EnableYourData.nl

Resources · Governance

The AI Act and GDPR for AI on business data: what to look out for

If you use AI on business data in the EU, two sets of rules apply: the AI Act, which sets requirements for AI systems based on their risk, and the GDPR, which applies as soon as personal data is processed. For most internal analytics applications, the focus is mainly on AI literacy, transparency and the GDPR basics: a lawful basis, a data processing agreement, data minimisation and, where necessary, a DPIA. This article is a practical orientation, not legal advice.

Key takeaways

  • The AI Act entered into force on 1 August 2024 and applies in phases; the prohibited practices and the AI literacy obligation have applied since 2 February 2025.
  • Which obligations you have depends on the risk category of the application and on your role: provider or deployer.
  • The GDPR applies as soon as personal data is processed, including when this happens through an AI tool.
  • Data minimisation is the most important lever with AI: the less data that goes to the model, the smaller the risk.
  • Always check the current status of the rules and, if in doubt, involve your data protection officer or a lawyer.

Two sets of rules side by side

The AI Act (Regulation (EU) 2024/1689) governs AI systems: which applications are prohibited, which must meet strict requirements and where transparency is enough. The GDPR (known in the Netherlands as the AVG) governs the processing of personal data. They complement each other: an AI application can be low-risk under the AI Act and still require a fair amount of GDPR work, for example when customer or employee data is involved.

This article helps you ask the right questions about AI Act compliance and the GDPR. It is not legal advice. The rules and their interpretation are still evolving; put specific applications to your data protection officer or a lawyer.

The AI Act timeline

The AI Act does not apply all at once, but in phases. At the end of 2025, the European Commission proposed adjusting parts of this schedule, including for high-risk systems (the so-called Digital Omnibus package). So always check the current status, for example via the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), which publishes extensive guidance on AI and algorithms in the Netherlands, via your own national supervisory authority, or via the official EU sources.

DateWhat starts to apply
1 August 2024The AI Act enters into force.
2 February 2025The ban on AI practices posing an unacceptable risk, and the AI literacy obligation.
2 August 2025Obligations for providers of general-purpose AI models.
Later, in phasesMost other obligations, including those for many high-risk systems. Originally planned from 2 August 2026 and, for certain products, from 2027; the EU has proposed adjusting parts of this.

Risk categories in the AI Act

The AI Act classifies AI systems by risk. The greater the risk to health, safety or fundamental rights, the stricter the requirements. Separate rules apply to general-purpose AI models, such as the language models behind well-known chatbots; these obligations fall mainly on the providers of those models.

Your role also matters. The provider develops an AI system and places it on the market; the deployer uses it under its own authority. If you use an AI tool for internal analysis, you are usually a deployer. A tool that writes SQL for internal reporting usually does not fall into the high-risk category, but the purpose matters: if you use the outcomes to assess employees or to decide on the creditworthiness of individuals, that may be different.

CategoryWhat it meansExamples
Unacceptable riskProhibitedSocial scoring, manipulative techniques that cause people harm, emotion recognition in the workplace or in education (with a few exceptions), untargeted scraping of facial images
High riskPermitted subject to strict requirements, such as risk management, data quality, documentation, logging and human oversightAI for recruitment and selection or for assessing employees, creditworthiness of individuals, access to education or essential services, safety components of products
Limited risk (transparency)People must know they are dealing with AIChatbots, AI-generated or manipulated content such as deepfakes
Minimal riskNo specific AI Act requirements, apart from AI literacySpam filters, recommendations in software, many internal analytics tools

AI literacy: an obligation that already applies

Since 2 February 2025, providers and deployers must take measures to ensure that their staff have a sufficient level of AI literacy, regardless of the risk category. People who work with AI need to know what the tool can and cannot do, what data they may put into it and how to check its outcomes.

In practice, that means a short training session per target group, clear guidelines for AI use and a record of who has completed what. For AI on business data, this includes users critically reviewing a generated query or chart before drawing conclusions.

The GDPR and AI on business data

As soon as personal data is processed, the GDPR applies, including when this happens through an AI tool. Think of customer names in a CRM, employee data in a planning system or email addresses in an order history.

A lawful basis might be, for example, the performance of a contract or legitimate interests; the latter requires a balancing test. You conclude a data processing agreement with every party that processes personal data on your behalf, such as a platform supplier or an AI provider. In the Netherlands, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) publishes a list of processing operations for which a DPIA is always required; in Belgium, the contact point is the Data Protection Authority (Gegevensbeschermingsautoriteit), and other EU countries each have their own national supervisory authority. The main topics at a glance:

TopicWhat the GDPR requiresPractical question for AI
Lawful basis and purposeA valid lawful basis (Article 6) and a clear, well-defined purposeMay I use this data for this AI purpose?
Data processing agreementAgreements with parties that process data on your behalf (Article 28)Which suppliers see personal data, and where?
Data minimisationDo not process more data than necessary (Article 5)Does the model need to see rows of data, or is the structure enough?
DPIAMandatory where processing is likely to result in a high risk (Article 35)Is the processing large-scale, sensitive or monitoring in nature?
SecurityAppropriate technical and organisational measures (Article 32)Who has access, and is it logged?
TransfersRules for processing outside the EEA (Chapter V)Does the AI provider process data outside the EU, and on what basis?

AI governance in practice

AI governance is the way your organisation makes agreements about the use of AI and monitors those agreements. For AI on business data, this checklist is a good start:

  1. Keep a register of AI applications: what does the tool do, for what purpose and with what data?
  2. Determine the risk category under the AI Act for each application, and whether personal data is involved.
  3. Record which data may go to which AI model, and where possible choose metadata or aggregated data instead of raw rows.
  4. Arrange access and logging: who may use the AI features, on which data, and who did what?
  5. Have people check and confirm AI outcomes before they are used.
  6. Make sure you can switch AI off without the rest of your reporting stopping.
  7. Schedule a periodic review of applications, suppliers and agreements.

What ENABLE does here, and what it does not

ENABLE has a number of measures that align with this checklist. The AI receives only metadata, such as table and column names and the data dictionary, plus the user's question; never rows of data or passwords. By default, the SQL Explorer with AI is available to administrators only, queries run read-only and every query that is run is recorded in the audit log. AI outcomes are only used after an action by the user. Access profiles, roles and row-level security determine who sees what, and an activity log records actions. The portal is hosted in Frankfurt; the AI works through the OpenAI API.

That does not make an application automatically compliant. Whether you comply with the AI Act and the GDPR depends on your purpose, your data, your agreements and your organisation. Also pay attention to what users type in themselves: the question is sent to the AI, so do not include personal data in it.

FAQ

Frequently asked questions

When does the AI Act apply?

The AI Act entered into force on 1 August 2024 and applies in phases. The ban on certain AI practices and the AI literacy obligation have applied since 2 February 2025, and the rules for general-purpose AI models since 2 August 2025. Most other obligations follow later. The EU has proposed adjusting parts of that schedule, so check the current status.

Does AI on business data fall under the AI Act?

An AI system falls under the AI Act, but the obligations depend on the risk. A tool that translates questions about revenue or stock into SQL usually falls into a low risk category, although AI literacy always applies. If you use AI for decisions about people, such as assessing employees, the application may be high-risk.

What is AI literacy under the AI Act?

AI literacy means that staff who work with AI have enough knowledge and skills to do so responsibly: they know what an AI tool can and cannot do, what data they may enter and how to check outcomes. Organisations that provide or use AI have had to take measures for this since 2 February 2025.

Is a DPIA mandatory if you use AI?

Not always. A DPIA is mandatory if processing personal data is likely to result in a high risk, for example with large-scale processing of sensitive data or systematic monitoring of people. Even when it is not mandatory, a short risk analysis helps you justify your choices.

How do you use AI in a GDPR-compliant way?

Start with a clear lawful basis and a well-defined purpose, conclude data processing agreements with your suppliers and send as little personal data as possible to the AI model. A set-up in which the AI sees only metadata and no rows of data helps with this. Record your considerations and involve your data protection officer.

Is ENABLE compliant with the AI Act or the GDPR?

ENABLE does not claim compliance on your behalf: whether an application complies depends on your purpose, data and agreements. The platform does have measures that help, such as AI that receives only metadata, AI features that are available to administrators only by default, read-only queries, access management and an activity log.

Share securely, live fast, no headache

In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.