The article numbers that collide

Both regimes number from Article 1, both are tested in the same exam, and several numbers land on completely unrelated subjects in each. Distractors are built from this directly: a real obligation, quoted with the right number, from the wrong instrument.

Number GDPR EU AI Act
Art. 5 Principles of processing Prohibited AI practices Both are the foundational article of their regime, which makes this the easiest one to hold.
Art. 6 Lawfulness — the six bases Classification rules for high-risk AI
Art. 9 Special categories of data Risk management system
Art. 10 Criminal conviction data Data and data governance Both are about data, which makes them feel adjacent — but one is a prohibition regime and the other a quality standard.
Art. 12 Transparent information and modalities Record-keeping and logging
Art. 13 Information where data is collected from the person Transparency and information for deployers Both say "transparency", to different audiences. GDPR 13 informs the individual; AI Act 13 informs the deployer.
Art. 14 Information where data is not obtained from the person Human oversight
Art. 15 Right of access Accuracy, robustness and cybersecurity
Art. 17 Right to erasure Quality management system
Art. 22 Automated individual decision-making Authorised representatives of providers The single most exploitable pair on the exam. See below.
Art. 25 Data protection by design and by default Responsibilities along the AI value chain AI Act 25 is where a deployer becomes a provider by rebranding or substantial modification.
Art. 26 Joint controllers Obligations of deployers of high-risk AI
Art. 27 Representatives of controllers not established in the Union Fundamental rights impact assessment The mirror of Art. 22. See below.

The 22 / 27 mirror — worth memorising as a pair

The same concept sits at swapped numbers, which is why these two are so easy to trade by accident:

Appoint an EU representative

GDPR Art. 27 · EU AI Act Art. 22

Everything else at those numbers

GDPR Art. 22 is automated decisions · AI Act Art. 27 is the FRIA

GDPR Article 22 in full

The single most-tested GDPR provision for AI, and the one where precision pays. Five things to hold:

1 The right, and its two conditions

Art. 22(1) gives the individual the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. Both limbs must be present: solely automated, and legal or similarly significant effect. An automated decision of no real consequence is outside it, and so is a consequential decision with genuine human involvement.

2 "Solely" is doing real work

A human placed in the loop to approve whatever the model outputs does not take the decision outside Art. 22. The involvement has to be meaningful: someone with the authority and the competence to reach a different conclusion, and the information needed to do it. Rubber-stamping is still solely automated in substance.

3 The three gateways — Art. 22(2)

Where the right is engaged, the decision is only permitted if it is necessary for entering into or performing a contract, authorised by Union or Member State law with suitable safeguards, or based on the individual’s explicit consent. Note that these permit the decision; they are not themselves the safeguards.

4 The safeguards — Art. 22(3)

For the contract and explicit-consent gateways, the controller must implement suitable measures to safeguard rights and freedoms, at least the right to obtain human intervention, to express a point of view, and to contest the decision. Read alongside Arts. 13–15, which require meaningful information about the logic involved and the significance and envisaged consequences.

5 Special categories — Art. 22(4)

Where the decision is based on special-category data, the menu narrows sharply. Only explicit consent or substantial public interest will do, and suitable safeguards must be in place. The other Art. 9(2) conditions are not available here.

The TDM exception

Text and data mining is the legal mechanism that makes training on a web-scale corpus arguable in the EU at all — and it is routinely met for the first time as a distractor:

What it is

Text and data mining is the automated analysis of text and data to generate information — which is, in substance, what training a model on a corpus does. Copying works in order to analyse them would ordinarily infringe copyright, so the EU created exceptions permitting it.

Where it comes from

The 2019 Copyright in the Digital Single Market Directive, not the AI Act. Art. 3 permits mining by research organisations and cultural heritage institutions for scientific research, and cannot be overridden. Art. 4 permits it for any purpose, including commercial — but only where rights have not been expressly reserved.

The opt-out is the whole point

Art. 4 is where commercial AI training sits, and its exception is conditional: a rights-holder may reserve their rights, in machine-readable form for content made publicly available online. Reserve the rights and the exception falls away, and mining that work needs a licence.

What the AI Act adds

The AI Act does not create the exception — it makes the opt-out enforceable. Providers of general-purpose AI models must put in place a policy to comply with EU copyright law, including identifying and respecting rights reservations, and must publish a sufficiently detailed summary of the content used for training. The summary is the transparency lever that lets a rights-holder tell whether their reservation was honoured.

The exam angle

Keep the two copyright questions apart. Inputs: is training on protected works infringement — fair use in the US, the TDM exception and its opt-out in the EU. Outputs: is what the model generates protectable — the human-authorship requirement. A distractor will say the TDM exception is unconditional, or that the AI Act created it.

How to stop trading the numbers

Read the instrument before the number. In an exam stem the regime is almost always named or strongly implied — controller and processor mean GDPR, provider and deployer mean the AI Act — so fix that first and the number becomes a lookup rather than a guess. Where an option names a number without an instrument, treat the omission as the trap it usually is.

Test yourself

5 questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.

Quick check: article numbers, Art. 22 and TDM1 / 5 · score 0

A non-EU provider of a high-risk AI system must appoint an authorised representative in the Union. Which article requires it?

Related: Which assessment, and who owes it · Roles, and how they change · GDPR vs EU AI Act · Cheat sheet

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →