Automatic decisions with AI: GDPR and AI Act in view

10. September 2026 Laura Künstliche Intelligenz DSGVO AI Act Datenschutz

Automatic decisions through AI systems have become increasingly important in many industries. But with the GDPR and the AI Act, the requirements for data protection and transparency become stronger. The article explains why GDPR Article 22 alone is not enough and how the AI Act provides additional protection. The focus is on the responsibility of companies using AI systems and the need to protect the rights of users.

The AI Act sets new standards for the use of AI. It requires systems to be transparent and users to be informed about the use of their data. In addition, companies must ensure that automated decisions are not discriminatory or inadmissible. The GDPR already stipulates that personal data may not be processed without consent. The AI Act complements these requirements and creates additional protective measures to minimize risks.

The impact of regulation is varied. Companies need to review their AI systems to ensure they comply with legal requirements. This applies not only to technology, but also to processes and communication with users. Transparent handling of data is crucial to gaining trust and avoiding legal risks.

## What does this mean for your company? Automatic decisions by AI can be efficient, but they require a clear legal basis. Companies must ensure that their systems are transparent and that users’ rights are respected. It is important to inform users about the use of their data and to give them the opportunity to object. Compliance with GDPR and the AI Act is not only a duty, but also an opportunity to build trust and implement innovation responsibly.

## How ISN/xynap supports this xynap’s AI technologies and data protection-compliant infrastructure help you use AI systems responsibly. Our modules ensure that automated decisions can be implemented transparently and securely.

Sources (2)

  1. www.dr-datenschutz.de
  2. www.heise.de