Skip to content
ComplianceAI Agents

GDPR and the AI Act: What to Check Before Putting an AI Agent in Production

What the GDPR and the AI Act actually require from a company using AI agents, the five points that cover most cases, and the mistake that costs the most.

GDPR and the AI Act: What to Check Before Putting an AI Agent in Production
In this article
  1. The two rules that apply
  2. What this requires in practice
  3. The common mistake
  4. What we do by default

It is the first serious objection in any conversation about AI in the European Union, and rightly so. It is worth separating real obligation from noise.

The two rules that apply

The GDPR applies as soon as the system processes personal data, which in practice is almost always: client names, emails, contact history. None of that changes because AI is involved. What changes is that there is one more place the data passes through, and therefore one more place to document.

The AI Act is the European regulation specific to artificial intelligence, applied in phases. It classifies systems by risk and imposes obligations proportional to that risk. Most enterprise cases (internal assistants, back office automation, customer support) fall under limited or minimal risk, where the main obligations are about transparency.

What this requires in practice

For most enterprise projects, the essentials come down to five points:

  1. Say that it is AI. When a customer talks to an automated assistant, it must be clear it is not a person. No heavy legal notice is needed; it just has to be obvious.
  2. Know where the data lives. Hosting in the European Union answers most of the hard questions about international transfers.
  3. Do not let the data train public models. This must be written into the contract with the model provider, not merely assumed.
  4. Log what the system does. Who consulted what, which decisions were automatic and which had human approval.
  5. Keep a person in the loop for decisions with significant impact on people, such as candidate screening or credit decisions. In those cases the risk classification rises and so do the obligations.

The common mistake

The most frequent mistake is not regulatory, it is procedural: getting the system working first and dealing with compliance afterwards. It always costs more, because it means redoing architectural decisions that are already in production.

The reverse costs little. Defining at design time what information each agent may read, what it may execute alone and where the log lives is two or three sessions of work, not a separate project.

What we do by default

In the systems we build, infrastructure stays in the European Union, in accounts the client company controls, data does not feed public models, permissions are defined by profile and every answer cites its source. Actions with real impact only run unsupervised if the client explicitly allows it.

We are not legal advisers and we do not give legal opinions. What we do ensure is that the technical decisions that depend on us do not create compliance problems for the people who have to answer for them.

Neumotik

Ready to implement in your company?

We develop custom software that solves exactly the problems described in this article. Free diagnosis, no commitment.