Guide

The EU AI Act and GDPR in 2026: what's required of a company that uses AI

What already applies, what's been pushed back to December 2027 under Regulation (EU) 2026/1744, what the GDPR adds when staff use AI with customer data, and a minimum checklist before rolling out.

September 28, 20267 min readAzimut

A Spanish company giving AI to its workforce has concrete, few and clear obligations today, and others that have been pushed back to late 2027. The confusion comes from mixing the two up. This page summarizes what the EU AI Act requires in 2026 of a company that uses AI —not one that builds it— what the GDPR adds, and what's worth having in writing before rolling it out. It isn't legal advice; it's the map for talking to whoever gives that.

What changed in July 2026

Regulation (EU) 2026/1744, published July 24, 2026 and in force since July 27, changed the AI Act's timeline. The essentials: the high-risk obligations under Annex III, due to apply from August 2, 2026, are pushed back to December 2, 2027; those for the regulated products under Annex I, to August 2, 2028. What wasn't pushed back is what affects almost every company that uses AI: prohibited practices, AI literacy and transparency obligations.

What already applies to your company

Prohibited practices (since February 2, 2025)

Some uses can't be done with any tool, whether built in-house or bought. The one that touches an ordinary company most is emotion recognition in the workplace. If a provider offers to measure employees' or customers' mood on a call, the answer is no.

AI literacy (since February 2, 2025)

A company using AI systems has to make sure its staff has a sufficient level of understanding of them, proportionate to their role. It doesn't require an accredited course; it requires that whoever uses the tool knows what it does, what it doesn't do, and what shouldn't go into it. In practice, written usage rules and a short training session by role satisfy this — and are also what makes the rollout actually work.

Transparency (since August 2, 2026)

When an AI system interacts with people, they have to know it's AI, unless it's obvious. And content generated or manipulated by AI has to be identifiable as such. For a company using customer-facing agents —a support assistant, say— that means saying so. Systems put on the market before August 2, 2026 have until December 2, 2026 for the technical labeling.

What's been postponed, and why it shouldn't be ignored

Annex III covers high-risk uses: screening and evaluating people for employment, access to education, credit, insurance and others. Its obligations (risk management, documentation, human oversight, EU registration) apply from December 2, 2027. That's fifteen months of margin, not an exemption. A company using AI today to screen candidates or decide about employees is building something that will be high-risk in 2027, with everything that entails for it and its provider.

Azimut's position. We exclude Annex III use cases in our terms of use. The canonical case is candidate screening: we don't offer or promote it, which is why our use-case pages have no Human Resources section. Employee support is viable —handbook queries, onboarding paperwork— since that isn't evaluating people.

General recommendation, whether or not you use our platform: decide in writing which uses stay off-limits for AI at your company before someone launches them on their own.

What the GDPR adds

The AI Act doesn't replace data protection; it adds to it. When your staff uses an AI platform with customer or employee data, the provider is a data processor and the usual pieces are needed, now with AI-specific nuances.

  • Data processing agreement with the platform provider, covering what it does with the data, where it's hosted and which subprocessors it uses, with the list published and advance notice of changes. Model providers are subprocessors and need to be listed.
  • Training. That the provider and its model providers don't use your data for training has to be in the contract, not on a web page.
  • Residency and transfers. Where the data is hosted and which region requests to the models pass through. If there's a transfer outside the EU, under what safeguards.
  • Record of processing activities. Using AI with personal data is one more activity that needs to be recorded, with its purpose and legal basis.
  • Permissions. That each person only accesses through AI what they could already see. A platform that ignores source permissions turns a search tool into a data leak.
  • Agents that act. The Spanish Data Protection Agency (AEPD) published guidance on agentic AI on February 18, 2026: agents that don't just answer but carry out actions in systems. It requires defining what each agent can do, with what data, under what oversight and with what logging. It's worth treating this as a spec when configuring agents, not as paperwork afterward.

Penalties

The AI Act provides for fines of up to €35 million or 7% of global turnover for prohibited practices, and up to €15 million or 3% for other breaches, including transparency. In Spain, the specific penalty regime depends on national legislation still being drafted. GDPR penalties remain in force independently of the above.

Minimum checklist before rolling out

  • AI usage rules for staff, on one page, with what shouldn't be entered and which uses are excluded.
  • Short, recorded training by role, covering AI literacy.
  • A data processing agreement with the provider, with a list of subprocessors and a no-training clause.
  • Hosting and processing region in writing.
  • Permissions inherited from source systems, verified with a real user.
  • AI notice on any agent that talks to customers.
  • Written decision on Annex III uses: off-limits until there's a specific project with its assessment.
  • Processing activity recorded.

How Azimut handles it

Hosted on Google Cloud, Madrid region. Our own data processing agreement with a published list of subprocessors and advance notice. Enterprise contracts with OpenAI, Anthropic, Google and Mistral that prohibit training on your data. Permissions inherited from source systems and a connection catalog closed by default, so a user can't connect an external service without administrator permission. Usage audit log. And exclusion of Annex III use cases in the terms of use. We treat this as hygiene, not as a sales pitch: it's the minimum you should demand from any provider.

Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 (EU Official Journal, July 24, 2026); summaries from Iberley, Finreg360 and Expeforma checked on September 28, 2026; AEPD guidance on agentic AI (February 18, 2026). This page is general information and doesn't constitute legal advice.

Frequently asked questions

Is my company a "provider" or a "deployer"?

If you buy a platform and use it, you're a deployer, with usage, literacy and transparency obligations. You'd be a provider if you developed or marketed your own AI system, with much greater obligations.

Do I have to do an impact assessment?

For Annex III high-risk uses, from December 2027, yes. For general use of an AI platform with personal data, the GDPR may require an impact assessment depending on the processing; check with your data protection officer.

Is it enough that the provider is in the EU?

It helps, but it isn't enough. What matters is where the data is hosted, which region requests to the models pass through, which subprocessors are involved, and what the contract says about training. Ask for it in writing.

Want the answers in writing?

Request a demo and we'll hand you the data processing agreement, the subprocessor list and the hosting region before you even ask.

Request a demo