GDPR and AI Act: checks before using generative AI at work

A recruiter pastes a CV into an online assistant to get a summary: within seconds, her company has passed personal data to a third party, possibly outside the Union, and used an AI system in an area that European law watches closely. Here is, text by text, what to check before getting to that point, in the state of the law on 1 October 2026.

Two texts, two logics

Two European regulations apply at the same time to the use of generative AI in business. The General Data Protection Regulation, or GDPR, governs any processing of personal data, that is, any information relating to an identifiable person. It applies as soon as a name, an email address or a customer file enters a request. The regulation on artificial intelligence, called the AI Act, governs AI systems themselves according to the level of risk of their use, whether or not they process personal data.

The AI Act distinguishes the provider, who develops the system or places it on the market, and the deployer, who uses it under its own authority in a professional setting. A company whose employees use a chat assistant for their work is a deployer, whatever its size. It does not have the obligations of a model publisher, but it does have obligations.

The GDPR reasons in terms of processing operations and purposes. The AI Act reasons in terms of systems and uses. The same action, summarising a CV, falls under both: under the GDPR because the CV contains personal data, under the AI Act because recruitment is among the high-risk areas listed in Annex III of the regulation.

The AI Act timeline, amended in July 2026

Regulation (EU) 2024/1689 entered into force on 1 August 2024, with staggered application. The prohibited practices, such as social scoring or certain forms of manipulation, and the AI literacy obligation, have applied since 2 February 2025. The rules on general-purpose AI models and the organisation of governance have applied since 2 August 2025. The European Commission states that the regulation became applicable on 2 August 2026, with a few exceptions, and that the transparency rules take effect on that date.

These exceptions come from the digital omnibus on AI, a simplification text proposed by the Commission on 19 November 2025. After a political agreement on 7 May 2026, the European Parliament adopted it on 16 June 2026 and the Council on 29 June. Published as Regulation (EU) 2026/1744, it entered into force on 27 July 2026. It postpones the obligations of the Annex III high-risk systems, including those used for recruitment, education or access to certain services, to 2 December 2027. High-risk systems built into products already subject to sectoral legislation, such as machinery or medical devices, have until 2 August 2028.

The omnibus adds a prohibition, applicable from 2 December 2026: that of systems which generate non-consensual intimate images or child sexual abuse material. It also gives providers of systems already on the market until 2 December 2026 to mark the synthetic content they produce in a detectable way.

Finally, it rewrites Article 4 on AI literacy. The former wording asked providers and deployers to ensure a sufficient level of literacy among their staff. The new one asks them to take measures to promote this literacy, taking into account people's knowledge and the context of use, without requiring a set level. The obligation has not been postponed: it applies to any company that uses an AI system in its activity.

The penalties remain those of Article 99: up to €35 million or 7% of worldwide turnover for prohibited practices, up to €15 million or 3% for most other obligations, including those of deployers and on transparency. For SMEs, the lower of the two amounts serves as the ceiling.

What the AI Act asks of a user company

Most office uses, writing an email, summarising a meeting, translating a manual, are not high-risk. For them, the deployer's obligations come down to two points: training and informing staff under Article 4, and complying with the transparency rules of Article 50.

Article 50 mainly concerns published content. A deployer that publishes a realistically faked image, sound or video must indicate that it has been generated or manipulated. A text produced by AI and published to inform the public on matters of public interest must be labelled too, unless it has undergone human review under the editorial responsibility of an identified person. The information must be given clearly, at the latest at the first contact with the content.

The obligations become heavier if the use falls under Annex III, for example screening applications or evaluating employees. Article 26 then requires the deployer to assign oversight of the system to competent people with the necessary authority, to keep the automatically generated logs for at least six months, to inform staff representatives and the employees concerned before the system is put into service in the workplace, and to use the provider's documentation to carry out the impact assessment provided for by the GDPR. These obligations will apply from 2 December 2027, but a project launched today will be in service by that date.

In France, the government presented on 9 September 2025 a supervision scheme that entrusts coordination to the DGCCRF and distributes oversight among several authorities, including the CNIL for high-risk systems linked to employment and education and Arcom for synthetic content. This scheme was to be validated by a law; its progress should be checked when launching a project.

GDPR: the questions to ask before the first request

The GDPR does not prohibit the use of generative AI. It requires answering, for each use that touches personal data, the usual questions: what purpose, on what legal basis among those in Article 6, with what strictly necessary data, for how long, with what information given to individuals and how they exercise their rights. The processing must appear in the record of processing activities.

Generative AI adds a difficulty: what goes into a request may come out elsewhere. The European Data Protection Board, which brings together the national authorities, issued on 17 December 2024 an opinion on AI models. It considers that a model trained on personal data cannot be regarded as anonymous in every case: it must be verified case by case that the likelihood of extracting data about individuals from it is negligible. It accepts that legitimate interest may be the basis for certain processing, provided it passes a three-step test: an identified interest, necessity of the processing, and a balancing against the rights of individuals.

For a user company, the practical consequence is simple. It needs to know whether the provider reuses requests to train its models, and be able to refuse this contractually. The CNIL reminds us, in its July 2024 questions and answers on generative AI, that the fact that data is accessible is not enough to authorise its reuse by the provider.

The GDPR itself could change. The Commission proposed on 19 November 2025 a second part of the digital omnibus which touches in particular on the definition of personal data. At the end of September 2026, this part remained at first reading, without a negotiating mandate from the Council. The current rules therefore apply unchanged.

The provider: processor, and under what contract

When a service provider processes personal data on behalf of a company, it is its processor within the meaning of Article 28 of the GDPR. A contract must then set the subject matter, duration, nature and purpose of the processing, the categories of data, and commit the provider to act only on instructions, to ensure security, to use other processors only with authorisation and to delete or return the data at the end of the contract.

The consumer versions of online assistants are generally not designed for this framework. Business offerings more often are, but the terms vary. The CNIL distinguishes three deployment modes. On site, the organisation keeps control of the infrastructure. In the cloud, a processing contract is needed that delimits responsibilities and the authorised access to data. By API, the CNIL considers the risk to be the highest and recommends avoiding transmitting personal data through it, watching the clauses on transfers outside the Union.

One point deserves careful reading: if the provider reuses the data received for its own purposes, for example to improve its models, it no longer acts solely on behalf of its customer. The characterisation of each party then changes, with its consequences for liability. The contract must settle this question in black and white.

Sensitive data and trade secrets

Article 9 of the GDPR prohibits in principle the processing of certain categories of data: ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health, sex life and sexual orientation. The exceptions are limited and must be identified before any processing. A sick note, a mention of disability in an HR file or a medical report pasted into an online assistant are examples.

The CNIL recommends defining, according to the deployment mode, the authorised and prohibited uses, and prohibiting the entry of certain confidential information, such as that covered by trade secrecy, when the tool is hosted externally. It also recommends training users in the operation and limits of the system, and asking them to check the results before reusing them.

Transfers outside the Union and the Cloud Act

Chapter V of the GDPR governs transfers of personal data outside the Union. To the United States, most now rest on the EU-US Data Privacy Framework, adopted by the Commission in July 2023. On 3 September 2025, the General Court of the European Union dismissed the action brought by French member of parliament Philippe Latombe against this framework, in case T-553/23. The applicant lodged an appeal before the Court of Justice on 31 October 2025, registered under number C-703/25 P. Until the Court has ruled, the legal basis for these transfers remains contested, and its status must be checked when choosing a tool.

The Cloud Act, a US law of 2018, adds another exposure. It inserted into the US federal code a provision, section 2713 of title 18, which obliges communication and storage service providers subject to US law to disclose, on demand, the data in their possession, custody or control, whether this data is stored in the United States or elsewhere. Hosting in a European data centre therefore does not remove this exposure when the provider falls under US law.

For the company, these two elements are a matter of risk analysis. For each tool, it must identify the country of the provider and of its own subprocessors, the legal instrument that frames the transfer, and what would happen if this framework fell.

Logging without surveilling

Logging consists of recording who did what, and when, in a system. It serves to detect abuse, to investigate after an incident and to demonstrate compliance. The CNIL published a recommendation on the subject on 18 November 2021. It advises keeping the traces of authorised users' accesses and actions for six months to one year, a longer period having to be justified and documented, and in most cases not exceeding three years.

With generative AI, the question is doubled. An assistant's logs often contain the text of requests and answers, and therefore personal data and sometimes trade secrets. They are themselves a processing operation to be secured, limited in time and protected against excessive monitoring of employees. For high-risk systems, the AI Act sets a floor of six months' retention of logs for the deployer. One must know where these logs are stored, who can read them and whether they are accessible to the provider.

The impact assessment, a decision tool

The data protection impact assessment, or DPIA, is mandatory under Article 35 of the GDPR when a processing operation is likely to result in a high risk to the rights and freedoms of individuals. The European authorities have set nine criteria, including sensitive data, large-scale processing, vulnerable individuals, the matching of datasets and the innovative use of a technology. A processing operation that meets at least two criteria is presumed to require an assessment.

The CNIL specifies that recent techniques, including generative AI, fall under the innovative-use criterion, unlike proven statistical methods. It also lists risks specific to AI to be included in the analysis: production of false content, discriminatory bias, attacks aimed at extracting data from the model. An assistant used by human resources on employee files thus quickly meets two criteria.

The DPIA is not one more form. Properly carried out, it forces you to describe the real data flow, to compare deployment options and to document the choice made. It is often at this stage that a company discovers that part of its uses should not go through an external service.

What on-site processing changes

Running the model on a machine installed on the company's premises changes several answers. The CNIL recommends this deployment mode for personal or confidential data, because it limits the risks of extraction by a third party. If no provider accesses the requests, there is no transfer outside the Union, no Cloud Act exposure through this channel, and no reuse of the data to train a third-party model. The subcontracting chain gets shorter, and the logs remain under the company's control.

It does not remove the rest. The legal basis, minimisation, information of individuals, security, retention periods and the impact assessment remain due. The AI Act obligations do not depend on where the model runs: screening applications remains a high-risk use, whether it is run in an American data centre or in a server cupboard. And if a provider carries out remote maintenance with access to the data, it becomes a processor again.

On-site processing also shifts part of the technical responsibility to the company: security updates, access control, backups. The legal gain presupposes a properly administered machine.

Before signing

The check comes down to a short series of points. A written policy distinguishes authorised and prohibited uses. Each use is classified according to whether or not it touches personal data, and among it sensitive data. For each tool, the company knows where requests are processed, the provider, the law it is subject to and the legal instrument that frames any transfer. The contract prohibits the reuse of data for training, or frames it. The logs have a defined location, access rights and retention period. The uses that fall under Annex III of the AI Act are identified, the impact assessment is carried out when required, and staff have received suitable training.

This article describes the state of the texts on 1 October 2026. It does not constitute legal advice: each particular case, in particular those touching on human resources, health or international transfers, requires the opinion of a lawyer or the data protection officer. It is to answer the question of where data is located that HOMN designs machines that process requests on site; the other questions on this list remain the responsibility of each company.

Is a company that uses ChatGPT or Copilot covered by the AI Act?

Yes. It is a deployer within the meaning of the regulation. At a minimum, it must take AI literacy measures for its staff (Article 4) and comply with the transparency rules of Article 50. Heavier obligations are added if the use is high-risk, such as recruitment.

Have the AI Act's high-risk obligations applied since August 2026?

No. Regulation (EU) 2026/1744, which entered into force on 27 July 2026, postponed them to 2 December 2027 for Annex III systems and to 2 August 2028 for those built into regulated products.

Is an impact assessment needed to use generative AI?

Not systematically. It is mandatory if the processing presents a high risk, presumed as soon as two of the nine European criteria are met. The CNIL ranks generative AI among innovative uses, which already counts as one criterion. It recommends carrying one out.

Is hosting AI in Europe enough to rule out the Cloud Act?

No. The Cloud Act targets providers subject to US law, whatever the location where the data is stored. Only processing by a provider not subject to this law, or on a company machine with no external access, rules out this exposure.