Data Act

Data Act applies to your AI system if it runs on a connected product, holds data generated by one, or is hosted on switchable cloud infrastructure. Most product teams haven’t mapped it.

EU compliance consultancy
EU compliance consultancy

How DSA works for AI products

The Data Act has applied since 12 September 2025, with access-by-design obligations for connected products following from 12 September 2026.

Data Act covers:

  • Manufacturers of connected products and providers of related services placed on the EU market
  • The data holders who control the data those products generate
  • The data recipients who receive it, providers of cloud and edge computing services used in the EU
  • Public sector bodies requesting data under exceptional need.

If your AI system runs on or inside a physical connected product sold into the EU, processes data generated by one, or is hosted on cloud or edge infrastructure offered to EU customers, Data Act reaches you — regardless of whether you are established in the EU and regardless of whether you think of yourself as a hardware company.

Data Act’s core demand is access: the user who generated the data, and in some cases a third party the user names, gets to have it, in a usable format, without the manufacturer or data holder standing in the way.

For AI systems this creates specific obligations around access-by-design in connected products, fair terms when AI training or inference data is shared with third parties, and switching rights for the cloud infrastructure AI workloads run on.

These obligations sit alongside and frequently interact with GDPR, where the data in question is personal, and with the EU AI Act’s own data governance requirements.

Data Act Compliance Assessment for Your AI System

Named lawyer · AI and connected-product specific · Delivered in 5 working days

Data Act and Your AI Product

EU compliance consultancy

Data Act organises its requirements across five areas. Each creates specific obligations for AI systems embedded in, trained on, or hosted alongside connected products and cloud infrastructure.

Access by design
Connected products and related services placed on the EU market from 12 September 2026 must be designed so that the data they generate is, by default, directly accessible to the user in an easy, secure, structured, and machine-readable format, including in real time where technically feasible.

An AI feature embedded in a connected product — a smart appliance, wearable, vehicle, or piece of industrial equipment — does not get a design exemption because the data pipeline runs through a model rather than a simple sensor log.

B2B data sharing and FRAND terms
Where a user requests it, the data holder must make the data generated by a connected product available to a third-party data recipient on fair, reasonable, and non-discriminatory terms.

Where the AI system is the data holder, or where an AI company is the requested third-party recipient, both sides of that exchange carry obligations — one to share without excessive friction, the other not to use the data to build a product that competes with the one it came from.

Unfair contract term protections
Contract terms imposed on SMEs and micro-enterprises that unilaterally restrict, override, or circumvent Data Act data-sharing rights are unenforceable.

Standard-form AI licensing and data-processing agreements written before September 2025 are a common source of now-unenforceable clauses, particularly around exclusivity over generated data.

Business-to-government data sharing
Public sector bodies and Union institutions can request data, including data processed or generated by an AI system, from private data holders in situations of exceptional need — public emergencies or where data is necessary to fulfil a specific legal mandate and cannot reasonably be obtained another way. Requests must be proportionate and the data holder is entitled to compensation in most cases.

Switching between data processing services
Providers of cloud and edge computing services used in the EU must remove technical, contractual, and financial barriers to switching, support standard export formats, and phase out switching charges entirely by January 2027.

Where your AI system’s training or inference infrastructure runs on a third-party cloud, or where you are the cloud provider hosting other companies’ AI workloads, this obligation reaches you directly.

Who Data Act Applies to

Data Act applies directly to manufacturers, data holders, data processing service providers, and — under specific data-sharing obligations — data recipients, regardless of where they are established.

AI companies frequently find themselves in scope of the Data Act through the connected product their AI feature sits inside, or through the cloud infrastructure their models run on, without having identified either as the trigger.

Entity typeIn scope?Key obligation
Manufacturer of an AI-powered connected product (wearable, vehicle, industrial equipment, smart appliance)Yes — as manufacturer/data holderAccess-by-design from 12 September 2026, user data access rights
Provider of a related service to a connected product (companion app, monitoring dashboard)Yes — as related service providerSame access-by-design and data access obligations as the manufacturer
Data holder processing and controlling connected-product data, including via AI analyticsYes — as data holderMust make data available to users and named third parties on FRAND terms
AI company receiving shared connected-product data as a third-party data recipientYes — as data recipientFRAND terms apply; cannot use the data to build a competing connected product
Cloud, edge, or GPU infrastructure provider hosting AI workloads for EU customersYes — as data processing service providerSwitching rights, interoperability, phased elimination of switching charges by January 2027
Public sector body requesting AI-derived data in a declared emergencyYes — under B2G provisionsRequest must be proportionate; compensation ordinarily due to the data holder
SME or micro-enterprise on the receiving end of a restrictive data clause in an AI licensing contractProtected — unfair term provisions applyRestrictive clauses that override Data Act rights are unenforceable
Company running AI purely on internally generated, non-connected-product data with no EU cloud customersNoDocument the determination

FRAND data sharing and the competing-product restriction: what AI companies miss

Data Act’s B2B sharing obligation looks like a straightforward access right until an AI company is the one requesting the data. Article 6(2)(e) prohibits a data recipient from using the data it receives to develop a product that competes with the connected product it came from, and from passing that data to a further third party for that purpose.

Training a model on Data-Act-sourced data without checking whether the output competes with the source product is not a theoretical risk — it is the single most common way AI companies end up on the wrong side of this regime.

Three things AI companies consistently misunderstand:

The competing-product restriction attaches to the data, not to the recipient’s intentions at the time of the request. An AI company that receives connected-product data for one stated purpose and later repurposes it for model training that produces a competing feature is exposed retroactively, not just at the point of misuse.

FRAND terms cut both ways. If your AI system is the data holder — because it processes and structures the data a connected product generates — you cannot use “commercially sensitive” as a blanket reason to refuse or degrade a legitimate third-party access request. The refusal has to survive scrutiny on its own terms.

Cloud switching obligations apply to the infrastructure your AI runs on even if you never touch a physical connected product. An AI company that trains or serves models exclusively on a single cloud provider, with contract terms that make migration commercially impossible, is the customer Data Act’s Chapter VI switching rules were written to protect — and by January 2027, provider-side switching charges disappear regardless of what the contract says.

What Data Act requires from AI products

These are the Data Act requirements that apply most directly to AI products embedded in connected products, trained on shared data, or hosted on EU cloud infrastructure.

Access-by-design assessment — a review of whether your AI-powered connected product or related service makes user-generated data directly, securely, and machine-readably accessible by default, ahead of the 12 September 2026 deadline

Data holder classification — a determination of whether your AI system’s role in processing connected-product data makes you a data holder with sharing obligations, rather than a passive processor

FRAND terms documentation — contractual and pricing terms for third-party data access requests that can withstand a fairness challenge, on both the sharing and receiving side

Competing-product use review — an assessment of whether any model trained on or informed by data received under a Data Act sharing request produces functionality that competes with the source connected product

Unfair contract term audit — a review of existing AI licensing and data-processing agreements with SME and micro-enterprise counterparties for clauses that Data Act now renders unenforceable

B2G request response protocol — a documented process for assessing and responding to public sector data requests under exceptional need, including entitlement to compensation

Cloud switching readiness — confirmation that your AI training and inference infrastructure contracts support data export, interoperability, and the phased removal of switching charges by January 2027

International access safeguards — technical and contractual measures preventing unlawful third-country government access to non-personal data held on your behalf by a cloud or edge provider.

One engagement. Every Data Act obligation mapped for your AI system.

A lawyer-built assessment of your AI system’s Data Act obligations — access-by-design review, data holder and data recipient classification, FRAND terms and competing-product exposure, unfair contract term audit, and cloud switching readiness — and a documented compliance record you and your counterparties can rely on.

Frequently Asked Questions About Data Act Compliance

What is Data Act and who does it apply to?

The Data Act is an EU regulation that has applied since 12 September 2025, with access-by-design obligations for connected products following from 12 September 2026.

Data Act applies to manufacturers of connected products and providers of related services placed on the EU market, data holders who control the data those products generate, data recipients, cloud and edge computing service providers offering services in the EU, and public sector bodies requesting data under exceptional need — regardless of where any of these parties are established.

Does the Data Act apply to AI companies that don’t make physical products?

Yes, in two common situations. First, if your AI system processes and controls data generated by someone else’s connected product, you are likely a data holder with sharing obligations.

Second, if you host or run AI training or inference workloads on cloud or edge infrastructure offered to EU customers, the Chapter VI switching rules apply to that infrastructure relationship directly, with no connected product involved at all.

Can an AI company be penalised for training on data it received under a Data Act sharing request?

It can be exposed to a claim, yes. Article 6(2)(e) prohibits using data received from a data holder to develop a product that competes with the connected product the data came from. Training a model on that data and shipping a feature that competes with the source product is the clearest way to trigger this restriction. The assessment has to happen before training starts, not after the model ships.

What is the difference between the Data Act and GDPR for AI systems?

GDPR governs personal data specifically — lawful basis, data subject rights, cross-border transfer restrictions. The Data Act governs a broader category of data generated by connected products, including non-personal and industrial data, and grants access and portability rights independent of GDPR.

\Where the same dataset is personal data generated by a connected product, both regimes apply, and Data Act itself provides that GDPR takes precedence where the two conflict.

What are the Data Act’s cloud switching requirements?

Providers of cloud, edge, and other data processing services must remove technical, contractual, and commercial barriers to switching providers, support functional equivalence and standard export formats, and give customers a maximum two-month exit window.

Switching charges are being phased down and must be eliminated entirely from January 2027. AI companies that train or serve models on a single cloud provider under long-term contracts should review those contracts against this timeline now, not at renewal.

What counts as a “connected product” under the Data Act?

A connected product is any physical item that obtains, generates, or collects data about its use or environment and can communicate that data via an electronic communications service, physical connection, or on-device access.

This is broad by design: smart appliances, wearables, connected vehicles, industrial machinery, and medical devices with embedded AI features all qualify.

Products that primarily store, process, or transmit data on behalf of a party other than the user, such as servers and routers, and products still in the prototype stage, are excluded from the data-sharing provisions.

Does the Data Act apply to non-EU AI companies?

Yes. The Data Act applies extraterritorially, in a similar way to GDPR. A non-EU manufacturer whose AI-powered connected product is placed on the EU market, or a non-EU cloud provider offering data processing services to EU customers, is in scope regardless of where the company is established.

What are the penalties for Data Act non-compliance?

The Data Act does not set a single EU-wide fine cap. Member states are required to lay down penalties that are effective, proportionate, and dissuasive, and for infringements involving personal data, member states may apply GDPR’s own fine levels. In practice, the more immediate commercial risk for AI companies is unenforceability of restrictive contract terms and exposure to third-party data-access and competing-product claims, both of which bite before any regulator does.

How do I start Data Act compliance for my AI product?

Four steps in order. First, determine whether your AI system is embedded in a connected product, processes data generated by one, or runs on cloud infrastructure offered to EU customers — any one of these triggers scope.

Second, if you hold or receive connected-product data, classify your role as data holder or data recipient and check any AI training use against the competing-product restriction.

Third, review your AI licensing and data-processing contracts with SME counterparties for now-unenforceable restrictive terms.

Fourth, if your AI infrastructure runs on a single cloud provider, check that contract against the 2027 switching-charge deadline.

A lawyer-built assessment covers all four steps and delivers a documented compliance position specific to your system and your data relationships.