Skip to content

AI law comparison · Data verified 2026-08-22

EU AI Act vs GDPR Article 22

EU AI Act and GDPR Article 22 are two of the 169 AI and data regulations Aegis Firma tracks. They have different scopes, effective dates, and penalties — and many businesses fall under both. Here is the side-by-side, drawn directly from the regulatory registry.

Find which laws apply to my business

Side by side

Attribute
EU AI Act
GDPR Article 22
Region
EU
EU
Effective date
2024-08-01
2018-05-25
Enforcement begins
2026-08-02
Who must comply
Applies to: (1) providers placing AI systems on EU market or putting into service, (2) deployers using AI systems within EU, (3) providers/deployers in third countries when output used in EU, (4) importers and distributo…
GDPR Art. 22 applies to: (1) any organization established in the EU/EEA; (2) organizations outside the EU/EEA that offer goods or services to EU/EEA data subjects or monitor their behavior. The "solely automated" thresho…
Maximum penalty
€35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities
€20,000,000 or 4% of global annual turnover — whichever is higher (GDPR Art. 83(5))
Compliance requirements
10 tracked
5 tracked
Enforcement actions on record
2
2
Data last verified
2026-08-22
2026-08-22

Summary of publicly available regulatory text. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

The key difference

GDPR Article 22 takes effect first, so it is usually the more urgent of the two. EU AI Act tracks 10 compliance requirements and GDPR Article 22 tracks 5. They are not interchangeable — meeting one does not discharge the other. The practical question is not which law is “stricter,” but which of them — or both — actually applies to your business.

EU

EU Artificial Intelligence Act

Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, critical infrastructure, law enforcement), limited-risk (transparency obligations for chatbots and deepfakes), minimal-risk (most AI tools). Providers AND deployers have obligations. Extraterritorial: applies when the AI s…

Full EU AI Act requirements
EU

EU GDPR Article 22 — Automated Decision-Making & AI Profiling

GDPR Article 22 (in force since May 25, 2018) gives EU and EEA residents the right not to be subject to decisions based solely on automated processing — including AI profiling — that produces legal or similarly significant effects (credit scores, hiring, insurance pricing, content moderation). Organizations must inform individuals of automated processing, provide meaningful explanations of logic, implement human revi…

Full GDPR Article 22 requirements

Common questions

Could both EU AI Act and GDPR Article 22 apply to my business?

Yes. EU AI Act and GDPR Article 22 are separate regulations with separate scopes — a business can fall under both at once. EU AI Act covers Applies to: (1) providers placing AI systems on EU market or putting into service, (2) deployers using AI systems within EU, (3) providers/deployers in third co… GDPR Article 22 covers GDPR Art. If your operations meet both scopes, you must comply with both. Aegis Firma's free scan checks all 169 tracked regulations against your business profile so you do not have to read each law to find out.

Which has the higher maximum penalty — EU AI Act or GDPR Article 22?

EU AI Act: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities GDPR Article 22: €20,000,000 or 4% of global annual turnover — whichever is higher (GDPR Art. 83(5)) Penalty structures differ by regulator and violation type — read each law's full page for the cure periods and per-violation detail.

When does each law take effect?

EU AI Act — effective 2024-08-01, enforcement from 2026-08-02. GDPR Article 22 — effective 2018-05-25. Dates last verified against official sources on 2026-08-22 and 2026-08-22 respectively.

Related comparisons

See all law comparisons

Stop guessing which laws apply

Answer a short questionnaire about your business and Aegis Firma tells you exactly which of 169 regulations apply — and what each one requires you to do.

Start free compliance scan