Why AI systems belong in the records at all
As soon as an AI system processes personal data – for instance in candidate screening, a customer-service chatbot, scoring models, or generative AI handling user input – this constitutes a processing activity within the meaning of the GDPR. Art. 30(1) GDPR obliges every controller to maintain a record of “all categories of processing activities carried out” under its responsibility. This applies regardless of whether the system qualifies as high-risk AI under the AI Act (EU) 2024/1689. The obligation under Art. 30 GDPR is tied to data processing, not to an AI-specific risk classification. Anyone waiting for the AI Act to become “active” for their system overlooks the fact that the GDPR obligation already applies in many cases.
What Art. 30 specifically requires
Under Art. 30(1) GDPR, the record must include, among other things:
- the purposes of the processing (lit. b) – for AI systems, for example, “automated pre-selection of job applications” or “creation of customer profiles for product recommendations”;
- categories of data subjects and categories of data (lit. c) – for training and inference data, this often needs to be framed more broadly than for classic processing, since models frequently work with heterogeneous, sometimes historical datasets;
- categories of recipients, including recipients in third countries (lit. d), for instance where a cloud-based foundation model is hosted outside the EU;
- transfers to third countries, including the safeguards under Art. 49(1) second subparagraph (lit. e) – relevant for many AI providers based in the US;
- retention periods, where possible (lit. f);
- a general description of the technical and organisational measures under Art. 32(1) (lit. g).
For processors, Art. 30(2) GDPR sets out a reduced but distinct catalogue. If your company uses an external AI service on behalf of a client, this may become relevant – examine the allocation of roles in the specific use case carefully.
Common gaps in practice
Three patterns come up regularly:
The purpose is defined too vaguely. “AI-assisted analysis” does not meet the requirement under lit. b. What is needed is a description that identifies the specific purpose of use – for example, risk assessment, personalisation, or automated decision support.
Training data is missing from the records. Where a model is fine-tuned or retrained using the company’s own personal data, this constitutes a separate processing activity with its own purposes and categories – it should be recorded separately, not implicitly subsumed under “operation of the chatbot”.
Third-country transfers to AI providers are overlooked. Many AI services run on infrastructure outside the EU. Without documentation of the safeguards under lit. e, a gap arises that will become immediately apparent should the supervisory authority make an enquiry under Art. 30(4) GDPR.
Interface with the AI Act: Art. 50 from 02.08.2026
Alongside the GDPR obligation, AI-specific transparency duties are drawing closer: the obligations under Art. 50 AI Act apply from 02.08.2026, with a grace period until 02.12.2026 for systems already placed on the market beforehand. Art. 50 concerns, in particular, the labelling of AI interactions and AI-generated content towards affected persons. These transparency obligations do not replace the documentation duty under Art. 30 GDPR – they supplement it. Anyone who already has to capture the purposes and data categories of an AI system for the records has a solid starting point for preparing the information duties under Art. 50 as well. The further-reaching high-risk obligations under Annex III of the AI Act are a separate matter – they only apply from 02.12.2027 and concern a different tier of obligations.
The 250-employee threshold – and its limits
Art. 30(5) GDPR generally exempts companies with fewer than 250 employees from the record-keeping obligation. However, this exception does not apply where the processing poses a risk to the rights and freedoms of data subjects, is not occasional, or involves special categories of data under Art. 9(1) or data under Art. 10 GDPR. AI systems that involve profiling, automated decisions, or the processing of sensitive characteristics regularly fall under this carve-out – in which case the size threshold offers no protection.
Whether your use of AI gives rise to a processing activity subject to documentation, and which further obligations under the AI Act apply in parallel, cannot be answered in general terms. You can get an initial overview of how your systems are classified using the free risk check at /einstufung.