BestAIAgents.app

Compliance & Legal · Updated July 20, 2026

Which AI agents are GDPR-compliant?

By Michael Okeje · Founder & Editor

No AI agent is GDPR-compliant out of the box — compliance is a property of your deployment, not a badge the vendor holds. You are the controller. What you check for is an Article 28 DPA, a published sub-processor list, no-training-by-default, and a documented EU hosting region. Mistral and n8n host in the EU by default; Anthropic stores Claude data in the US.

The short version

  • GDPR compliance is a property of your deployment, not the product. You are the controller and carry the legal risk even when the agent is someone else's software.
  • Four contract checkpoints do most of the work: an Article 28 data processing agreement, a published sub-processor list, no-training-on-your-data by default, and a documented EU hosting region.
  • EU data residency is rarer than the marketing implies. Anthropic states Claude data is stored in the US; OpenAI's EEA+CH API region is gated behind Zero Data Retention approval; Azure OpenAI 'Global' deployments may process prompts in any geography.
  • If your agent decides something about a person on its own — credit, hiring, pricing — Article 22 applies. Under the CJEU's SCHUFA ruling (7 December 2023) an automated score is itself the decision when a human leans on it decisively.
  • A DPIA is the default expectation, not the exception: an agent that profiles people at scale using new technology trips several of the EDPB's nine high-risk criteria, and two are enough.
  • The EU AI Act's Article 50 transparency duty applies from 2 August 2026 and was not postponed. Only the high-risk deadlines moved — to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

AI agent and automation vendors — EU data residency and GDPR contract checkpoints (verified against official trust, legal and documentation pages, July 2026)

VendorEU data residencyPublic DPATrains on your data by default?Certifications
Mistral (Le Chat, API)Yes — EU by default, US is opt-in; some features may transfer temporarilyYesNo on paid tiers; yes on Free/Pro unless you opt outISO 27001, ISO 27701, SOC 2 Type II
n8nYes — EU-hosted cloud, plus full self-hostingYesNoSOC 2 Type II (ISO 27001 not listed)
OpenAI (API)Yes — EEA+CH region via a separate EU endpoint, but gated behind Zero Data Retention or Modified Abuse Monitoring approvalYesNo, for API and enterprise tiersISO 27001:2022, ISO 42001, SOC 2 Type II
Microsoft Azure OpenAIPartly — EU Data Boundary regions exist, but 'Global' deployment types may process prompts in any geographyYesNoISO 27001
MakeYes — EU or US data centre, selected per organisationYesNot stated in the DPAISO 27001, SOC 2 Type II
Anthropic (Claude, Claude Code)No — Anthropic states data is stored in the US; European regions via cloud partners marked as comingYesNoISO 27001:2022, ISO 42001, SOC 2 Type I and II
ZapierNot documented on official pagesYesNot statedSOC 2 Type II (its ISO 27001 wording covers infrastructure providers, not Zapier itself)

There is no such thing as a GDPR-compliant AI agent

The phrase is a category error, and vendors are happy to let you make it. The GDPR does not certify products. It allocates responsibility between two roles: the controller, who decides why and how personal data is processed, and the processor, who processes it on the controller's documented instructions. When you deploy an AI agent to handle your customer emails, screen your applicants, or enrich your CRM, you are the controller. The vendor is your processor. The legal exposure sits with you, and no amount of trust-centre badging moves it.

What a vendor can do is make compliance achievable or impossible. That is the real question behind "is this agent GDPR-compliant?" — not whether the vendor has a certificate, but whether it gives you the contractual and technical hooks you need to discharge your own obligations. Article 28(1) puts it plainly: a controller may use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. If a vendor will not sign a data processing agreement, will not tell you who its sub-processors are, or will not say where your data is processed, you cannot lawfully use it for EU personal data. That is a vendor-selection filter you can apply before you ever look at features.

This also means the answer changes by deployment, not by product. The same agent can be compliant in one configuration and unlawful in another — a point that matters more for agents than for ordinary SaaS, because an agent's whole value proposition is that it decides at runtime what to do with the data it can reach.

The four contract checkpoints — and what vendors actually offer

Start with the data processing agreement. Article 28(3) specifies what it must contain, and the list is not boilerplate: the subject-matter, duration, nature and purpose of processing; the type of personal data and categories of data subjects; and binding stipulations that the processor acts only on your documented instructions, imposes confidentiality on its staff, implements Article 32 security, assists you with data subject rights requests and with breach notification and DPIAs, deletes or returns the data at the end of the service, and submits to audits. It must also require the processor to tell you immediately if one of your instructions would breach the law. Most major AI vendors now publish a standard DPA that auto-incorporates into their terms — OpenAI, Anthropic, Microsoft, Google, Mistral, n8n, Zapier and Make all do.

Second, the sub-processor list. Article 28(2) says a processor cannot engage another processor without your authorisation, and under the usual general authorisation it must inform you of intended additions or replacements and give you the chance to object. Article 28(4) requires the same obligations to flow down, and keeps your direct processor fully liable for its sub-processors' failures. For AI agents this clause is doing heavy lifting, because the sub-processor chain is long and interesting: the model provider, the vector database, the cloud host, and every tool or API the agent is wired into. n8n publishes a sub-processor list that names US model providers — which tells you plainly that EU-hosted orchestration does not mean EU-only inference.

Third, training. "We do not train on your data" is now standard for paid and enterprise tiers at OpenAI, Anthropic, Microsoft and Google, and Anthropic's commercial terms carry it as a contractual prohibition rather than a policy statement. But check the tier. Mistral trains on Free and Pro data by default unless you opt out, while its paid Studio and enterprise plans do not. Make's DPA contains no no-training language at all. The difference between a policy page and a contract clause matters when you are the one who has to demonstrate accountability under Article 5(2).

Fourth, data residency — and this is where the marketing and the documentation diverge most sharply. Mistral hosts in the EU by default. n8n hosts its cloud in the EU and can be fully self-hosted. Make lets you pick an EU or US data centre per organisation. OpenAI does offer an EEA+CH region covering both storage and inference, but it runs on a separate endpoint and is gated behind Zero Data Retention or Modified Abuse Monitoring approval, so it is a sales conversation rather than a toggle. Anthropic is the clearest counterexample: its documentation states that Claude data is stored in the US, with European regions via cloud partners still marked as coming. And Microsoft's EU Data Boundary is real but conditional — for any Azure OpenAI deployment type labelled "Global", prompts and responses may be processed in any geography. Two traps worth naming explicitly: zero data retention is not data residency, and an infrastructure provider's certification is not the vendor's own.

Two vendors resisted verification and deserve a note rather than a table row. Salesforce publishes an explicit zero-retention commitment for Agentforce, but it is scoped to third-party LLM providers not retaining your data — which is a different claim from data never being used for training, and should not be merged with it. Salesforce's own EU Operating Zone documentation does not name Agentforce and excludes "select Einstein features" from EU-only processing, so treat Agentforce-on-EU-residency as unconfirmed until Salesforce documents it. Google publishes a Cloud Data Processing Addendum and a sub-processor list, and Generative AI on Vertex AI appears in its ISO 27001:2022 scope, but its Vertex data-residency and data-governance pages could not be verified directly, so we are not printing residency or training claims for it.

Article 22: when your agent is not allowed to decide alone

Article 22(1) gives people the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. Three elements have to line up: a decision, made solely by automation, with legal or similarly significant effect. Recital 71 gives the canonical examples — automatic refusal of an online credit application, and e-recruiting without human intervention. The Article 29 Working Party's framing is that this captures processing that may lead to exclusion or discrimination; processing with little or no effect on individuals does not qualify.

The case law has made this harder to design around than teams expect. In C-634/21 SCHUFA Holding, decided 7 December 2023, the Court of Justice held that credit scoring is itself an automated individual decision prohibited in principle by Article 22(1), where the client receiving the score — a bank, say — attributes to it a determining role in granting credit. The Court refused to treat only the bank's downstream act as the decision. Translate that into agent architecture: an intermediate score, ranking or recommendation produced by one component of your pipeline can be the regulated decision, if the human or system downstream leans on it decisively. A nominal human sign-off does not automatically take you out of Article 22.

In C-203/22 Dun & Bradstreet Austria, decided 27 February 2025, the Court addressed what you owe the person afterwards. Under Article 15(1)(h) the controller must describe the procedure and principles actually applied, concisely and intelligibly, so the person can understand which of their data was used and how — for instance by indicating how a variation in the data would have changed the result. Handing over a complex mathematical formula or an exhaustive step-by-step description of the automated process does not satisfy the obligation; neither is a sufficiently intelligible explanation. And where the controller pleads trade secrets, it must supply the allegedly protected material to the supervisory authority or court to balance the interests — a national rule categorically excluding access on trade-secret grounds is precluded. For agent builders, this rules out both extremes: you cannot answer with a shrug, and you cannot answer with a raw trace.

Where Article 22 does apply, you need one of three gateways: necessity for a contract, authorisation under Union or Member State law with safeguards, or explicit consent. For the contract and consent routes, Article 22(3) requires you to implement suitable measures including, at minimum, the right to obtain human intervention, to express a point of view, and to contest the decision. Article 22(4) further bars decisions based on Article 9 special-category data unless explicit consent or substantial public interest applies with safeguards. In practice the cleanest design is to keep the agent in a recommending role with a genuine, documented human decision step — genuine being the operative word after SCHUFA.

You almost certainly need a DPIA

Article 35(1) requires a data protection impact assessment before processing where a type of processing, in particular using new technologies, is likely to result in a high risk to people's rights and freedoms. Article 35(3) names three cases in particular: systematic and extensive evaluation of personal aspects based on automated processing including profiling, on which decisions with legal or similarly significant effect are based; large-scale processing of special-category or criminal-offence data; and systematic monitoring of a publicly accessible area on a large scale. Note that the first of these maps almost word for word onto Article 22(1) — if your agent is doing Article 22 decision-making, you are in mandatory-DPIA territory by construction.

The list is not exhaustive, and the operative guidance is WP248rev.01, endorsed by the EDPB in May 2018, which sets out nine criteria: evaluation or scoring; automated decision-making with legal or similar significant effect; systematic monitoring; sensitive or highly personal data; large-scale processing; matching or combining datasets beyond reasonable expectations; vulnerable data subjects; innovative use or new technological solutions; and processing that prevents people from exercising a right or using a service. The rule of thumb is that meeting two criteria normally means a DPIA is required, and in some cases one is enough.

Count them for a realistic agent deployment. An agent that scores inbound leads, triages support tickets by customer value, or ranks job applicants hits evaluation or scoring, automated decision-making, large-scale processing, and innovative use of new technology — four criteria, where two suffice. Deploy it against employees or customers and you add vulnerable data subjects, since the EDPB treats any relationship of imbalance, employees explicitly included, as engaging that criterion. The honest position is that for most non-trivial agent deployments touching personal data, a DPIA is the default expectation rather than an edge case.

Article 35(7) sets the minimum contents: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to rights and freedoms, and the measures envisaged to address them, including safeguards and security measures. For agents, the necessity-and-proportionality section is the one that bites, because it forces you to articulate why the agent needs the scope of data access you have granted it — a question most teams answer by default rather than by design.

Data minimisation and security are where agents actually break

Ordinary software processes the data you hand it. An agent decides at runtime which data to pull and where to send it, and that difference is what makes Article 5 and Article 32 harder to satisfy than for a conventional SaaS tool. Article 5(1)(c) requires personal data to be adequate, relevant and limited to what is necessary for the purpose. An agent given broad OAuth scopes across a mailbox, a CRM and a file store is not limited to what is necessary — it is limited to what is convenient. Scoping tool permissions per task, rather than granting the union of everything the agent might ever need, is the single most effective minimisation control available, and it is one you implement, not the vendor.

Article 5(1)(b) purpose limitation is the clause that catches log reuse. If conversation transcripts collected to answer customer queries are later mined for model improvement or product analytics, that is further processing that must be compatible with the original purpose. Article 5(1)(e) storage limitation catches agent memory and traces: persistent memory is a selling point for agents, and an indefinite retention liability at the same time. Default retention windows are real numbers you should know — Anthropic's default is two years for inputs and outputs on commercial API keys, Make retains logs 30 days by default — and zero-retention options generally exist but are gated behind enterprise plans and approval.

Then there is Article 32. It requires security appropriate to the risk for both controller and processor, and names pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience, restoration after incidents, and a process for regularly testing and evaluating the effectiveness of the measures. Article 32(2) specifically calls out risks of unauthorised disclosure of, or access to, personal data. Prompt injection sits squarely in that provision: an agent that reads untrusted content and holds credentials to send email or query a database is an exfiltration path, and the regular-testing obligation in Article 32(1)(d) is the textual hook for adversarially testing it before deployment rather than after an incident. Article 32(4) closes the loop, requiring that anyone acting under the controller's authority processes personal data only on the controller's instructions — which is exactly the constraint you are trying to impose on an autonomous system.

None of this is exotic. It is the same defence-in-depth reasoning covered in our guide on whether AI agents are safe, applied through the lens of a regulator who will ask you to demonstrate, not assert, that you did it.

Transfers: the US question, and where it stands in 2026

Most widely used AI agents route data to US companies, so Chapter V of the GDPR is unavoidable. The current position is stable but not settled. The European Commission's adequacy decision for the EU-US Data Privacy Framework, Implementing Decision (EU) 2023/1795 of 10 July 2023, remains in force and is listed by the Commission as current. It was challenged, and on 3 September 2025 the General Court dismissed the annulment action in Latombe v Commission (T-553/23), holding that the United States ensured an adequate level of protection at the date the decision was adopted. An appeal to the Court of Justice was lodged on 31 October 2025 and no ruling had issued as of July 2026. An appeal does not suspend the decision.

The practical consequence is that transfers to DPF-certified US importers are lawful today under Article 45, while a competent privacy team keeps standard contractual clauses in place as a fallback. That is not paranoia; it is the lesson of Safe Harbour and Privacy Shield, both of which were struck down after years of reliance. The 2021 SCCs, Commission Implementing Decision (EU) 2021/914, remain the operative Article 46 tool, and the major AI vendors incorporate them — OpenAI and Anthropic both attach Modules Two and Three, with Anthropic's clauses pointing to the Republic of Ireland. Mistral is the unusual case, using Module 4 with itself as exporter, which reflects an EU-first posture rather than a US-first one.

One caveat that catches people out: DPF certification is per-company and per-data-type, so check the vendor's actual listing rather than accepting a claim on a marketing page. A second: an EU hosting region does not remove the transfer question if the contracting entity is American. Make offers EU data centres, but its DPA names Celonis, Inc., a US entity, as the counterparty for EEA customers, with the DPF as the primary transfer mechanism and SCCs as fallback. EU-hosted and EU-contracted are different properties, and only one of them is usually advertised.

There is also a gap the Commission has not yet closed. It has said it is developing additional SCC sets, including for transfers to controllers or processors outside the EU whose processing is already directly subject to the GDPR. No adoption date is given, and no implementing decision adopting them could be found as of July 2026. If your importer falls into that category, the 2021 modules remain an awkward fit.

Does self-hosting an open-source agent fix it?

It removes one contract and adds nothing else. Self-hosting does not reduce your obligations — it concentrates them on you.

What genuinely changes: if you run an open-weights model on your own EU infrastructure with no third party processing personal data on your behalf, there is no processor, so no Article 28 DPA is required for the model itself, and if nothing leaves the EEA the Chapter V transfer obligations fall away for that flow. Those are real simplifications, and they are why regulated industries keep gravitating to self-hosted stacks. n8n is the practical example here, since it can be run entirely on your own infrastructure — though note its licence is the Sustainable Use License, which is source-available rather than open source, and permits use for internal business purposes or non-commercial use rather than any use at all.

What does not change is longer. You are still the controller, now unambiguously and solely, with no processor sharing the operational burden. The DPIA obligation applies on exactly the same triggers — self-hosting is not an Article 35 exemption. Article 22 applies unchanged, because the legal character of an automated decision does not depend on who owns the GPU. You still need a lawful basis, and purpose limitation and minimisation apply as before. Article 32 security is now entirely yours, including all the controls a hyperscaler would otherwise have implemented and evidenced through SOC 2 and ISO 27001 reports — which is a meaningful amount of work to absorb.

The model's provenance also remains your problem. In Opinion 28/2024, adopted 17 December 2024, the EDPB held that where an AI model was developed using unlawfully processed personal data, that can affect the lawfulness of its deployment, unless the model has been duly anonymised. The same opinion sets a demanding anonymity test: it must be very unlikely both that individuals whose data was used can be identified, and that such data can be extracted from the model through queries. Downloading open weights does not launder upstream unlawfulness. And self-hosted agents still call third-party tools and APIs, each of which can reintroduce processors and transfers through the back door.

The EU AI Act runs alongside the GDPR, not instead of it

Two separate regimes apply, and satisfying one does not discharge the other. The GDPR regulates personal data. The AI Act, Regulation (EU) 2024/1689, regulates AI systems by role — provider or deployer — and by risk class, regardless of whether personal data is involved and regardless of where you host.

The timeline as it stands in July 2026: the prohibitions on certain AI practices and the AI literacy requirements have applied since 2 February 2025. The general-purpose AI model obligations, the governance framework and the penalty provisions have applied since 2 August 2025, with GPAI models placed on the market before that date having until 2 August 2027 to comply.

The important recent change is the Digital Omnibus simplification package, which is no longer a proposal. The European Parliament endorsed it on 16 June 2026 by 423 votes to 57 with 174 abstentions, and the Council gave its final green light on 29 June 2026. It defers the high-risk deadlines substantially: standalone Annex III high-risk systems move from 2 August 2026 to 2 December 2027, and Annex I systems embedded in regulated products move to 2 August 2028. If you have been treating August 2026 as your high-risk deadline, you have more time than you thought.

What did not move is the part most likely to apply to an ordinary AI agent. The Article 50 transparency obligations still apply from 2 August 2026. Article 50(1) requires providers to design AI systems intended to interact directly with people so that those people are informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person given the circumstances and context of use. Article 50(4) requires deployers generating deepfake image, audio or video content to disclose that it is artificially generated or manipulated, with narrower rules for evidently artistic, creative, satirical or fictional work, and a parallel duty for AI-generated text published to inform the public on matters of public interest. If you have deployed a customer-facing agent that could be mistaken for a person, that is the clause to read first.

Note also that fine-tuning and deploying your own system can make you a provider rather than a mere deployer, with correspondingly more obligations — another reason the self-hosting route is not the simplification it looks like.

What EU enforcement has actually looked like

The enforcement record is instructive mainly for what it does not yet include. The Italian Garante has been the most active authority. It fined OpenAI €15 million and ordered a six-month institutional communication campaign across radio, television, newspapers and the internet, on grounds of failing to notify the March 2023 data breach, processing users' personal data to train ChatGPT without an appropriate legal basis, breaching transparency and information obligations, and lacking age verification mechanisms. Because OpenAI established its European headquarters in Ireland during the investigation, the Garante transferred the file to the Irish Data Protection Commission as lead supervisory authority for continuing violations.

The Garante also fined Luka Inc., the US operator of the Replika companion chatbot, €5 million, and simultaneously opened a fresh investigation into the training of the underlying generative model — examining risk assessments across development and training, the categories of data used, and whether anonymisation or pseudonymisation was implemented. Its earlier Replika decision held that performance of a contract cannot be a lawful basis where children are involved, since minors cannot conclude valid contracts under Italian law.

On 30 January 2025 the Garante ordered an emergency limitation of processing against the two DeepSeek entities and opened an investigation. The trigger is worth noting: the companies had responded to the authority's information request by declaring that they do not operate in Italy and that European legislation does not apply to them — a position the Garante found contradicted by its own findings and deemed entirely unsatisfactory. The privacy policy was also available only in English.

The pattern across all three is consumer-facing chatbots, and the recurring themes are training legal basis, transparency and minors. As of July 2026 there appears to be no GDPR enforcement action anywhere in the EU specifically targeting an agentic AI product with tool and API access, or an automation platform. That is a timing artefact, not a safe harbour. The agents now being deployed have broader data access and more autonomy than the chatbots that drew these fines, and the regulatory theories already tested — unlawful training data, inadequate transparency, no lawful basis — transfer directly.

A practical pre-deployment checklist

Before an AI agent touches EU personal data, work through this in order. Confirm you have a signed or auto-incorporated Article 28 DPA covering all required content, and read the sub-processor list rather than noting that one exists. Establish where processing actually happens — not where the company is headquartered, and not where data is stored at rest, but where inference runs. Confirm the no-training position for your specific tier, in the contract rather than a help page. Check the transfer mechanism, and whether the contracting entity is EU or US even when the hosting is EU.

Then turn to your own side of the line. Scope the agent's tool permissions to the task rather than to convenience. Set and document retention for conversation logs, agent memory and traces, and ask whether zero-retention is available on your plan. Run a DPIA — assume you need one, and document the reasoning if you conclude otherwise. Identify whether any decision the agent makes engages Article 22, and if so build a genuine human decision step and an explanation you could actually give a data subject under Article 15(1)(h). Test adversarially for prompt injection before deployment, and record that you did, because Article 32(1)(d) asks for a process, not a one-off. Finally, if the agent interacts directly with people, make sure it tells them it is an AI system — that obligation arrives on 2 August 2026 and will not wait for the rest of the AI Act.

None of this makes an agent "GDPR-compliant". It makes your deployment defensible, which is the only thing the regulation actually asks for.

Indexed agents mentioned here

Real, verified agents from our index referenced in this answer.

ChatGPT agent$20/mo (ChatGPT Plus)

Agent mode inside ChatGPT: browses, clicks, and completes tasks

Claude Code$20/mo

Terminal-native autonomous coding agent from Anthropic

Manus$39/mo

General AI agent that plans and executes whole tasks in the cloud

Fin$0.99/resolution

The market-leading AI support agent, priced per resolution

SierraCustom enterprise

Branded enterprise AI agents for chat and voice

Frequently asked questions

Is ChatGPT GDPR-compliant?

ChatGPT is not compliant or non-compliant by itself — your deployment is. OpenAI provides a DPA, standard contractual clauses, no-training-by-default on API and enterprise tiers, and an EEA+CH API region gated behind Zero Data Retention approval. Italy's Garante fined OpenAI €15 million over training legal basis, transparency and age verification.

Do I need a DPA with my AI agent vendor?

Yes, if the agent processes personal data on your behalf. Article 28(3) requires a binding contract covering the subject-matter, duration, nature and purpose, data types and data subjects, plus documented-instructions-only processing, confidentiality, security, deletion or return, and audit rights. Most major vendors auto-incorporate a standard DPA into their terms.

Which AI agents offer EU data residency?

Mistral hosts in the EU by default, n8n hosts its cloud in the EU and can be self-hosted, and Make lets you pick an EU data centre. OpenAI offers an EEA+CH API region behind approval. Anthropic states Claude data is stored in the US. Azure OpenAI depends on deployment type — 'Global' processes anywhere.

Does self-hosting an open-source AI agent make it GDPR-compliant?

No. It removes the need for a DPA with a model provider and can eliminate international transfers, but you remain the controller and still need a lawful basis, a DPIA, Article 32 security and Article 22 safeguards. You also absorb all security work a cloud provider would otherwise evidence through SOC 2 and ISO 27001.

Do I need a DPIA before deploying an AI agent?

Usually yes. Article 35 requires one where processing is likely to result in high risk, particularly using new technologies. The EDPB's nine criteria mean two triggers are normally enough, and a typical agent that scores or profiles people at scale hits four: evaluation, automated decision-making, large-scale processing and innovative technology.

Can an AI agent make decisions about people under GDPR?

Only within Article 22. Decisions made solely by automation with legal or similarly significant effects are prohibited unless necessary for a contract, authorised by law, or made with explicit consent — and then you must offer human intervention, the right to express a view, and the right to contest the decision.

Does a human reviewing the agent's output take me outside Article 22?

Not automatically. In C-634/21 SCHUFA, decided 7 December 2023, the Court of Justice held that an automated score is itself the regulated decision where the recipient attributes to it a determining role. Rubber-stamp review does not qualify — the human step has to be genuine, informed and documented.

Is it legal to send EU personal data to a US AI provider?

Yes, currently. The EU-US Data Privacy Framework adequacy decision of July 2023 remains in force; the General Court dismissed a challenge on 3 September 2025 and an appeal is pending without suspensive effect. Check the vendor's actual DPF listing, and keep 2021 standard contractual clauses in place as a fallback.

Does the EU AI Act apply to my AI agent?

Probably in part. Prohibitions and AI literacy have applied since February 2025 and GPAI obligations since August 2025. Article 50 transparency — telling people they are interacting with an AI system — applies from 2 August 2026. High-risk obligations were deferred to 2 December 2027 for Annex III systems.

Has any company been fined over an AI chatbot in the EU?

Yes. Italy's Garante fined OpenAI €15 million and Luka Inc., operator of Replika, €5 million, and in January 2025 ordered an emergency processing limitation against DeepSeek. All three concerned consumer chatbots and centred on training legal basis, transparency and protection of minors rather than agentic tool use.

Keep reading