The final report of the series analysing different aspects of the new AI rulebook examines the interaction of the AI Act with existing or draft legislation on data protection and cybersecurity.
The report addresses the references in the AI Act to the General Data Protection Regulation (GDPR), the Law Enforcement Directive (LED), the draft Cyber Resilience Act (CRA) and the Digital Services Act (DSA).
The new AI rulebook provides a new legal basis for further processing lawfully collected personal data in the context of regulatory sandboxes. Such processing will nevertheless need to be compatible with the GDPR requirements.
Moreover, providers of high-risk AI (HRAI) systems are allowed to process special categories of personal data as defined under the GDPR only exceptionally. Providers can resort to such processing only to correct biases in the datasets, and subject to safeguards additional to those foreseen in the GDPR.
For HRAI systems which fall within the scope of the draft CRA and fulfil its cybersecurity requirements, a presumption of conformity will apply vis-a-vis the mandatory cybersecurity requirement for HRAI systems under the AI Act (e.g. resilience against unauthorised use by third parties).
Further, if AI systems are embedded into very large online platforms or very large search engines under the DSA, the AI Act clarifies that such systems are subject to the risk assessment obligations in the DSA.
See also:
Part 1: Scope
Part 2: Obligations
Part 3: Enforcement
For more information and to access our AI Act report series, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
12 March 26
National implementation of the EU Gigabit Infrastructure Act
The Gigabit Infrastructure Act (GIA) is a regulation and as such directly applicable in all member states without the need for transposition into national law. Despite being a regulation, the GIA often sets minimum requirements, on top of which member states can adopt additional measures to address country-specific circumstances. Our new benchmark shows the choices made by member states when implementing the GIA.
09 March 26
How are EU member states transposing NIS2?
Our latest benchmark tracks the progress of the Directive on measures for a high common level of cybersecurity across the EU (NIS2) transposition in the 27 EU member states.
05 March 26
CSRD: Austria and Malta finalise national transposition
Cullen International’s latest benchmark tracks the progress made by the 27 EU member states in transposing the Corporate Sustainability Reporting Directive (CSRD) and the related “stop-the-clock” directive.