EU AI Act adds new pressure to GDPR compliance
The EU AI Act is adding a new enforcement layer to GDPR for companies that use automated systems to make decisions about people. The GDPR can impose penalties of €20 million or 4% of global annual turnover for the most serious violations, while the EU AI Act adds a separate ceiling of €35 million or 7% of global turnover for prohibited AI practices.
GDPR already gives individuals rights over how their personal data is collected, used and applied in automated decision-making. The EU AI Act does not replace those protections. It adds requirements for high-risk AI systems, including representative and accurate training data, auditability, human oversight, technical documentation, conformity assessments, post-market monitoring and registration in the EU database before deployment.
The overlap is especially relevant for AI used in creditworthiness checks, employment screening, biometric categorisation and access to private services. A company screening rental applications, for example, may need to explain its decision-making under GDPR while also proving under the EU AI Act that the system is fit for deployment.
Businesses in Malta face added urgency as member states designate national competent authorities. Firms using third-party AI tools must determine whether they are providers or deployers, map systems against high-risk categories, assess fundamental rights impacts and prepare to cooperate with supervisory authorities.