Skip to content
Compliance reference

EU privacy and AI rules: what applies, and when

GDPR has applied since 2018. The AI Act, NIS2 and the Data Act layer new duties on top of it, phased across 2024 to 2028. This page lists every date that is already in force and every one still ahead, what each rule actually requires, and where an offline tool changes the answer.

Four EU regimes now govern how organisations handle personal data and AI. GDPR applies in full today. NIS2 has applied since 18 October 2024 and the Data Act since 12 September 2025. The AI Act phases in from 2 February 2025 to 2 August 2028, with high risk duties now landing on 2 December 2027.

Verified 23 July 2026. Dates change: this page records when it was last checked so you can judge it.

The calendar

Every date, in force and ahead

EU digital regulation commencement dates, verified 23 July 2026.
DateRegulationWhat appliesStatus
NIS2Cybersecurity risk management and incident reporting duties enter into force for essential and important entities.in force
AI ActProhibited AI practices apply. This is the tier carrying the heaviest penalty.in force
AI ActObligations for general purpose AI models apply, covering transparency, documentation and copyright policy.in force
Data ActAccess and sharing rules for connected product data apply, plus cloud switching provisions.in force
AI ActWatermarking and provenance labelling for AI generated content is expected to apply. A ban on AI nudifier applications takes effect the same day.upcoming
AI ActGeneral purpose AI models placed on the market before 2 August 2025 must reach full compliance.upcoming
AI ActHigh risk obligations for standalone AI systems apply. Moved back from 2 August 2027 by the Digital Omnibus agreement of 7 May 2026.upcoming
AI ActHigh risk obligations for AI embedded in products already regulated under Annex I, such as machinery and medical devices.upcoming
Rule by rule

Who each one binds, and what it asks for

GDPR

Known as DSGVO in Germany and Austria, RGPD in France and Spain, and GDPR in Ireland and the Netherlands.

Who it binds. Any organisation processing personal data of people in the EU, wherever that organisation is based.

What it requires

  • A lawful basis for every processing activity.
  • Data minimisation: collect and retain only what the purpose requires.
  • A Data Protection Impact Assessment where processing is likely to be high risk.
  • Restrictions on transfers outside the EU under Article 44 and the chapter that follows it.
  • Breach notification to the supervisory authority within 72 hours.

Penalty. Up to 20 million euro or 4 percent of global annual turnover, whichever is higher.

Where Omit changes it. Redaction before disclosure is data minimisation applied at the point of sharing. Because Omit runs on the machine that already holds the file, there is no transfer to assess under Article 44, and no processor to contract with.

EU AI Act

Who it binds. Providers and deployers of AI systems placed on the EU market or whose output is used in the EU.

What it requires

  • Prohibited practices ceased from 2 February 2025.
  • Transparency and documentation for general purpose AI models from 2 August 2025.
  • Risk management, data governance, logging, human oversight and accuracy testing for high risk systems.
  • A Fundamental Rights Impact Assessment for high risk deployments, which sits alongside the GDPR assessment rather than replacing it.
  • Provenance labelling for generated content, expected from 2 December 2026.

Penalty. Up to 35 million euro or 7 percent of global annual turnover for prohibited practices.

Where Omit changes it. The Act does not stop teams pasting personal data into general purpose models, and neither does policy. Removing the identifiers before the paste is the control that survives an audit, because it happens on the endpoint and is logged there.

NIS2

Who it binds. Essential and important entities across eighteen sectors, including health, public administration, energy, transport and digital infrastructure.

What it requires

  • Risk management measures proportionate to exposure.
  • Incident reporting, with an early warning inside 24 hours.
  • Supply chain security, covering the tools staff use day to day.
  • Management bodies can be held personally accountable for failures.

Penalty. Up to 10 million euro or 2 percent of global annual turnover for essential entities.

Where Omit changes it. A tool that never opens a network socket removes an entire class of supply chain exposure. There is no vendor endpoint to assess, no data processing agreement to negotiate, and no third party breach that can reach your documents.

Data Act

Who it binds. Manufacturers of connected products, related service providers, and cloud providers serving EU customers.

What it requires

  • Users can access and share the data their connected products generate.
  • Cloud switching provisions, including the removal of egress charges.
  • Safeguards against unlawful third country access to non personal data held in the EU.

Penalty. Set by member states. Enforcement sits with national authorities.

Where Omit changes it. Perpetual local licensing means there is no lock in to unwind. There is no stored corpus to export, because nothing was ever uploaded.

The control that does not depend on a promise

Most compliance controls are contractual. You sign a processing agreement, accept a retention commitment, and trust that the vendor honours both. That is a reasonable way to run a business, and it is also the part that fails during an incident, because the exposure has already happened by the time you read the notification. An offline tool moves the control from a promise to a property of the system. Pull the network cable and Omit works exactly the same. Nothing was sent, so nothing can be retained, subpoenaed, or breached at a third party. That is a claim your auditor can verify in a minute, without reading a contract.

Questions

What teams ask first

Does the AI Act replace GDPR?

No. They apply at the same time. A high risk deployment that processes personal data typically needs both a Data Protection Impact Assessment under GDPR and a Fundamental Rights Impact Assessment under the AI Act. Meeting one does not discharge the other.

Did the high risk deadline actually move?

Yes. Obligations for high risk standalone AI systems were due to apply on 2 August 2027. A provisional political agreement on the Digital Omnibus, reached on 7 May 2026, pushed that to 2 December 2027. Systems embedded in products already regulated under Annex I have until 2 August 2028.

We only use AI internally. Are we in scope?

Probably yes. The AI Act binds deployers, not only providers. If staff put personal data into a general purpose model, GDPR applies to that processing regardless of whether the tool is internal, and the transfer rules apply if the model runs outside the EU.

What counts as high risk?

The Act lists the categories, and employment, education, essential services, law enforcement, migration and the administration of justice are among them. Recruitment screening and staff evaluation are the cases most organisations meet first.

Does redaction remove data from scope entirely?

It depends on whether the result is anonymous or pseudonymous. Irreversible removal can take data outside GDPR. Reversible tokenisation does not, because the mapping still exists and remains personal data. Omit supports both and the distinction is deliberate: choose irreversible when you never need the original back.

How does an offline tool help with Article 44 transfers?

There is no transfer. Article 44 governs sending personal data to a third country or international organisation. Processing that happens entirely on a machine inside your own premises does not engage it, which is why an offline control is structurally simpler to defend than a contractual one.