Artificial Intelligence

Background information on the AI Act
The Artificial Intelligence Act is a European Union (‘EU’) legal instrument which entered into force on 1 August 2024 to regulate the use of Artificial Intelligence (‘AI’) technologies across the EU bloc, to ensure that they are safe, ethical, transparent, non-discriminatory and overseen by people, rather than by automation, to prevent harmful outcomes. The AI Act is considered the first comprehensive regulation on AI establishing a risk-based AI classification system designed to address the varying degrees of risk posed by AI models, whilst adopting a technology-neutral definition for AI which can be applied to future AI iterations.
The AI Act – Key important dates
The infographic above details the AI Act’s key dates of its coming into force in the light of the AI Omnibus.
Interplay between AI Act and the GDPR
The Artificial Intelligence Act (‘AI Act’) marks a significant step in the EU's efforts to regulate innovative technologies, ensuring their development and deployment are aligned with fundamental rights. As AI systems increasingly shape various sectors, and in practice processing personal data to deliver quality output, their potential impact on personal data protection cannot be overlooked. The AI Act, while focusing on the regulation of AI, draws upon essential data protection principles found under the EU General Data Protection Regulation (GDPR), such as fairness, transparency, human oversight - closely linked to fairness - accountability, as well as privacy and data governance itself.
In cases where AI systems process personal data, not only does the AI Act apply, but so will the GDPR, which takes legal precedence, reinforcing the EU's commitment to privacy and data protection as the underlying concern and impetus. The AI Act’s human oversight principle echoes the GDPR’s right not to be subject to automated decision-making. The AI Act’s alignment with GDPR principles highlights the EU's holistic approach to both advancing technological innovation and upholding privacy protections.
The IDPC’s competency and role on AI systems
Drawing from extensive experience in overseeing automated decision-making processes, national data protection supervisory authorities, such as the IDPC, are in a position to contribute valuable input, ensuring that the AI Act addresses key ethical concerns and strengthens safeguards for individuals insofar as data relating to them is concerned. For this reason, the AI Act has prescribed data protection authorities as the market surveillance authority (‘MSA’) for certain high risk AI systems concerned with law enforcement, migration & border control, and justice & democracy.
This supervisory authority is committed to safeguarding individuals' fundamental rights through the protection of personal data, in the face of evolving technological advancements.
As a data protection supervisory authority in terms of the GDPR, this Office has also been designated as a fundamental rights authority ('FRA') under the AI Act, specifically concerning the protection of personal data. For more information on the IDPC's roles under the AI Act, please click here.
To view the Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025, under the Data Protection Act (CAP.586), please click here.
