Ever since the Digital Omnibus deferred high-risk system obligations to 2 December 2027, many companies have filed the AI Act under things to look at later. It is an understandable reading, and a mistaken one, because it conflates two different instruments.
The deferral concerns the Artificial Intelligence Regulation. It does not concern the General Data Protection Regulation, which has applied for eight years, has an active supervisory authority and a penalty regime that works today. And virtually any AI system a company deploys processes personal data.
Put differently: a Spanish SME’s real exposure in 2026 is not under the AI Act. It is before the AEPD.
Two instruments, one processing operation
It is worth understanding how they fit, because the relationship is not one of alternatives but of accumulation.
The AI Act regulates the system: what it is, what it is for, what risk it presents, who places it on the market and with what documentation. The GDPR regulates the processing: which personal data go in, on what legal basis, for how long, with what information to data subjects and what rights against the decision.
A single deployment triggers both. An AI system that helps screen candidates is, for AI Act purposes, an Annex III high-risk system whose obligations have been deferred. And it is, for GDPR purposes, processing involving profiling that requires a legal basis, an impact assessment, information about the logic involved, and respect for the candidate’s right not to be subject to a solely automated decision. The second is enforceable today.
The AEPD itself frames it this way in its material on processing involving artificial intelligence, placing Regulation (EU) 2024/1689 alongside the GDPR and the rest of the European data package as frameworks operating in parallel, not in substitution.
What the Agency’s practice teaches
Without waiting for the first file formally grounded in the AI Act, the AEPD’s activity in recent years already maps fairly clearly where the problems arrive from.
Biometrics is the most hostile terrain. This is where the Agency has been firmest. The best-known case remains the facial recognition system deployed in retail premises, which ended in one of the largest fines the AEPD has imposed. And its criteria on biometric attendance and access control in the workplace effectively closed a door many companies assumed was open: biometric data are special category data under Article 9, an employee’s consent is hardly free in a relationship of subordination, and without an adequate legal basis the system does not stand however efficient it may be.
The lesson for anyone assessing an AI product with a biometric component — access control, identity verification, in-store customer analysis — is that a good contract is not enough here: necessity and proportionality must be evidenced before anything is installed.
Automated decisions are underestimated. Article 22 GDPR grants the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects the person. Articles 13 and 14 require information about the existence of such decisions and about the logic involved.
The common error is not ignoring the rule: it is believing it does not apply because “a person always reviews it in the end”. To exclude Article 22, that review must be real and substantive, with effective capacity and authority to change the outcome. A formal sign-off on a list already ranked by the system is not.
The impact assessment is almost always mandatory and almost never done. Article 35 requires one where processing is likely to result in a high risk, and the criteria that determine this — profiling, systematic monitoring, special category data, large-scale processing, use of innovative technology — accumulate easily in any AI deployment. It is also one of the easiest failures to establish in an inspection: either the document exists or it does not.
Transparency arrives through two channels at once. The GDPR’s duty to inform does not disappear because Article 50 of the AI Act imposes its own. They are distinct obligations, with distinct addressees and content, and both must be met. We will look at this in detail in the next piece in this series.
And in the workplace there is a further layer. Article 64.4(d) of the Spanish Workers’ Statute, following the 2021 reform, requires informing employee representatives of the parameters, rules and instructions on which algorithms or artificial intelligence systems affecting working conditions, access to employment or retention of a post are based. It is a specific obligation, predating the AI Act, that many companies discover late.
Why the deferral is a trap
The practical conclusion is uncomfortable but clear. A company that deployed AI in 2026 and decided to wait until December 2027 has given itself relief under the instrument that does not yet penalise, and remains exposed under the one that already does.
There is an added effect worth anticipating. The work the GDPR requires — identifying the legal basis, documenting the impact assessment, describing the system’s logic, setting retention periods, mapping processors and transfers — is substantially the same material the AI Act’s technical file will later call for.
Whoever does it now out of data protection obligation will reach December 2027 with much of the ground covered. Whoever defers everything will have to do it twice, and in a hurry.
What to review this week
— Inventory which AI systems are deployed and which process personal data. Without an inventory, nothing else follows.
— Identify the legal basis for each processing operation, with particular attention to any involving biometric or special category data.
— Check whether any produces decisions with significant effects and, if so, whether the human intervention is real or decorative.
— Verify that an impact assessment exists where required, and document the analysis even where the conclusion is that none is needed.
— Review privacy notices: they must mention the existence of automated decisions and the logic involved.
— For deployments affecting staff, comply with the duty to inform employee representatives.
— Formalise processing agreements with providers and review international transfers.
Have you deployed AI in your company?
At Ferrer-Bonsoms & Sanjurjo we help companies organise this work: system inventory, legal basis analysis, impact assessments and the required documentation. If you have deployed AI and are unsure where you stand, get in touch and we will review it.
Download our free Artificial Intelligence Compliance Calendar 2026-2028: every AI Act application date after the Digital Omnibus, on a single page.
