IAPP published an analysis mapping the specific interplays between the new EU AI Act and existing GDPR regulations.

The Story
The report details how these two frameworks will overlap for European businesses.
Why It Matters
For European SMBs, particularly in pharma or legal, the August 2026 AI Act deadline is fast approaching. This IAPP analysis confirms that AI adoption is not just a tech problem; it is a compliance one. You cannot treat AI projects in isolation from your existing GDPR obligations. This means new requirements for data governance, impact assessments, and vendor due diligence will be mandatory for your high-risk systems.
What To Do About It
First, identify any AI tools your teams are already using, especially those handling client or patient data. Start a basic audit to understand if any of these fall under the AI Act's "high-risk" categories. If you need a structured approach to this initial audit, contact me.


