Interplay Between the AI Act, the CRA and the GDPR: Understanding How Digital Regulations Overlap

Artificial intelligence is now at the heart of digital compliance challenges. Its development takes place within an increasingly complex regulatory environment, where obligations continue to multiply. Today, a single product or service may simultaneously fall under the AI Act when it incorporates an AI system or model, the Cyber Resilience Act (CRA) when it qualifies as a product with digital elements, and the GDPR whenever it involves the processing of personal data. In this context, organizations can no longer assess digital regulations in isolation. 

The Cyber Resilience Act (CRA), the AI Act and the GDPR represent three complementary pillars of the European digital regulatory framework. Each pursues a distinct objective: the CRA governs the cybersecurity of products with digital elements, the AI Act regulates AI systems and models that are placed on the market, put into service or used within the European Union, while the GDPR applies whenever personal data are processed. 

For organizations, the challenge is therefore not choosing between these regulatory frameworks, but identifying when they apply independently, when they overlap, and how they should be combined to achieve compliance. 

I- Understanding the Distinct Objectives of the CRA, the AI Act and the GDPR 

The CRA: Ensuring the Security of Products with Digital Elements 

The Cyber Resilience Act is built around a product security approach. It does not only target AI systems or personal data processing activities, but more broadly all products with digital elements, including software, connected hardware, software components and digital solutions. 

This objective is reflected in mandatory cybersecurity requirements applicable to manufacturers, importers and distributors of products with digital elements placed on the EU market. These requirements cover the entire product lifecycle, from design, development and production to maintenance, vulnerability management and the provision of security updates. 

In practice, the CRA encourages organizations to view cybersecurity as an intrinsic product requirement rather than a measure added afterwards. Compliance must therefore be embedded at the design stage and maintained throughout the product lifecycle to ensure an appropriate level of security based on the product’s intended use and associated risks.

The AI Act: Regulating Risks Associated with AI Systems and Models 

The AI Act follows a risk-based approach to regulating artificial intelligence. It does not focus on digital products as such, but on AI systems and AI models placed on the market, put into service or used within the European Union. 

This objective is implemented through different categories of obligations depending on whether the AI system constitutes a prohibited practice, a high-risk AI system, an AI system subject to transparency requirements, a general-purpose AI model, or an AI application presenting limited risks. 

In practice, the AI Act requires organizations to classify their AI systems as early as the design or acquisition phase in order to determine the applicable risk level and the governance measures that must be implemented. Compliance must therefore be integrated throughout the AI system lifecycle, from design to deployment, monitoring and subsequent modifications.

The GDPR: Protecting Individuals Subject to Personal Data Processing 

The GDPR is based on the protection of individuals whose personal data are processed. It does not apply because a product is digital or because AI technology is used, but whenever personal data processing takes place. 

This objective is achieved by regulating the conditions under which personal data may be collected, used, stored, shared or deleted. In particular, the GDPR requires that processing activities be lawful, transparent, proportionate and limited to what is necessary in light of the purposes pursued. 

In practice, the GDPR encourages organizations to integrate data protection into the design of the relevant products, services and systems. Compliance therefore requires identifying the personal data processed, the purposes pursued, the data subjects concerned and the safeguards necessary to protect their rights and freedoms throughout the processing lifecycle. 

II- The Interplay of Regulations in Modern Digital Use Cases 

For many years, cybersecurity, personal data protection and artificial intelligence were addressed separately by different teams. Digital products were primarily assessed from a technical and security perspective, AI systems from a data or innovation perspective, and personal data processing activities from a legal or compliance perspective. 

This siloed approach is becoming increasingly inadequate. Modern digital products and services combine multiple technological and functional layers. A single service may simultaneously constitute:

  • a product with digital elements potentially falling within the scope of the CRA; 
  • an AI system, or incorporate an AI model, potentially falling within the scope of the AI Act; 
  • a personal data processing activity subject to the GDPR. 

For example, a connected health device incorporating predictive analytics functionality may simultaneously qualify as a digital product, an AI system and a personal data processing activity. Likewise, a customer support application integrating a conversational agent may fall under the AI Act, the GDPR and, depending on how it is made available, the CRA. 

The correct approach is therefore to start from the specific use case and assess, step by step, whether the product or service falls within the scope of the CRA, the AI Act, the GDPR, or a combination of these frameworks. 

III- Identifying the Main Regulatory Scenarios 

1. The Product Contains Digital Elements Only 

Where a product contains digital elements but neither incorporates an AI system nor involves the processing of personal data, it will primarily fall under the CRA and generally remain outside the scope of both the AI Act and the GDPR. 

For example, software embedded in a connected industrial machine and used solely to control its operation based on technical data may fall under the CRA without triggering obligations under the AI Act or the GDPR. 

In this scenario, the primary objective is to ensure the cybersecurity of the product throughout its lifecycle by complying with the requirements introduced by the Cyber Resilience Act.

2. The Product Contains Digital Elements and Incorporates an AI System or Model 

Where a product with digital elements incorporates an AI system or AI model, both the CRA and the AI Act may apply simultaneously. 

For example, a weather forecasting application that uses an AI model to analyze meteorological data and generate local forecasts may fall under the CRA as a digital product and under the AI Act because of its AI functionality. 

In this situation, the two regulations address different aspects. The CRA focuses on product cybersecurity, whereas the AI Act governs the risks associated with the embedded AI system or model. 

3. The Product Contains Digital Elements, Incorporates an AI System and Processes Personal Data 

This is the most comprehensive scenario. A single product or service may simultaneously fall under the CRA, the AI Act and the GDPR when it contains digital elements, incorporates an AI system or model and processes personal data. 

For example, an application using a user’s geolocation data together with an AI system to recommend personalized travel routes may fall under all three regulations. The CRA may apply to the cybersecurity of the application, the AI Act to the route optimization or recommendation functionality, and the GDPR to the processing of location and usage data. 

In such cases, the three regulatory frameworks should be addressed through a unified compliance approach.

4. The Product Contains Digital Elements and Processes Personal Data, but Does Not Incorporate AI 

A digital product may also fall under both the CRA and the GDPR without being subject to the AI Act. 

For example, appointment scheduling software used by a business to allow customers to book appointments online may fall under both the CRA and the GDPR. 

In this scenario, compliance efforts must combine product cybersecurity requirements with personal data protection obligations. 

5. The Project Involves Personal Data Processing Only 

Finally, some projects may fall outside the scope of both the CRA and the AI Act while remaining fully subject to the GDPR. 

For example, a company maintaining a customer contact database for marketing communications processes personal data such as names, email addresses and interaction history. If this processing does not involve an AI system and does not concern a product with digital elements placed on the market, it will primarily be subject to the GDPR. 

In this case, compliance focuses on the legal framework governing personal data processing, including purpose limitation, legal basis, transparency obligations, retention periods and data subjects’ rights.

A Case-by-Case Assessment Is Essential 

These examples demonstrate that the interplay between the CRA, the AI Act and the GDPR cannot be determined in the abstract. It depends on the specific characteristics of the product or service, its functionalities, the technologies used, the data processed and the conditions under which it is made available. 

Organizations should therefore begin with the intended use case and ask the following questions: 

  • Does the product contain digital elements? 
  • Does it incorporate an AI system or AI model? 
  • Does it process personal data? 
  • Is it placed on the market, put into service or used within the European Union? 

This approach makes it possible to identify the applicable regulations, understand areas of overlap and establish a more coherent compliance strategy while avoiding unnecessary duplication and regulatory blind spots.

IV- Building an Integrated Compliance Approach Across the CRA, the AI Act and the GDPR 

The relationship between the CRA, the AI Act and the GDPR is not merely a legal qualification exercise. It also requires an appropriate internal organization capable of addressing cybersecurity, artificial intelligence and data protection issues simultaneously. 

In digital projects, the same information can often support several compliance initiatives. Product descriptions, functionalities, data used, identified risks, security measures and governance decisions may all contribute to CRA, AI Act and GDPR assessments. 

The objective is therefore to avoid creating three completely separate compliance streams. Excessive compartmentalization may lead to duplication, inconsistencies and regulatory blind spots. By contrast, an integrated governance framework helps organizations streamline assessments, strengthen decision traceability and manage compliance more effectively throughout the product lifecycle. 

In practice, this means: 

  • mapping relevant products, services, AI systems and personal data processing activities; 
  • determining applicable regulations from the design, acquisition or processing initiation stage; 
  • coordinating product, legal, compliance, cybersecurity, data and privacy teams; 
  • documenting qualification decisions and implemented measures; 
  • monitoring product and processing evolutions throughout their lifecycle; 
  • updating assessments whenever functionalities, data or use cases evolve. 

This approach enables organizations to move from regulation-by-regulation compliance towards use-case-driven compliance. It is particularly valuable where digital products evolve rapidly, incorporate new AI functionalities or rely on increasingly complex data processing activities.

Anticipating Regulatory Overlaps with Naaia 

With Naaia, organizations can structure their compliance efforts by identifying their AI systems, digital use cases and applicable regulations. The platform already enables organizations to document assessments, identify obligations arising from the AI Act and the GDPR, and track related compliance actions. Future CRA integration will also support the identification and management of cybersecurity obligations applicable to products with digital elements. 

By centralizing system inventories, use case qualification, obligation management and decision traceability, Naaia helps organizations move from fragmented compliance processes to a more coherent, operational and sustainable digital governance framework.