Brief № 077 · Regulation
One AI file must answer several regulators
The EDPB wants digital regulators to share information. EU SMEs need one factual AI record with separate legal analyses before cooperation hardens.
On this page
The next difficult question about an AI system may not come from the regulator named on its compliance folder. The same facts can matter to a data protection authority, an AI market-surveillance authority, a consumer body or a sector supervisor, even when each applies a different legal test.
On 17 July 2026, the European Data Protection Board asked the European Commission for a clear legal basis allowing regulators with different competences to exchange enforcement information, including confidential information. The Board linked the pressure on data protection authorities partly to the rising number and complexity of complaints involving AI.
That request does not create a new company filing duty. There is no single EU inbox into which an SME must now upload its AI records. It does, however, expose a practical weakness in the familiar approach of keeping one account for privacy, another for the AI Act and a third inside procurement. When those accounts describe the same system differently, regulatory cooperation turns an internal documentation gap into an external credibility problem.
Cooperation is moving ahead of the single rulebook
The EU digital framework was never one rulebook. The GDPR protects personal data. The AI Act assigns duties according to a company’s role and the type of AI system. Consumer law tests commercial practices and redress. Employment, financial, medical and product rules add their own controls. Competition and platform rules address market power, access and choice.
Those regimes can overlap without merging. A customer-service assistant may process personal data under the GDPR, disclose that it is an AI system under Art. 50 of the AI Act, make claims that consumer law can test and connect to a payment or communications service with sector-specific duties. One interaction can therefore produce evidence relevant to several authorities.
Formal cooperation already exists in parts of the framework. Art. 40 of the Digital Markets Act created a high-level group containing data protection, competition, consumer, communications and media-regulatory networks. Its statutory role includes identifying interactions between the DMA and sector-specific rules. That machinery is aimed at gatekeepers, not ordinary small businesses, but it shows the direction of travel: specialist authorities are expected to compare views rather than work as isolated desks.
The EDPB’s 2026–2027 work programme goes further. It lists joint guidance on the interplay between the AI Act and GDPR, work with the Commission on the DMA and GDPR, guidance on the DSA and GDPR, cooperation with competition and consumer authorities, and a template for cross-regulatory cooperation agreements.
The Commission and EDPB also began joint work in April 2026 on competition and data protection guidance. A stakeholder process announced in July will feed that work. The precise legal bridges are still being built, but an SME should not treat today’s institutional boundaries as a durable information firewall.
Build one fact layer, not one legal opinion
The safest common record is deliberately unglamorous. It states what the system is, what it does, who controls each step and what changed. It does not try to compress every legal conclusion into a universal assessment.
| Fact layer | Minimum question | Evidence worth controlling |
|---|---|---|
| Identity | Which system and release are under review? | Internal ID, supplier, model, configuration, deployment and retirement dates |
| Purpose | What outcome was approved, and for whom? | Use-case statement, prohibited uses, target users and acceptance criteria |
| Roles | Who provides, deploys, integrates and operates it? | Contracts, role map, named business owner and technical owner |
| Data | What enters, leaves and remains? | Data-flow map, categories, sources, recipients, location and retention |
| Decisions | What can the output change for a person? | Workflow, thresholds, human review, refusal and appeal routes |
| Performance | What has actually been tested? | Test set, expected behaviour, error analysis and signed acceptance record |
| Change | What altered after approval? | Model, prompt, tool, data, interface and supplier change log |
| Events | What failed or was challenged? | Incident, complaint, override, rollback and remediation records |
Source: Flint Brief control model derived from the EDPB’s 2026–2027 cross-regulatory work programme and position paper. Last verified 2026-08-05.
This layer should contain observations that can be checked. “The assistant reads account balances from system X” belongs here. “Legitimate interests is the correct legal basis” belongs in a GDPR analysis. “The system is not high-risk” belongs in an AI Act classification record. “The recommendation is fair” is not a fact at all until the company defines the test and evidence behind it.
The distinction matters because a fact may remain stable while the legal interpretation changes. A new guideline, court judgment, supplier feature or national enforcement position may alter one assessment without changing the underlying data flow. If facts and conclusions are fused in a single document, every legal update risks rewriting operational history.
Give each regime its own overlay
A common fact record should feed separate legal overlays with clear owners. They may link to the same evidence, but they should not silently copy and diverge.
| Overlay | Questions it must answer | Typical owner |
|---|---|---|
| GDPR | Controller or processor roles, purpose, legal basis, transparency, rights, security, transfers and DPIA threshold | Privacy lead or DPO where appointed |
| AI Act | Provider or deployer role, prohibited practice screen, risk classification, instructions, logs, oversight and transparency | Product compliance or legal owner |
| Consumer | Accuracy of claims, material information, default settings, vulnerable users, cancellation and redress | Commercial compliance |
| Employment | Worker information, consultation, monitoring, discrimination, challenge and collective rules | HR and employment counsel |
| Sector or product | Safety, suitability, professional responsibility, record keeping and incident reporting | Sector compliance or quality owner |
| Competition or platform | Choice architecture, access to data, tying, interoperability and dependency | Competition counsel when relevant |
Source: regulatory categories reflected in the EDPB work programme, the EDPB competition-law position paper and Art. 40 DMA. Last verified 2026-08-05.
Separate overlays prevent two common errors. The first is assuming that a positive answer under one regime settles another. Valid consent under the GDPR does not by itself make a commercial practice fair. Human review in a workflow does not automatically establish meaningful oversight under every applicable rule. A supplier’s AI Act classification does not decide the SME’s controller obligations for its own data processing.
The second error is giving every reviewer access to everything. Cross-regulatory cooperation does not erase legal privilege, trade-secret controls, employee confidentiality or purpose limits. The common record needs permissions, document owners and a disclosure log. Legal advice should remain identified as advice rather than being pasted into an operational ticket that hundreds of staff can open.
Contradictions are more dangerous than missing polish
The EDPB’s January 2025 position paper on competition and data protection says cooperation can be mandatory in some cases and that its level still varies considerably between Member States. It also stresses that the two fields remain distinct, with different concepts, objectives and enforcement structures.
That combination is the reason to reconcile facts now. A polished DPIA saying a feature is optional will not survive contact with a product specification that makes the feature the default. An AI inventory calling an SME the deployer will look unreliable if the contract shows that it materially modified the system and sells it under its own name. A procurement questionnaire promising no training on customer inputs must match technical settings, subprocessor terms and observed network behaviour.
The useful control is a contradiction review, not a larger policy. Pick one system and compare the current contract, privacy notice, data-flow diagram, AI inventory entry, security review, user interface and sales claims. Mark every disagreement about purpose, role, data source, retention, human control or supplier behaviour. Resolve the underlying fact before debating its legal consequence.
This review should also record dates. “No personal data” may have been true before a support tool was connected. “Human approval required” may have changed when a workflow gained an automatic action. “Model version fixed” may no longer be true after a managed API update. A regulator comparing files needs to know whether it has found a contradiction or two accurate records from different moments.
A 30-day evidence drill
An SME does not need to predict which authority will ask first. It can test whether the company can assemble one coherent answer.
- Select the AI system that affects the largest number of customers, workers or consequential decisions.
- Name one operational owner and one person responsible for each applicable legal overlay.
- Freeze the current system identity: supplier, model, configuration, tools, data connections and release date.
- Draw the actual data and decision flow from input to output, action, review and deletion.
- Link existing contracts, notices, assessments, tests, incidents and user-facing claims to that flow.
- Run the contradiction review across procurement, privacy, security, product and marketing records.
- Separate observed facts, legal conclusions, assumptions and unresolved questions.
- Restrict privileged and confidential material, then create a log for any external disclosure.
- Simulate a request for the system’s purpose, roles, data sources, human controls, test results and last material change.
- Record what took longer than one working day to find and assign a repair date.
The objective is not to create a giant dossier in advance. It is to make the system explainable without inventing a fresh account for each recipient. If authorities gain stronger channels for sharing information, the SME should be confident that the shared facts remain the same — and that each legal conclusion can still show the distinct rule and reasoning that produced it.
Frequently asked questions
Has the EU already created a new cross-regulatory reporting duty?
No. The EDPB has asked the European Commission to propose a clear legal basis for information sharing between regulators. The request itself does not create a new filing channel or reporting obligation for companies.
Should an SME create one combined compliance assessment?
Create one controlled factual record for the system, but keep each legal assessment separate. The GDPR, AI Act, consumer law and sector rules ask different questions and may require different owners, access controls and retention periods.
Which facts should be common across the files?
At minimum: the system owner, intended purpose, company role, supplier and model versions, data flows, affected people, outputs, human review, deployment dates, tests, incidents and material changes.
Does this matter only to large platforms?
No. The DMA has formal cross-regulatory machinery for gatekeepers, but ordinary SMEs can still face overlapping data-protection, AI, consumer, employment, financial or product rules when they deploy the same system.
Sources
- Official EDPB calls for legal basis for cross-regulatory information sharing European Data Protection Board accessed
- Official EDPB work programme 2026-2027: easing compliance and strengthening cooperation European Data Protection Board accessed
- Official Position paper on interplay between data protection and competition law European Data Protection Board accessed
- Official Commission services and EDPB start joint work on competition and data protection guidance European Commission accessed
- Primary Regulation (EU) 2022/1925 — Digital Markets Act EUR-Lex accessed
Image credit: Photo: rows of old filing cabinets — Mike Stoll, Unsplash License (Unsplash)
Eleanor Whitcombe covers EU AI regulation for Flint Brief.
Spotted an error or want a right of reply? hello@flintbrief.com (subject [Right of reply]).