Two Regulators, One AI Tool: GDPR and the AI Act Now Apply Together
Until recently an organization using AI to handle text had one regulator to think about in Europe: its data protection authority, under GDPR. From 2 August 2026 the AI Act’s enforcement machinery is live as well, with the AI Office covering general-purpose model providers and national authorities covering the rest.
These are not alternatives. They apply at the same time, to the same tool, for different reasons, and the analysis you do for one does not answer the other.
That sounds like a compliance burden and mostly it is a clarity problem. Once you separate what each regime is asking, the practical work gets smaller rather than larger.
They Ask Different Questions
GDPR asks about personal data. Is there personal data in the text, what is your legal basis for processing it, who else processes it, where does it go, how long is it kept, and can the person exercise their rights over it.
The AI Act asks about the system. What kind of AI system is this, what risk category does it fall into, what obligations attach to that category, and are the transparency duties met.
A single AI writing tool can be entirely fine under one and problematic under the other. A tool with no personal data anywhere near it still has AI Act transparency questions in some deployments. A tool with clean AI Act positioning still processes personal data every time a client’s name appears in an email.
The overlap is real. Enforcement actions in 2025 and 2026 have cited both regimes in the same decision, which is a signal that authorities are willing to run the analyses together rather than treating them as separate worlds.
The One Fact That Answers Both
Here is the shortcut, and it is genuinely a shortcut rather than a rhetorical one.
If the text is processed by a model running on the author’s own machine, and no network request is made during processing, then:
Under GDPR, there is no transfer to a processor, no subprocessor to disclose, no international transfer to assess, and no third-party retention period to document. The processing happens on your own equipment, which you already account for.
Under the AI Act, the transparency questions about interacting with an AI system and about synthetic content are unchanged, because those attach to what you do rather than where the compute is, but the whole set of questions about the provider’s obligations and your relationship to them falls away.
Local processing does not make either regime disappear. It removes the hardest category of question from both: the one about a third party you do not control. That is why the split between local and cloud is a compliance decision and not only a technical one, as set out in which tasks should stay local.
Where Cloud Processing Is Fine
Most of the time, for most text, with the right paperwork.
A hosted model with a data processing agreement, EU processing, documented retention, and no training on customer data is a normal, defensible arrangement. Thousands of organizations run on exactly that and always have. The relevant questions are in GDPR checklist for AI writing tools and what zero data retention actually means.
The point is not that cloud is wrong. It is that cloud requires you to obtain, read, and maintain a set of contractual facts, and local does not. For text where the stakes are low, that overhead is worth it for the extra capability. For a client’s confidential paragraph, it usually is not.
The Documentation That Covers Both
One artifact does most of the work under both regimes: a dated record of what you decided and why.
Not a policy document nobody reads. A short record, per category of text, saying where it is processed and on what reasoning.
Before:
We use AI tools in a GDPR compliant manner and have appropriate safeguards in place for all processing activities.
After:
Client correspondence containing personal data: rewritten locally on the author’s machine. No transmission, no processor, no transfer.
Internal drafts with no personal data: hosted model, EU processing, retention 30 days, DPA signed 14 March 2026, no training on our content.
Decision owner: Head of Operations. Last reviewed 5 August 2026. Next review February 2027.
The second version answers a regulator’s question, a client’s questionnaire, and your own internal review, in three lines. The first version answers nothing and asserts a conclusion you would then have to defend.
A Wrivio Context for compliance records could say:
Rewrite this as a precise compliance record. Neutral register, complete sentences, one line per category. Keep every date, vendor name, retention period, and legal term exactly as written. Do not add claims of compliance, do not generalize a specific statement, and do not remove a stated limitation.
Press Ctrl+Shift+Space, paste the draft, and check the diff. The failure mode with compliance text is upgrading: a careful “we do X” becoming “we are compliant with Y”. Models do this because the register invites it, and the diff is where you catch it.
What To Watch Over The Next Year
Two open questions worth tracking rather than acting on.
How the two regimes divide labor in practice. Formally the AI Office covers general-purpose model providers and national authorities cover systems, with data protection authorities retaining their GDPR remit throughout. How that works in a specific case is still being established.
Whether enforcement reaches ordinary deployers. The early focus is on large providers. Whether and when authorities look at how businesses deploy these tools is unknown, and anyone claiming certainty about it in 2026 is guessing.
Neither uncertainty changes the sensible response, which is to know where your text goes and to have written it down.
Common Questions
Do GDPR and the AI Act both apply to the same AI tool?
Yes, simultaneously and for different reasons. GDPR governs personal data in the text; the AI Act governs the system and its transparency obligations.
Does running a model locally make me GDPR compliant?
It removes the third-party processing and transfer questions, which are the hardest part. You still have obligations for the personal data you hold, on the same terms as any other data on your own equipment.
Which regulator would come after a business using an AI writing tool?
Realistically the data protection authority, under GDPR, if personal data were mishandled. AI Act enforcement is currently aimed at model providers.
What is the minimum documentation to have?
One dated page listing categories of text, where each is processed, and who owns the decision. If you produce nothing else, produce that.
Download Wrivio for Windows to process client text locally, which removes the transfer question from both regimes at once.
Read Next
Five Questions To Ask An AI Vendor About Your Data
Vendor privacy pages are written to reassure. Five specific questions that produce answers you can act on, and what an evasive response tells you.
Legal Professionals and AI: Balancing Efficiency with Confidentiality
How attorneys and paralegals are navigating the ethical complexities of AI by adopting secure, local tools for document review and drafting.
Why Your Company NDA Means You Cannot Use ChatGPT
A deep dive into the legal and ethical conflicts between standard Non-Disclosure Agreements and the use of public cloud AI services.
OpenAI Cut GPT-5.6 Prices in August 2026: What Cheap Inference Changes
An 80 percent cut on the cheapest tier and 20 percent on the middle one. What falling token prices actually change for work writing, and what they do not.
This article is filed underPrivacy & Compliance, which has 53 articles.