL oversees the GDPR and has been designated as one of the competent authorities for AI. It works with the EU AI Office on general-purpose models. A single case can therefore involve both regimes before the same body.
Does the high-risk deferral to December 2027 leave me in the clear? No. Only the deadline for Annex III high-risk systems moved. Prohibited practices, the training obligation and the GDPR remain fully in force. The deferral is extra time for the heaviest cases, not a general pause.
How much does cross-compliance cost for an SME? It depends on the number of systems and the sensitivity of the data. An SME with a solid GDPR base mostly deals with mapping and classification work, often achievable in a few weeks with targeted support.
At GrowthPerf, we treat the AI Act and the GDPR as one effort, not two projects. We map your AI systems and your processing, classify the risks, and train your teams to use AI tools compliantly, which Article 4 of the AI Act makes mandatory. Our AI training for business is Qualiopi-certified and fundable, and our audits build on what you already have in place for the GDPR to avoid duplicated work. For the full framework, go back to our complete EU AI Act guide for SMEs.
Want to know where your dual compliance stands? Book a free, no-commitment 30-minute AI Act and GDPR cross-audit.