Which rules apply to which firm: GDPR, DORA, SS1/23 and the AI Act?

Each uses its own test. GDPR and UK GDPR follow personal data and where the controller, processor or people are. The DORA regulation names the EU financial entities it covers, and their ICT suppliers. SS1/23 covers UK banks with internal-model approval. The AI Act turns on a firm’s role, where it is based, and where its system’s output is used.

David McMillan, Governed AI Deployment. Checked against the sources on .

§01GDPR Art. 2, GDPR Art. 3, UK GDPR Art. 3, DORA Art. 2, PRA SS1/23 para 1.2, Art. 2

Side by side

RuleWho it applies to
GDPRProcessing of personal data in the context of an establishment in the EU, or of people in the EU when offering them goods or services or monitoring their behaviour
UK GDPRThe same territorial test, for the United Kingdom
DORA regulationThe EU financial entities it lists, from credit institutions to crowdfunding service providers, and ICT third-party service providers
PRA SS1/23UK banks, building societies and PRA-designated investment firms with approval to use internal models for regulatory capital
EU AI ActProviders placing AI systems or general-purpose AI models on the EU market, or putting AI systems into service in the EU, deployers in the EU, and providers and deployers elsewhere whose system’s output is used in the EU, among others

§02Art. 113

When each applies

The AI Act’s high-risk rules apply from 2 December 2027 for systems classified as high-risk under Annex III, and from 2 August 2028 for those under Annex I. SS1/23’s principles are in effect. When the AI Act’s rules apply has the full table.

§03

Who decides

Whether a firm, a system or a use falls within any of these is for the firm and its counsel. A firm can fall within several at once.

§04

Sources

§05

Book a scoping call

Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.