EU AI Act + GDPR • U.S. → EU
EU AI Act and GDPR compliance for U.S. companies using AI in Europe
A U.S. company can face both regimes at the same time. The efficient approach is to collect the system facts once, then run separate EU AI Act and GDPR legal tests and reuse evidence only where the requirements genuinely overlap.
Published / updated: 26 September 2026 · Reviewed by Constantin Razvan Gospodin · EUAIACTUS.COM is a service provided by Lexara Advisory LLC.
Short answer
The same AI system can trigger two different European compliance frameworks.
The EU AI Act applies through its own territorial and actor rules, including Article 2. GDPR applies when personal data processing falls within its material and territorial scope, including Article 3. Neither framework substitutes for the other.
EU AI Act analysis
Identify EU nexus, provider/deployer/importer/distributor or other role, prohibited practices, Article 50 transparency, GPAI responsibilities, high-risk classification and the applicable timetable.
GDPR analysis
Identify personal-data processing, controller/processor roles, lawful basis, transparency, Article 22 automated decisions, DPIA requirements, data-subject rights, security and international-transfer mechanisms.
Extraterritorial reach
A U.S. headquarters does not end the analysis.
EU AI Act Article 2
The Act can apply to third-country providers placing AI systems or GPAI models on the EU market and to certain non-EU providers or deployers where AI-system output is used in the Union. The exact role and facts matter.
GDPR Article 3
GDPR can apply to a non-EU controller or processor when processing relates to offering goods or services to people in the Union or monitoring their behaviour there. This is a different territorial test from the AI Act.
The overlap map
Six areas where U.S. AI teams should run coordinated reviews
1. Automated decisions and profiling
Where AI drives or materially shapes decisions about people, GDPR Article 22 and related safeguards may matter. Separately, the AI Act may classify the system by intended purpose and impose system-level or deployer/provider duties.
2. DPIA and AI risk management
A GDPR DPIA assesses high risks to individuals from personal-data processing. AI Act risk-management and classification work asks different legal questions. Teams can reuse system facts, testing and controls without merging the conclusions.
3. Transparency
GDPR information duties and AI Act Article 50 disclosures can appear in the same user journey. They should be designed together but mapped to the separate legal provisions they satisfy.
4. Human involvement and oversight
Meaningful human involvement matters to GDPR automated-decision analysis. High-risk AI can separately require human-oversight design and operational controls under the AI Act.
5. Vendors, models and data flows
One vendor relationship can involve GDPR processor/subprocessor and transfer issues while also creating AI Act value-chain, documentation and compliance-cooperation dependencies.
6. International data transfers
Using AI from the United States can involve EU-to-U.S. personal-data transfers. Transfer compliance is a GDPR question and should be documented alongside, but not confused with, AI Act territorial scope and system obligations.
High-priority use cases
Where combined EU AI Act + GDPR review is especially important
HR, recruitment and worker management
Candidate screening, ranking, performance evaluation, task allocation and employment decisions can raise Annex III classification issues alongside GDPR profiling, transparency, DPIA and Article 22 questions.
Creditworthiness and financial decisions
AI used to evaluate natural-person creditworthiness can fall within Annex III while automated scoring can also require separate GDPR Article 22 analysis. Decision workflow and actual human involvement matter.
Generative and interactive AI
Article 50 can create AI-specific transparency duties while prompts, account data, outputs, logs or model-improvement workflows may separately involve GDPR obligations.
Cross-border SaaS
A U.S. SaaS provider can have EU AI Act exposure through market/output tests while GDPR exposure depends on personal-data processing, EU data subjects and the Article 3 criteria.
Evidence architecture
Build one factual record, then map it to each regulation.
- AI-system inventory, intended purpose, users and affected persons.
- EU AI Act territorial-scope and actor-role determination.
- Personal-data map, controller/processor position and lawful-basis analysis.
- Article 22 decision-workflow and meaningful-human-involvement analysis where relevant.
- DPIA status and high-risk processing rationale where Article 35 is engaged.
- AI Act prohibited-practice, Article 50, GPAI and high-risk classification record.
- EU-U.S. transfer mechanism and vendor/subprocessor data-flow evidence where applicable.
- Human oversight, monitoring, testing, incident and change-management controls.
- Contractual documentation and value-chain cooperation obligations.
- Dates, owners, review triggers and primary sources used for each conclusion.
Common mistakes
Four shortcuts that create avoidable compliance gaps
“Our DPIA covers the AI Act.”
A DPIA can be valuable evidence, but it does not determine AI Act actor role, risk classification, Article 50 or GPAI duties.
“The vendor is compliant, so we are compliant.”
Provider, deployer, controller and processor responsibilities can coexist. Vendor evidence supports your analysis; it does not replace it.
“A human signs off, so Article 22 cannot apply.”
A nominal human step is not the same as meaningful human involvement. The actual decision workflow needs review.
“We are in the U.S., so EU rules are irrelevant.”
Both regimes can reach non-EU organisations, but through different territorial tests. Location alone is not a complete answer.
Frequently asked questions
EU AI Act + GDPR for U.S. companies
Does EU AI Act compliance replace GDPR compliance?
No. The AI Act and GDPR regulate different legal questions. An AI system can be compliant with one framework and still have unresolved obligations under the other.
Can both laws apply to a U.S. company with no EU subsidiary?
Yes, depending on the facts. The EU AI Act has third-country scope rules under Article 2, while GDPR Article 3 can reach certain non-EU controllers and processors offering goods/services to people in the Union or monitoring their behaviour there.
Does a GDPR DPIA satisfy EU AI Act risk management?
No. A DPIA can provide reusable factual and risk evidence, but the legal tests and required conclusions are different.
Does human review automatically avoid GDPR Article 22?
No. The analysis depends on whether the human involvement is meaningful and capable of influencing the decision, not simply whether a person appears somewhere in the workflow.
Primary sources
Official material used for this compliance map
EUR-Lex — EU AI Act consolidated text, including Article 2 scope
EUR-Lex — GDPR, including Articles 3, 22 and 35
EDPB — automated individual decision-making and profiling guidance
EDPB Opinion 28/2024 — data protection aspects of AI models
Combined governance
Map EU AI Act and GDPR obligations around the same AI-system record.
Start with system facts, EU nexus, actor roles, personal-data flows and decision impact. Then build separate legal mappings and a common evidence architecture.