Group Purchasing
Group Purchasing

The EU AI Act: Is It GDPR for the 2020s, or the Limits of the Brussels Effect?

A discussion paper on what the Act means for your organization, paired with a benchmarking survey on how companies are preparing organisationally and strategically.

EU Stylized Map

One Regulation, Two Very Different Compliance Jobs

GDPR taught a generation of compliance teams what a single-market regulation with global reach costs to implement, and what it doesn't. The EU AI Act runs on a different model. Instead of one compliance build that applies broadly, it sorts AI systems into four risk tiers, from prohibited to minimal, and phases obligations in on a timetable that stretches to August 2028. Most of an organisation's AI use may end up unregulated. Some of it may carry heavy, ongoing duties. Which side of that line you're on can also change without warning, since fine-tuning or rebranding a third-party system can reclassify a deployer as its provider overnight.

Two Ways to Engage

Read the paper, then tell us where your organization stands today.

Key Findings:

  • GDPR preparation cost the world's 500 largest companies an estimated $7.8 billion combined, or roughly $15.8 million on average per company, according to a 2018 IAPP/EY survey.
  • GDPR enforcement has produced approximately €7 billion in fines, but that total is heavily concentrated in a small number of large penalties against major technology platforms, several of which are under appeal.
  • The EU AI Act's high-risk obligations were postponed once, after regulators determined the enforcement architecture, including national authorities and technical standards, wasn't ready in time. They now apply from 2 December 2027 for standalone AI systems and 2 August 2028 for AI embedded in regulated products.
  • Unlike GDPR's controller-processor model, a deployer that fine-tunes, rebrands, or repurposes a third-party AI system can be reclassified as its provider, inheriting a far heavier set of compliance obligations.
  • Penalties under the Act can reach €35 million or 7% of global annual turnover for prohibited practices, and €15 million or 3% of global annual turnover for most other infringements.

Frequently Asked Questions

The paper argues the comparison holds in part: both are extraterritorial, horizontal laws enforced through national competent authorities, but the AI Act requires triaging which systems and activities are covered, rather than the near-universal obligations GDPR imposed.

Yes. A deployer that fine-tunes, rebrands, or repurposes a third-party AI system can be reclassified as its provider, taking on a far heavier set of obligations than it had as a deployer.

High-risk obligations for standalone AI systems apply from 2 December 2027. Obligations for high-risk AI embedded in regulated products apply from 2 August 2028.

No. Total GDPR fines reach approximately €7 billion, but that figure is concentrated in a handful of large penalties against major platforms, and the paper argues the real, lasting impact of GDPR was organisational change, not fines.

It covers AI system inventories, risk classification, governance responsibility, and expected strategic impact, plus whether prior GDPR experience helped organisations prepare this time.

About 10 to 15 minutes.

Yes. Individual responses are confidential and reported only in aggregate.

Keep Exploring

This paper covers one regulation. SANS is tracking AI's impact across cybersecurity practice more broadly, through ongoing research, webcasts, and practitioner tools.