AI agents · OpenClaw · self-hosting · automation

Quick Answer

EU AI Act vs DSA vs GDPR: Which Applies to Your AI?

Published:

The Short Answer

Three separate EU instruments now apply to AI products, with different regulators, different triggers, different deadlines and separate penalties:

  • GDPR — applies if you touch personal data. Any size. Enforced by national data protection authorities.
  • EU AI Act — applies based on the risk category of your AI system. Any size.
  • DSA — applies based on distribution scale. The strict tier starts at 45 million monthly EU users.

Coverage that treats “EU AI regulation” as one thing is describing at least three. They stack.

Last verified: September 2, 2026.

Side by Side

EU AI ActDSAGDPR
RegulatesAI systems by riskIntermediaries by distributionPersonal data
TriggerRisk category of use45M+ monthly EU users (very large tier)Any personal data processing
Applies to startups?Yes, by use caseRarelyYes, always
Primary regulatorNational authorities + AI OfficeEuropean Commission (very large tier)National DPAs
Max penaltyUp to 7% turnoverUp to 6% turnoverUp to 4% turnover
Core dutyRisk management, documentation, transparencySystemic risk assessment, audits, ad repositoryLawful basis, minimisation, subject rights
Enforcement maturityBuilding — first RFIs issued Aug 2026Active for designated servicesMature

The Case That Shows How They Stack

ChatGPT is now subject to all three at once.

On August 31, 2026, the European Commission designated ChatGPT a Very Large Online Search Engine under the DSA — the first generative AI chatbot in the category — giving OpenAI until the end of December 2026 to comply with systemic risk assessments, independent audits, algorithmic transparency, an advertising repository and researcher data access.

That designation says nothing about the AI Act, which continues to apply on its own timeline through its own risk framework, with the first enforcement requests for information issued in August 2026. And GDPR applies underneath both, as it has since 2018.

One product, three regulators, three deadlines, three penalty regimes. That is the structural fact most compliance planning gets wrong.

Which One Actually Applies to You

GDPR — assume yes.

If EU users send you prompts, you process personal data. Prompts contain names, employment details, health information and client data as a matter of routine, regardless of what your product is nominally for.

The AI-specific pressure points are: what lawful basis covers your processing; whether prompts and outputs go to training; how long logs are retained; whether users can exercise access and deletion rights over data embedded in a system that cannot easily forget; and where processing physically happens.

The practical risk: GDPR is the instrument with a mature enforcement machine and a decade of case law. For a company below DSA scale, this is where enforcement realistically arrives.

EU AI Act — depends entirely on what your AI does.

Not on your size. The Act sorts by risk:

  • Prohibited — social scoring, certain biometric categorisation, manipulative techniques. Not a compliance project; a design constraint.
  • High risk — employment and recruitment, education, credit and essential services, critical infrastructure, law enforcement, migration. Substantial obligations: risk management, data governance, technical documentation, human oversight, accuracy and robustness.
  • Limited risk — transparency duties. Users must know they are interacting with AI; synthetic content must be marked.
  • Minimal risk — most productivity and coding tools. Little beyond good practice.

The question to ask: not “am I an AI company?” but “does my system make or materially inform a decision about a person’s job, education, credit, health or liberty?” That single question separates the light regime from the heavy one.

DSA — probably not, unless you are very large.

The very large tier requires 45 million average monthly EU users. Almost nothing does. Smaller platforms carry lighter baseline DSA duties around notice-and-action and terms transparency, but the audit-and-risk-assessment machinery is reserved for designated services.

The signal worth taking from ChatGPT’s designation: the Commission classified it by function — retrieving, ranking and summarising web content — not by branding. Any assistant doing web retrieval at that scale should assume the same category is available to regulators.

What to Do About It

If you are pre-scale and building on an AI API:

  1. Get GDPR right first. Lawful basis, retention policy, subprocessor list, a real answer on whether prompts train anything.
  2. Classify your AI Act risk category honestly and write it down with reasoning.
  3. Ship the transparency basics regardless — disclose AI interaction, mark synthetic content. Cheap now, expensive to retrofit.
  4. Ignore the DSA very large tier.

If you are approaching scale:

Design for the DSA obligations before designation. Retrofitting an advertising repository, a researcher data-access pipeline and an audit trail into a live product under a four-month deadline is exactly the position OpenAI is in as of September 2026, and it is not a position you choose voluntarily.

For everyone: track the three deadlines separately in whatever system holds your compliance work. They do not converge, they are not enforced by the same body, and satisfying one provides no defence under another.

Sources