AI Act and personal data in LLMs: a compliance guide for companies
European companies are connecting ChatGPT, Claude, Gemini or in-house models to emails, contracts, tickets and customer databases. Every prompt may contain names, ID numbers, IBANs or health data, and once sent to an external provider, control over them drops sharply.
Two frameworks apply at once: the AI Regulation (Regulation (EU) 2024/1689, the AI Act), which regulates AI systems by risk, and the GDPR, which still governs any processing of personal data, including inside a prompt.
The AI Act timeline after the Digital Omnibus
The Digital Omnibus on AI, in force since late July 2026, postponed some obligations but did not remove them. The current timeline is:
- February 2025: prohibited practices and the AI literacy obligation.
- August 2025: obligations for general-purpose AI (GPAI) models.
- August 2026: Article 50 transparency obligations (chatbots, synthetic content).
- 2 December 2027: Annex III high-risk systems (employment, credit, education, biometrics, essential services).
- 2 August 2028: high-risk systems embedded in regulated products (Annex I).
Where the AI Act and GDPR intersect
Sending personal data to an LLM is processing: it needs a legal basis, minimisation, information to data subjects and, if the provider is outside the EEA, safeguards for the international transfer. The AI Act adds data governance, logging and human oversight for high-risk systems.
The common denominator is evidence: being able to show an auditor or authority which data left, to which model, with what protection and under which policy.
The real risk: PII in prompts
Most leaks come not from the model but from usage: employees pasting whole documents, integrations sending unfiltered CRM records, or agents with broad access to internal systems. Banning AI does not work; the traffic simply moves to uncontrolled tools.
Recommended architecture: a governance layer between the company and the model
The pattern that works best is a proxy or gateway that intercepts every request before it reaches the LLM:
- Detects and anonymises or pseudonymises personal data in the prompt.
- Restores original values in the response, so users keep context.
- Applies policies per team, use case and model provider.
- Produces an auditable record of every interaction, sealed so it cannot be altered.
What to prepare now
Even though the high-risk regime applies in December 2027, GDPR is enforceable today. Inventory AI uses, classify their risk, define data policies per use case and start generating compliance evidence from day one instead of reconstructing it when an audit arrives.