
The EU AI Act is now the world's most consequential piece of AI legislation. With high-risk obligations due to apply from 2 December 2027, enterprises that deploy AI in Europe — or that use AI systems supplied by European vendors — face a new compliance reality that sits alongside, and in places overlaps with, the General Data Protection Regulation (GDPR). Getting ahead of these obligations is no longer optional: non-compliance carries fines of up to €35M or 7% of global annual turnover for prohibited practices and €15M or 3% for high-risk obligation breaches — and the reputational cost of a high-profile AI incident in a regulated context is higher still.
What the EU AI Act Actually Requires
The Act uses a risk-tiered approach. Unacceptable-risk systems — such as social scoring or, with narrow exceptions, real-time remote biometric identification in public spaces for law enforcement — are prohibited outright. General-purpose AI models above certain capability thresholds face transparency and systemic-risk obligations. But the category that affects most enterprise AI programmes is high-risk AI, which includes systems used in:
- Employment decisions — recruitment screening, performance management, task allocation
- Credit and insurance assessments that influence access to essential services
- Educational evaluation and student assessment
- Safety-critical infrastructure management
- Law enforcement, border control, and administration of justice
- Healthcare — AI-assisted diagnostics, treatment recommendations, and medical device software
Operators of high-risk systems must establish conformity assessments, maintain technical documentation, implement human oversight mechanisms, conduct post-market monitoring, and register systems in the EU AI Act database. The obligations apply not just to AI developers but to any enterprise deploying a third-party AI system in a high-risk context.
The GDPR Intersection: Where the Two Regimes Overlap
GDPR and the EU AI Act are not parallel tracks — they intersect significantly. Any high-risk AI system that processes personal data triggers both regimes simultaneously. Under GDPR, you need a lawful basis for processing, must honour data subject rights (including the right not to be subject to solely automated decisions with significant effects), and must conduct Data Protection Impact Assessments (DPIAs) for high-risk processing. Under the AI Act, you need conformity assessments, risk management documentation, and transparency disclosures about AI involvement.
In practice, this means your AI governance programme needs to be designed to cover both regimes together. A DPIA that ignores the AI Act's technical documentation requirements — and vice versa — will leave compliance gaps that regulators increasingly have the appetite and tooling to find.
India's DPDP Act: A Parallel Obligation for Global AI Programmes
Enterprises with operations or customers in India must also account for the Digital Personal Data Protection (DPDP) Act, whose Rules are being phased in, with most obligations applying from 13 May 2027. Like GDPR, the DPDP Act establishes consent and legitimate use requirements for personal data processing, government power to restrict cross-border transfers to notified countries, and mechanisms for data principals to withdraw consent and seek grievance redress.
For AI systems that train on or process Indian citizens' personal data — including AI agents that interact with customers or employees in India — the DPDP Act creates obligations that must be designed into your data pipelines and model training protocols, not bolted on after deployment. Enterprises running multi-geography AI programmes need a unified data governance framework that is parameterisable by jurisdiction, rather than separate compliance silos that inevitably diverge.
How humaineeti's Responsible AI Approach Addresses Compliance
At humaineeti, responsible AI is not a post-deployment checklist — it is a design principle embedded from the first line of agent specification. Our approach centres on three interlocking practices:
Zero Trust as an AI Architecture Principle
We apply Zero Trust principles to every AI system we build: no agent, model, or data pipeline is implicitly trusted by any other component. Every interaction is authenticated, authorised, and logged. This architecture directly supports the EU AI Act's requirements for human oversight and post-market monitoring, because the observability infrastructure needed for Zero Trust compliance is the same infrastructure needed to produce the audit trails regulators require.
Observe · Evaluate · Report
Our operational framework for AI systems running in production is built around a continuous observe-evaluate-report cycle. Agents are monitored in real time; their outputs are evaluated against quality and policy thresholds; and anomalies, policy violations, or confidence degradations trigger automated reports and escalations. This cycle maps directly to the EU AI Act's post-market monitoring obligations and supports the GDPR requirement to detect and report data breaches involving AI-processed personal data within 72 hours.
PII Detection, SIEM Integration, and Explainability
Every agent we deploy includes automated PII detection at the data ingestion and output stages, ensuring that personally identifiable information is identified, handled according to the relevant jurisdiction's rules, and never inadvertently surfaced in model outputs or logs. We integrate with enterprise SIEM and SOC tooling so that AI-related security events flow into existing incident response workflows rather than creating a separate monitoring silo. And we build explainability into our agent architectures — not as a theoretical commitment but as observable traces that show regulators, auditors, and affected individuals why an AI system reached a particular conclusion or took a particular action.
Practical Steps to Start Building Compliance Now
Waiting for full regulatory clarity before acting is itself a compliance risk — the Act is in force and enforcement is active. Enterprises should begin with three immediate steps: first, catalogue every AI system in use or under development and classify it against the Act's risk tiers; second, map each high-risk system's data flows against both GDPR and, where applicable, DPDP Act obligations; third, implement the observability and human oversight mechanisms that are non-negotiable for high-risk deployment. The enterprises that do this now will be positioned to scale their AI programmes confidently. Those that defer will find compliance retrofitting far more expensive than building it in from the start.
Explore humaineeti's Responsible AI PracticeFrequently Asked Questions
Does the EU AI Act apply to Indian companies?
Yes. The EU AI Act applies extraterritorially: any provider, deployer, importer, or distributor that places an AI system on the EU market or whose system's output is used in the EU is in scope. Indian IT services firms, SaaS vendors, and BPO operators serving EU clients must comply for the systems they ship into the EU.
When does the EU AI Act take full effect?
The Act entered into force on 1 August 2024. Prohibitions on unacceptable-risk AI took effect 2 February 2025. GPAI obligations took effect 2 August 2025. Following the AI Omnibus amendment (in force since 27 July 2026), high-risk obligations for stand-alone Annex III systems apply from 2 December 2027, and for AI embedded in products covered by Annex I from 2 August 2028.
What is a high-risk AI system under Annex III?
Annex III lists eight categories: biometrics, critical infrastructure, education and vocational training, employment and worker management, essential public and private services (including credit scoring), law enforcement, migration and border control, and administration of justice. Systems used in these contexts are high-risk unless they fall within the limited Article 6(3) exemptions.
What are the penalties for EU AI Act non-compliance?
Fines scale with severity. Use of prohibited AI: up to €35M or 7% of global annual turnover. High-risk obligation breaches: up to €15M or 3%. Supplying incorrect information to authorities: up to €7.5M or 1%. SMEs face proportionate caps.
How do GDPR and the EU AI Act interact?
GDPR governs personal-data processing; the AI Act governs the AI system itself. Both apply in parallel for AI that processes personal data. AI Act obligations sit on top of GDPR — DPIA requirements, lawful basis, and data subject rights all remain. The Act imports GDPR's risk-based logic and defers to GDPR for personal-data specifics.
Can DPDP Act compliance count toward EU AI Act readiness?
DPDP Act 2023 covers personal data, not AI systems specifically, so it does not substitute for AI Act obligations. But DPDP-driven controls — consent capture, purpose limitation, breach notification, automated-decision review — overlap meaningfully with the human-oversight, transparency, and data-governance pillars of the AI Act. A unified India-EU compliance posture is more efficient than two separate programmes.
What documentation does a high-risk AI system need?
Annex IV requires technical documentation including: a general description of the system, design specifications, training methodology and datasets, risk-management process, performance metrics, monitoring plan, and a record of conformity assessments. Documentation must be kept for ten years and provided to authorities on request.


