Regulatory Timeline
A dated view of the EU and DACH data-protection and AI developments that make protecting data in AI systems a present concern, and what they mean in practice. Background, not legal advice.
Audience: security and compliance leads, Data Protection Officers, and engineering leaders adopting AI on sensitive data in the EU and DACH region
The ground under AI adoption has moved quickly, and enforcement is now active and coordinated across EU supervisory authorities. This page tracks the developments most relevant to a team putting sensitive data through AI, with dates and sources, and what each one means in practice. It is background, not legal advice. For the section 203, CLOUD Act, and transfer detail, see Data Sovereignty.
Timeline
23 May 2024: EDPB ChatGPT Taskforce report
The European Data Protection Board published the first coordinated EU position on the GDPR and generative AI, covering lawfulness, fairness, accuracy, transparency, and data-subject rights, and noting investigations across several member states. It signaled that the supervisory authorities were treating generative AI as a live GDPR matter, not a future one.
1 August 2024: EU AI Act enters into force
The EU AI Act became law, with obligations phasing in over the following years. Prohibited practices (Article 5) and AI-literacy duties (Article 4) applied from 2 February 2025, obligations for general-purpose AI from 2 August 2025, and, on the original timeline, most high-risk-system obligations from 2 August 2026, with later transition dates for some categories. The high-risk dates were later deferred by the Digital Omnibus (see the entry below), while the February 2025 prohibited-practice and AI-literacy duties were not (see the EU AI Act section in Data Sovereignty).
December 2024: EDPB opinion on personal data in AI models
The EDPB adopted Opinion 28/2024 (17 December 2024) on how the GDPR applies to personal data used to build and run AI models, addressing when a model can be considered anonymous, the use of legitimate interest as a legal basis, and the consequences of unlawful processing in the training data. It set expectations that reach the data you send to a model, not just the model itself.
20 December 2024: Garante fines OpenAI EUR 15 million
The Italian supervisory authority (Garante) issued one of the first major GDPR fines against a generative AI provider, citing the lack of an adequate legal basis for training-data processing, a failure to notify a 2023 breach, and weak age verification, and it ordered a public awareness campaign. OpenAI is appealing and the final outcome is still being litigated. The durable point stands regardless of the amount: a DPA enforced the GDPR directly against a generative AI provider.
30 January 2025: Garante limits DeepSeek, and DACH follows
The Garante ordered an immediate limitation on the processing of Italian users' data by the operators of DeepSeek, and the app was removed from the Italian Apple and Google stores. a German data-protection authority asked Apple and Google to remove it from German stores over transfers of personal data to China, and the Netherlands restricted it on government devices. Several other member states opened their own probes.
3 September 2025: the Data Privacy Framework is upheld, for now
The EU General Court dismissed the Latombe challenge to the EU-US Data Privacy Framework, so the transfer basis remains valid. An appeal to the Court of Justice is pending, and a separate challenge continues, so the durability of the framework is not settled (see Data Sovereignty).
7 May to 29 June 2026: the Digital Omnibus defers the high-risk deadlines
The EU agreed to move the high-risk applicability dates. Council and Parliament reached a political agreement on 7 May 2026, the Parliament endorsed the package on 16 June 2026, and the Council gave its final green light on 29 June 2026. Under the deferral, stand-alone Annex III high-risk obligations move from 2 August 2026 to 2 December 2027, and high-risk AI embedded in Annex I regulated products moves to 2 August 2028. The Article 4 AI-literacy and Article 5 prohibited-practice duties, in force since 2 February 2025, are not deferred.
The new dates bind only once the Omnibus is published in the EU Official Journal, entering into force on the third day after publication. Publication was anticipated in July 2026; verify the current Official Journal status before relying on the December 2027 date, because until publication the original 2 August 2026 date remains the formal law.
2 August 2026: original EU AI Act high-risk date (deferred, pending Official Journal)
On the original timeline, most obligations for high-risk AI systems, including the Article 10 data-governance requirements, apply from this date. The Digital Omnibus (above) defers the stand-alone Annex III high-risk obligations to 2 December 2027, binding once published in the Official Journal. Until that publication the 2 August 2026 date is still the formal law, so plan against it and treat the deferral as runway, not a cancellation. Article 50 transparency obligations were not among the deferred high-risk items; confirm the final scope on Official Journal publication.
What this means in practice
- Enforcement is active and coordinated. The first GenAI GDPR fine and the DeepSeek actions show supervisory authorities acting quickly and together, and app-store and device-level restrictions show the measures are not only monetary.
- The transfer basis is not settled. Relying on the Data Privacy Framework alone carries the risk that a future ruling moves the ground, as it did twice before.
- Data minimization is the durable response. The less identifiable data you send to a model, the less exposed you are to any single rule changing, which is why the supervisory authorities point to technical measures alongside contracts.
Where OGuardAI fits, honestly: it does not make you compliant and it does not replace a data processing agreement, a transfer assessment, or legal counsel. It narrows what leaves your runtime by tokenizing detected identifiers before the request reaches a model, which is one technical data-minimization measure inside the assessment you still own. See Approaches for how that compares to the alternatives and Trust for the honest posture.
Sources
- EDPB, Report of the work undertaken by the ChatGPT Taskforce (23 May 2024).
- EDPB Opinion 28/2024 on personal data in AI models (17 December 2024).
- Garante, decision fining OpenAI EUR 15 million (20 December 2024).
- Garante, limitation order on DeepSeek operators (30 January 2025) and subsequent DACH actions.
- EU General Court, dismissal of the Latombe challenge to the EU-US Data Privacy Framework (3 September 2025).
- Council of the EU press release, "Artificial Intelligence: Council and Parliament agree to simplify and streamline rules" (7 May 2026), and subsequent Parliament endorsement (16 June 2026) and Council green light (29 June 2026) on the Digital Omnibus.
- Regulation (EU) 2024/1689 (EU AI Act), application dates, as amended by the Digital Omnibus (verify the Official Journal publication status).
Approaches
The four common ways teams protect data when adopting AI, their real tradeoffs, and where OGuardAI fits. OGuardAI is not the right choice for every case.
EU AI Act Readiness
What the EU AI Act requires, an honest map of where OGuardAI helps and where it does not, and what stays the customer's. Background, not legal advice.