Your data stays yours: governance for enterprise AI under GDPR and the EU AI Act
Governance is what lets a company put AI into production without losing control of its data. What the GDPR and the EU AI Act ask of a company that uses AI, with the AI Act timeline as amended in July 2026.
- By
- Andrea Belloni, CEO
- Published
7 min read
In short
- The GDPR applies to AI like to any other processing: lawful basis, minimisation, impact assessment where the risk is high, processor contracts, rules on transfers.
- The AI Act has been in force since 1 August 2024 and applies in general from 2 August 2026.
- The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- Most back-office document automation is not high-risk, but transparency and AI literacy duties can still apply.
- EU data residency, logs, human oversight and documentation are the practical core of governance.
The first question enterprise clients ask about AI is rarely about accuracy. It is: where does our data go? It is the right place to start. An AI system that cannot answer that question clearly should not be in production, whatever else it can do.
This article covers the two European frameworks that shape the answer — the General Data Protection Regulation and the Artificial Intelligence Act — and the practical measures we use to meet them. It reflects the rules as we checked them on 27 September 2026.
The GDPR, applied to AI
The GDPR, Regulation (EU) 2016/679 (external link) has no chapter on AI, and it does not need one. When an AI system processes personal data — names on invoices, contacts in emails, voices on calls — the ordinary rules apply.
- Lawful basis (Article 6). Every processing needs one. For back-office automation it is often the performance of a contract or the company's legitimate interest. The choice must be documented, and legitimate interest requires a balancing test.
- Purpose limitation and minimisation (Article 5). Process only the data the task needs. An agent that extracts invoice totals does not need to keep the whole mailbox.
- Data protection impact assessment (Article 35). Required when processing is likely to result in a high risk to people's rights and freedoms, for example systematic evaluation of individuals or large-scale monitoring. The use of new technologies is one of the factors the article names.
- Processors (Article 28). A cloud platform or model provider that processes personal data on your behalf is a processor, and needs a contract that sets out what it may do with that data.
- International transfers (Chapter V). Sending personal data outside the European Economic Area requires an adequacy decision or other safeguards, such as standard contractual clauses. The simplest governance is not to transfer at all.
- Automated decisions (Article 22). People have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them. Human review is also a legal safeguard.
In Italy the supervisory authority is the Garante per la protezione dei dati personali (external link).
The EU AI Act in brief
The AI Act, Regulation (EU) 2024/1689 (external link), regulates AI systems according to the risk they pose. It distinguishes four levels:
- Unacceptable risk: prohibited practices, such as social scoring or manipulative techniques that cause significant harm.
- High risk: systems used in the sensitive areas listed in Annex III — among them employment and the management of workers, access to essential services such as credit, education and critical infrastructure — and AI that is a safety component of products covered by the EU legislation listed in Annex I.
- Transparency risk: systems that interact with people or generate content must make this clear. A chatbot or a voice agent, for example, must let people know they are dealing with an AI.
- Minimal risk: everything else, for which the Act sets no specific rules.
Obligations also depend on the role. The provider develops an AI system, or has it developed, and places it on the market or puts it into service under its own name. The deployer uses it under its own authority. A company that commissions a bespoke AI system and puts it into service under its own name can therefore be its provider as well as its deployer. Roles are worth settling in writing at the start of a project.
The timeline, as amended in 2026
The AI Act entered into force on 1 August 2024 and applies in stages. The dates below take into account the Digital Omnibus on AI, Regulation (EU) 2026/1744 (external link), published in the Official Journal on 24 July 2026 and in force since 27 July 2026.
- 2 February 2025: the prohibited practices and the AI literacy obligation apply.
- 2 August 2025: the obligations for general-purpose AI models and the governance rules apply.
- 2 August 2026: the Act applies in general, including the transparency obligations of Article 50.
- 2 December 2026: end of the grace period for the machine-readable marking of AI-generated content (Article 50(2)), for generative systems placed on the market before 2 August 2026. From the same date, a new prohibition added by the Omnibus applies to AI systems that generate non-consensual intimate content or child sexual abuse material.
- 2 December 2027: the obligations for high-risk systems in the areas listed in Annex III apply. The original date was 2 August 2026.
- 2 August 2028: the obligations for high-risk AI embedded in products covered by Annex I apply. The original date was 2 August 2027.
The Omnibus also reworded the AI literacy duty of Article 4. Providers and deployers must take measures to support the AI literacy of their staff and of the people who operate AI systems on their behalf, without being required to guarantee a specific level. It remains an obligation.
In Italy, Law no. 132 of 23 September 2025 (external link), in force since 10 October 2025, complements the AI Act and designates the Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN) as the national authorities for artificial intelligence.
Checked on 27 September 2026
We verified these dates on the European Commission's AI Act page (external link) and against the texts published in the Official Journal. The Act may be amended again: check the current text before relying on a date.
What this means for typical enterprise AI
Most of the AI we build for enterprises — reading supplier invoices, turning order emails into transport orders, answering questions from company documents — does not fall into the high-risk categories. That does not mean there is nothing to do.
- The GDPR applies in full whenever personal data is involved, which is almost always.
- Chat and voice agents that talk to customers must tell them they are dealing with an AI.
- AI literacy measures are required for the staff who use or operate the systems.
- A system used to screen candidates, evaluate employees or assess creditworthiness is high-risk, and must be designed for the obligations that apply from 2 December 2027.
Practical governance
Regulation sets the minimum. What gives a company real control is a small number of practices, applied consistently from the first pilot.
EU data residency
Keep processing, storage and backups in the European Union, and choose model deployments that process data in an EU region. List every processor that touches the data, with its location and its contract. If nothing leaves the European Economic Area, the questions of Chapter V do not arise.
Model choice
Choose models by task, data sensitivity and deployment, not by brand. Read the provider's terms on data retention and on the use of data for training. Keep the system model-agnostic, so that a provider can be replaced if its terms, its location or its quality change. Where a client requires it, bring the client's own model and provider.
Logs and audit trail
Record, for each case, the input, the model and version used, the output, the rules applied, the human decisions, and what was written to other systems. Set retention periods consistent with the GDPR: logs contain personal data too.
Human oversight
Design the points where people decide: which cases go to review, what the reviewer sees, how a decision is recorded, who can override the system. Oversight that exists only on paper is worth nothing, to the regulator or to the business.
Documentation
Keep a description of the system — purpose, data flows, models, evaluation results, known limits — and update it with every release. Architecture decision records explain why it is built the way it is. When an auditor, a customer or a regulator asks, the answer already exists.
A short checklist
- A lawful basis identified and documented for each processing.
- The need for an impact assessment evaluated, and the assessment carried out where the risk is high.
- Processor contracts in place for every provider, with locations listed.
- No transfers outside the European Economic Area, or valid safeguards where there are.
- The AI Act role (provider, deployer) and risk level assessed for each system.
- Transparency towards the people who interact with the system.
- AI literacy measures for the staff involved.
- Audit trail, retention periods and human oversight designed and tested.
We apply these practices in every enterprise AI project, and our architecture and operations work keeps them true after go-live. Your data stays yours: documented, governed, compliant.
This article is general information, not legal advice.