The EU Data Act and EU AI Act are distinct regulations with different primary objectives — one governs data access and sharing, the other governs AI system development and deployment. But for companies building AI systems that process data from connected products, or deploying AI within IoT infrastructure, the two regulations interact in ways that create compound compliance obligations.
Where the Overlap Occurs
AI Systems Embedded in Connected Products
Many connected products include AI components:
- Industrial equipment with predictive maintenance AI
- Smart home devices with voice recognition or behaviour analysis
- Medical devices with AI-assisted diagnostics
- Vehicles with driver assistance or autonomous navigation
For these products:
- The Data Act governs data access rights — the operational data generated by the product's use must be accessible to users
- The AI Act governs the AI system embedded in the product — risk classification, technical documentation, transparency, and (for high-risk systems) conformity assessment
Compound obligation example: An AI-assisted industrial robot used in workplace safety contexts is a high-risk AI system under AI Act Annex III. It is also a connected product under the Data Act. The manufacturer must comply with AI Act high-risk requirements (technical documentation, conformity assessment, human oversight mechanisms) and Data Act data access requirements (making operational data accessible to the factory operator using the robot).
AI Systems That Consume IoT Data
AI systems that are trained on or operate using data from connected products face Data Act implications when:
- The AI system developer is a data recipient under a B2B data sharing arrangement
- The AI system is deployed as a "related service" to a connected product
Data recipient restrictions: If an AI company receives IoT data under a B2B data sharing arrangement, the Data Act prohibits using that data to develop a competing product. For AI companies, this creates a risk: an AI system trained on an IoT manufacturer's data could be seen as a competing product if it replicates the manufacturer's core functionality. Purpose limitations must be specific and respected.
GPAI Models and Training Data
General Purpose AI (GPAI) models under the AI Act have data governance obligations — providers must document their training data (Article 53). If training data includes IoT operational data obtained through Data Act B2B sharing arrangements:
- The data use must comply with the Data Act's purpose limitation
- Using IoT data to train a GPAI model that the data holder would view as competitive could breach Data Act restrictions
- Data Act purpose limitation and AI Act training data documentation create a documentation chain that must be consistent
Key Interactions in Detail
Transparency Obligations
AI Act Article 13 (high-risk AI): Deployers of high-risk AI must be provided with transparency information about the system's performance, limitations, and the data it was trained on.
Data Act user access rights: Users of connected products with embedded AI must be able to access the data generated by the product's use.
Where these overlap — an AI system embedded in a connected product — the manufacturer faces combined obligations: AI Act transparency documentation for the deployer plus Data Act data access for the user (who may be the same person or different people in a B2B context).
Technical Documentation Requirements
AI Act Annex IV: Technical documentation for high-risk AI systems must cover, among other things, the training data and data governance approach.
Data Act: If IoT data was used in training and was obtained through Data Act-governed B2B sharing, the purpose of use and basis for training must be documented in a way consistent with the data sharing arrangement.
For a manufacturer building AI into their connected product using operational data from customer use:
- Did the customer consent to their operational data being used for AI training?
- Does the Data Act B2B arrangement (if applicable) cover training use?
- Is the AI Act's training data documentation consistent with the Data Act's purpose limitation?
Cloud Providers Hosting Both AI Services and IoT Data
Cloud providers that host both AI inference services and IoT data storage face both regulatory frameworks simultaneously:
- Data Act cloud switching rules apply to the data storage service
- AI Act obligations (if any) apply to the AI inference service
- If the same data is used for both, purpose limitation questions under the Data Act arise
Practical Interaction Matrix
| Scenario | Data Act obligation | AI Act obligation |
|---|---|---|
| Connected product with embedded AI | Data access by default for product-generated data | AI Act risk classification; if high-risk, conformity assessment |
| AI deployed as related service to IoT product | Data sharing mechanism for users | Transparency to deployers (Article 13); high-risk obligations if applicable |
| AI trained on B2B IoT data | Purpose limitation compliance | Training data documentation (Annex IV, Article 53) |
| Cloud AI service | Cloud switching provisions | AI Act SaaS deployer obligations |
| GPAI model using IoT training data | Data sharing purpose must cover training use | Article 53 training data documentation |
Steps for Companies at the Intersection
-
Map your AI systems against both frameworks: Which AI systems are embedded in connected products? Which AI systems consume IoT data?
-
Assess AI Act risk classification: High-risk AI in connected products creates the most compound obligation — both full AI Act compliance and Data Act access rights.
-
Audit B2B data sharing agreements for training use: If you have obtained IoT data under commercial B2B arrangements, confirm whether the purpose limitation covers AI training. If not, renegotiate before building models on that data.
-
Align documentation: AI Act technical documentation and Data Act data sharing records must be consistent — they may both be reviewed by regulators or enterprise customers in due diligence.
-
Plan user-facing transparency: If an AI system's outputs are based on a user's IoT data, the user has a right to access that underlying data (Data Act) and, if automated decision-making is involved, Article 22 GDPR rights and AI Act deployer transparency rights.