Key takeaways
- The AI Act entered into force on 1 August 2024 and applies in phases; the prohibited practices and the AI literacy obligation have applied since 2 February 2025.
- Which obligations you have depends on the risk category of the application and on your role: provider or deployer.
- The GDPR applies as soon as personal data is processed, including when this happens through an AI tool.
- Data minimisation is the most important lever with AI: the less data that goes to the model, the smaller the risk.
- Always check the current status of the rules and, if in doubt, involve your data protection officer or a lawyer.
Two sets of rules side by side
The AI Act (Regulation (EU) 2024/1689) governs AI systems: which applications are prohibited, which must meet strict requirements and where transparency is enough. The GDPR (known in the Netherlands as the AVG) governs the processing of personal data. They complement each other: an AI application can be low-risk under the AI Act and still require a fair amount of GDPR work, for example when customer or employee data is involved.
This article helps you ask the right questions about AI Act compliance and the GDPR. It is not legal advice. The rules and their interpretation are still evolving; put specific applications to your data protection officer or a lawyer.
The AI Act timeline
The AI Act does not apply all at once, but in phases. At the end of 2025, the European Commission proposed adjusting parts of this schedule, including for high-risk systems (the so-called Digital Omnibus package). So always check the current status, for example via the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), which publishes extensive guidance on AI and algorithms in the Netherlands, via your own national supervisory authority, or via the official EU sources.
| Date | What starts to apply |
|---|---|
| 1 August 2024 | The AI Act enters into force. |
| 2 February 2025 | The ban on AI practices posing an unacceptable risk, and the AI literacy obligation. |
| 2 August 2025 | Obligations for providers of general-purpose AI models. |
| Later, in phases | Most other obligations, including those for many high-risk systems. Originally planned from 2 August 2026 and, for certain products, from 2027; the EU has proposed adjusting parts of this. |
Risk categories in the AI Act
The AI Act classifies AI systems by risk. The greater the risk to health, safety or fundamental rights, the stricter the requirements. Separate rules apply to general-purpose AI models, such as the language models behind well-known chatbots; these obligations fall mainly on the providers of those models.
Your role also matters. The provider develops an AI system and places it on the market; the deployer uses it under its own authority. If you use an AI tool for internal analysis, you are usually a deployer. A tool that writes SQL for internal reporting usually does not fall into the high-risk category, but the purpose matters: if you use the outcomes to assess employees or to decide on the creditworthiness of individuals, that may be different.
| Category | What it means | Examples |
|---|---|---|
| Unacceptable risk | Prohibited | Social scoring, manipulative techniques that cause people harm, emotion recognition in the workplace or in education (with a few exceptions), untargeted scraping of facial images |
| High risk | Permitted subject to strict requirements, such as risk management, data quality, documentation, logging and human oversight | AI for recruitment and selection or for assessing employees, creditworthiness of individuals, access to education or essential services, safety components of products |
| Limited risk (transparency) | People must know they are dealing with AI | Chatbots, AI-generated or manipulated content such as deepfakes |
| Minimal risk | No specific AI Act requirements, apart from AI literacy | Spam filters, recommendations in software, many internal analytics tools |
AI literacy: an obligation that already applies
Since 2 February 2025, providers and deployers must take measures to ensure that their staff have a sufficient level of AI literacy, regardless of the risk category. People who work with AI need to know what the tool can and cannot do, what data they may put into it and how to check its outcomes.
In practice, that means a short training session per target group, clear guidelines for AI use and a record of who has completed what. For AI on business data, this includes users critically reviewing a generated query or chart before drawing conclusions.
The GDPR and AI on business data
As soon as personal data is processed, the GDPR applies, including when this happens through an AI tool. Think of customer names in a CRM, employee data in a planning system or email addresses in an order history.
A lawful basis might be, for example, the performance of a contract or legitimate interests; the latter requires a balancing test. You conclude a data processing agreement with every party that processes personal data on your behalf, such as a platform supplier or an AI provider. In the Netherlands, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) publishes a list of processing operations for which a DPIA is always required; in Belgium, the contact point is the Data Protection Authority (Gegevensbeschermingsautoriteit), and other EU countries each have their own national supervisory authority. The main topics at a glance:
| Topic | What the GDPR requires | Practical question for AI |
|---|---|---|
| Lawful basis and purpose | A valid lawful basis (Article 6) and a clear, well-defined purpose | May I use this data for this AI purpose? |
| Data processing agreement | Agreements with parties that process data on your behalf (Article 28) | Which suppliers see personal data, and where? |
| Data minimisation | Do not process more data than necessary (Article 5) | Does the model need to see rows of data, or is the structure enough? |
| DPIA | Mandatory where processing is likely to result in a high risk (Article 35) | Is the processing large-scale, sensitive or monitoring in nature? |
| Security | Appropriate technical and organisational measures (Article 32) | Who has access, and is it logged? |
| Transfers | Rules for processing outside the EEA (Chapter V) | Does the AI provider process data outside the EU, and on what basis? |
AI governance in practice
AI governance is the way your organisation makes agreements about the use of AI and monitors those agreements. For AI on business data, this checklist is a good start:
- Keep a register of AI applications: what does the tool do, for what purpose and with what data?
- Determine the risk category under the AI Act for each application, and whether personal data is involved.
- Record which data may go to which AI model, and where possible choose metadata or aggregated data instead of raw rows.
- Arrange access and logging: who may use the AI features, on which data, and who did what?
- Have people check and confirm AI outcomes before they are used.
- Make sure you can switch AI off without the rest of your reporting stopping.
- Schedule a periodic review of applications, suppliers and agreements.
What ENABLE does here, and what it does not
ENABLE has a number of measures that align with this checklist. The AI receives only metadata, such as table and column names and the data dictionary, plus the user's question; never rows of data or passwords. By default, the SQL Explorer with AI is available to administrators only, queries run read-only and every query that is run is recorded in the audit log. AI outcomes are only used after an action by the user. Access profiles, roles and row-level security determine who sees what, and an activity log records actions. The portal is hosted in Frankfurt; the AI works through the OpenAI API.
That does not make an application automatically compliant. Whether you comply with the AI Act and the GDPR depends on your purpose, your data, your agreements and your organisation. Also pay attention to what users type in themselves: the question is sent to the AI, so do not include personal data in it.