With €1.2 billion in GDPR fines issued in 2024 alone and the EU AI Act’s full applicability deadline set for August 2, 2026, European organisations face a convergence of regulatory pressure that demands immediate, coordinated action. Recent opinions from EU regulators — including targeted GDPR revision proposals and evolving AI Act timelines — signal not a relaxation of standards, but a structural recalibration of how innovation and data privacy are expected to coexist. For CFOs, General Counsel, and enterprise risk teams, the window to establish compliant AI governance frameworks is narrowing fast.
The Regulatory Convergence: GDPR Revisions Meet AI Act Obligations
The European Data Protection Board (EDPB) has issued a landmark opinion supporting targeted revisions to the GDPR, specifically to accommodate AI development workflows. Key proposals include narrow derogations for incidental processing of special category data during AI model training — subject to robust safeguards — and clearer rules governing scientific research exemptions. Simultaneously, the European Commission’s Q4 2025 GDPR amendment package proposes reshaping cookie consent mechanisms, expanding SME exemptions, and explicitly clarifying AI-related obligations under existing data privacy law.
These revisions do not operate in isolation. The EDPB has also confirmed that large language models rarely meet the threshold for GDPR anonymisation, meaning organisations deploying third-party LLMs must conduct legitimate interests assessments and, in many cases, mandatory Data Protection Impact Assessments (DPIAs). Biometric data processing and questions of model training data provenance further trigger DPIA requirements — a compliance burden that sits squarely with both data controllers and AI deployers.
On the AI Act side, proposals are circulating to postpone certain high-risk AI obligations from August 2026 to December 2027, while relaxing registration requirements for low-risk systems and expanding regulatory sandboxes. However, organisations should not treat this as a reprieve. Classification of AI systems, conformity assessments, and technical documentation requirements remain live obligations, with fines of up to 7% of global annual turnover for the most serious breaches.
Dual Compliance Risk: Where GDPR and the AI Act Intersect
The practical challenge for enterprise risk management lies in the overlap. Any AI system that processes personal data — which encompasses the vast majority of enterprise AI deployments, from HR analytics to fraud detection — is simultaneously subject to GDPR obligations and AI Act requirements. This dual exposure creates compounding liability risk that neither legal nor technology teams can manage in isolation.
Three pressure points demand immediate board-level attention:
- AI system classification: Organisations must audit and classify all deployed and in-development AI systems against the AI Act’s risk tiers. High-risk designations — covering areas such as credit scoring, recruitment, and critical infrastructure management — carry the heaviest documentation and conformity assessment obligations.
- Data provenance and training transparency: The EDPB’s position on LLM anonymisation means that data lineage for AI training sets must be documented and defensible. Contracts with third-party AI vendors should be reviewed to ensure data processing agreements reflect current regulatory expectations.
- DPIA integration into AI governance: DPIAs should no longer be treated as standalone compliance exercises. They must be embedded within AI project governance frameworks, triggered at the design stage and updated as systems evolve.
Implications for Business: Governance, Investment, and M&A Due Diligence
From a corporate governance perspective, the EDPB’s 2026–2027 work programme signals sustained enforcement focus on AI-related data privacy. Boards and audit committees should expect regulators to scrutinise AI governance frameworks with the same rigour applied to financial controls. Organisations that have not yet appointed or empowered a cross-functional AI compliance function — bridging legal, technology, and risk — are exposed.
For M&A practitioners, AI Act and GDPR compliance status is rapidly becoming a material due diligence consideration. Target companies with unclassified AI systems, inadequate DPIAs, or opaque data training practices represent quantifiable regulatory liability. Acquirers should incorporate AI compliance assessments into standard pre-close diligence protocols, particularly in sectors such as financial services, healthcare, and HR technology.
SMEs and mid-market AI providers should monitor the proposed GDPR SME exemptions and expanded regulatory sandboxes closely, as these mechanisms may offer structured pathways to compliant AI development without the full compliance overhead applied to large enterprises.
Key Takeaway
The evolving EU regulatory landscape does not offer organisations a choice between innovation and compliance — it demands both, simultaneously. The convergence of GDPR revisions and AI Act obligations creates a dual compliance imperative that requires integrated enterprise risk management, not sequential legal review. Organisations that begin AI system classification, DPIA integration, and vendor contract remediation now will be materially better positioned than those awaiting final regulatory text. With August 2026 as the operative deadline and enforcement machinery already active, the cost of inaction is measurable — and rising.