
Picture a head of sales who, minutes before a meeting, pastes a customer contract into ChatGPT and asks for a summary. It takes two minutes and saves half an hour. In doing so, he sends names, terms and durations to a provider in the United States, through a private account and without a data processing agreement. Under data protection law, that was always delicate. Since 2 August 2026, the AI Act applies on top, with its transparency obligations and fines. This article explains which rules from the GDPR and the AI Act apply side by side, what businesses need to regulate internally, and who supervises compliance in Germany and the Netherlands.
Two sets of rules that apply side by side
The AI Act does not replace the GDPR. Both apply at the same time as soon as an AI tool processes personal data or produces content for the public.
The General Data Protection Regulation does not ask whether software is conventionally programmed or runs on artificial intelligence. It applies as soon as someone processes personal data, which means every customer name, every personnel file and every contracting party that ends up in an AI input field.
The AI Act (Regulation (EU) 2024/1689) has applied alongside it since 2024 and regulates the system rather than the data: it bans certain practices, sets requirements for high-risk systems and obliges providers and deployers to be transparent. A deployer is any business that uses an AI system under its own responsibility. A company running an AI assistant in customer service is therefore a deployer without having written a single line of code.
The timeline that became binding this summer
The AI Act entered into force on 1 August 2024 and takes effect in stages:
- 2 February 2025: bans on certain practices and the duty under Article 4 to equip staff with sufficient AI literacy.
- 2 August 2025: obligations for providers of general-purpose AI models.
- 2 August 2026: transparency obligations under Article 50. From this date, authorities can fine breaches.
The Digital Omnibus on AI (Regulation (EU) 2026/1744), adopted in July 2026, stretched the timeline elsewhere. Stand-alone high-risk systems must meet the requirements only from 2 December 2027; AI components in already regulated products such as machinery or medical devices only from 2 August 2028. Providers of generative systems that were on the market before 2 August 2026 have until 2 December 2026 to machine-label their outputs. The Omnibus did not postpone the transparency obligations for deployers.
What Article 50 requires of deployers
Three obligations hit everyday business directly:
- Disclose chatbots. A business that runs an AI system talking directly to people, on its website or in customer service, must tell users they are interacting with a machine, unless that is obvious from the context.
- Label synthetic images, audio and video. Content that an AI generated or substantially altered, and that could pass for real, needs a notice that it was artificially created.
- Disclose AI-written text. Anyone informing the public on matters of public interest with AI-generated text must make that visible, unless a person has reviewed the text editorially and takes responsibility for it.
An article drafted with AI support and checked by an expert before publication therefore needs no label; a text published unchecked does. Breaches of Article 50 cost up to 15 million euros or 3 per cent of worldwide annual turnover under Article 99(4) of the AI Act, whichever is higher. For small and medium-sized enterprises, the lower amount is the cap.
The GDPR side: contract, plan and data flow
Regardless of the AI Act, one rule stands: if an external service processes personal data on a company’s behalf, Article 28 GDPR requires a data processing agreement. With the major providers, that agreement comes with the business plan. OpenAI states that it offers its Data Processing Addendum for ChatGPT Team, Enterprise and the API, but not for the free version and not for the consumer plan Plus. These two consumer products also use inputs to train the models by default unless the user switches that off in the settings. That rules them out for company data, however carefully the individual works.
On top of this come the duties businesses know from other cloud services: add the AI tool to the record of processing activities, assess the transfer to the United States, and run a data protection impact assessment where the use calls for one. Activating EU data residency in a business plan lowers the transfer risk but does not remove it, because the provider remains a US company.
What needs to be regulated internally
An AI policy for staff is where the GDPR and the AI Act meet in practice. It does not have to be long, but it must answer four questions:
- Which tools may staff use, and through which accounts?
- Which data stays out altogether: customer data, personnel data, contract contents, credentials?
- Who reviews AI-generated content before it leaves the building?
- How does the company document that review?
Article 4 of the AI Act has also required since February 2025 that staff working with AI systems have sufficient AI literacy, matched to their tasks. A documented training session is the simplest way to show it.
Who is in charge in Germany and the Netherlands
In Germany, the AI Market Surveillance and Innovation Promotion Act (KI-MIG) has applied since 29 July 2026. It makes the Bundesnetzagentur the central market surveillance authority, contact point and complaints body for the AI Act; BaFin keeps supervising AI connected with regulated financial activities. The Netherlands relies on ten existing supervisory authorities, coordinated by the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur. The Autoriteit Persoonsgegevens will, among other things, supervise the transparency obligations. The accompanying Uitvoeringswet AI-verordening went through consultation in spring 2026 and is not yet in force. That changes nothing for businesses. The regulation applies directly, whether or not national supervision is fully in place.
Outlook
The rules for everyday work have applied in full since August 2026. What remains open is practice: how strictly the authorities read the labelling duties for images and text, and how Dutch supervision will operate once the Uitvoeringswet is adopted. A business that uses a business plan with a data processing agreement, has a short policy in place and trains its staff already meets the core of both frameworks.
References
European Union (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, Articles 4, 50 and 99. Retrieved from https://eur-lex.europa.eu/eli/reg/2024/1689/oj
European Union (2026). Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Retrieved from https://eur-lex.europa.eu/eli/reg/2026/1744/oj
European Union (2016). Regulation (EU) 2016/679 (General Data Protection Regulation), Article 28. Retrieved from https://eur-lex.europa.eu/eli/reg/2016/679/oj
Bundesnetzagentur (2026). Bundesnetzagentur übernimmt zentrale Rolle bei der Umsetzung der KI-Verordnung, press release of 29 July 2026. Retrieved from https://bundesnetzagentur.de/SharedDocs/Pressemitteilungen/DE/2026/20260729_KI_VO.html
Deutscher Bundestag (2026). Ausschuss nimmt Gesetz zur Durchführung der KI-Verordnung an, hib 469/2026. Retrieved from https://www.bundestag.de/presse/hib/kurzmeldungen-1184102
IHK Nürnberg für Mittelfranken (2026). EU AI-Act: Transparenz- und Kennzeichnungspflichten ab 2. August. Retrieved from https://www.ihk-nuernberg.de/meldungen/details/eu-ai-act-transparenz-und-kennzeichnungspflichten-ab-2-august
Future of Life Institute (2026). The EU AI Act’s transparency rules: a practical guide to Article 50. Retrieved from https://artificialintelligenceact.eu/de/transparency-rules-article-50/
Stibbe (2026). Nederlands voorstel voor AI-toezicht: hybride samenwerking tussen markttoezichtautoriteiten. Retrieved from https://www.stibbe.com/nl/publications-and-insights/nederlands-voorstel-voor-ai-toezicht-hybride-samenwerking-tussen
Security Management (2026). EU AI Act: Nederlandse toezichthouders AP en RDI krijgen sleutelrol. Retrieved from https://www.securitymanagement.nl/eu-ai-act-nederlandse-toezichthouders-ap-en-rdi-krijgen-sleutelrol/
Image: FJ Design Agentur (fjdesign.de).



