Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
ATMEDIUM coverage1 enforcement action

Austria — DSG + EU AI Act + Austrian AI Strategy: AI Compliance Requirements

Austria's Datenschutzgesetz (DSG) implements GDPR at national level and applies to AI systems processing personal data of Austrian residents. The Datenschutzbehörde (DSB) is Austria's DPA and actively enforces GDPR in AI contexts. Austria published its national AI Strategy ("KI-Strategie") in 2021, emphasizing human-centric AI with sectoral guidance from FinMA (financial AI), Gesundheit Österreich (healthcare AI), and the WKO (business AI frameworks). All EU AI Act obligations apply to Austria-based organisations and those processing Austrian residents' data.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

July 1, 2022

Enforcement Begins

August 2, 2026

Maximum Penalty

DSG/GDPR: up to €20M or 4% of global turnover (DSB enforcement). EU AI Act: €35M or 7% of global turnover.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

EU AI Act Compliance (Mandatory)

Critical

Austria is subject to the EU AI Act. Classify AI systems by risk level. For high-risk AI: technical documentation, conformity assessment, human oversight procedures, registration in the EU database. For limited-risk AI (chatbots, deepfakes): transparency disclosure to users. Prohibited practices ban effective August 2025. NOTE: the EU AI Act high-risk (Annex III) conformity-assessment deadline was deferred EU-wide from 2026-08-02 to 2027-12-02 by the "Digital Omnibus" amendment, Regulation (EU) 2026/1744 (in force 2026-07-27) -- Article 50 transparency obligations still apply from 2026-08-02, but conformity assessment/technical documentation/registration for stand-alone high-risk systems is not due until 2027-12-02 (2028-08-02 for Annex I product-embedded high-risk systems).

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

DSB GDPR Compliance for AI Systems

High Priority

The Datenschutzbehörde enforces GDPR Art. 22 (automated decision-making) strictly. Conduct DPIAs for AI systems processing personal data at scale, implementing profiling, or making consequential automated decisions. Document legal basis for all AI training data sourced from Austrian residents.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA)

Austrian AI Strategy — Sectoral Requirements

Medium Priority

Austria's national AI strategy creates sectoral AI governance expectations. Financial services organisations must comply with FinMA AI guidance. Healthcare AI must meet Gesundheit Österreich guidelines and Austrian Medical Association frameworks. WKO provides voluntary AI certification that improves market trust with Austrian clients.

Who Does This Apply To?

Applies to: any organisation established in Austria, and any organisation outside Austria that processes the personal data of Austrian residents through AI systems — the Datenschutzgesetz (DSG) implements GDPR with extraterritorial reach (Art. 3), so obligations attach to the processing activity, not company size, and there is no general small-business exemption. As an EU member state, Austria is fully subject to the EU AI Act: providers, deployers, importers and distributors must classify each AI system by risk tier, and high-risk systems require conformity assessment, technical documentation, human-oversight procedures and EU-database registration. The Datenschutzbehörde (DSB) enforces GDPR Article 22 strictly for automated decision-making and profiling and requires a DPIA for AI processing at scale — the DPIA does not substitute for AI Act conformity assessment (both regimes apply independently). Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act. Sectoral AI-strategy expectations (FinMA for financial AI, Gesundheit Österreich for healthcare AI, WKO frameworks) apply additionally in regulated and government-procurement contexts.

Recent Enforcement Actions

2026-06-24Source verified· as of 2026-08-22

Against:

Source

Recent Regulatory Guidance

guidance2024-03

DSB AI Guidance — GDPR Compliance for Automated Decision Systems (2024)

Austrian DSB guidance on EU AI Act + GDPR interplay: organizations must conduct both DPIA (GDPR) and conformity assessment (AI Act) for high-risk AI — the DPIA is NOT a substitute for AI Act conformity. DSB publishes a list of high-risk processing activities requiring consultation, updated to include AI recommendation engines, automated credit scoring, and AI HR screening.

Frequently Asked Questions

Does Austria — DSG + EU AI Act + Austrian AI Strategy apply to my business?

Austria's Datenschutzgesetz (DSG) implements GDPR at national level and applies to AI systems processing personal data of Austrian residents. The Datenschutzbehörde (DSB) is Austria's DPA and actively enforces GDPR in AI contexts. Austria published… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Austria — DSG + EU AI Act + Austrian AI Strategy is: DSG/GDPR: up to €20M or 4% of global turnover (DSB enforcement). EU AI Act: €35M or 7% of global turnover.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Austria — DSG + EU AI Act + Austrian AI Strategy?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.bmdw.gv.at/Themen/Wirtschaftsstandort-Oesterreich/Digitalisierung/kuenstliche-intelligenz.html

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan