Why this is a buying question, not just a legal one
If you run a business in Slovenia, Croatia or the wider EU, "is this AI GDPR compliant" is one of the first questions your legal team, and increasingly your customers, will ask. Getting it wrong is expensive, and in regulated sectors like banking, insurance and health, it can end a deal before it starts.
The good news, from the regulators' own guidance, is that most AI can be used compliantly with the right safeguards. The work is in knowing which ones, and checking that your vendor actually meets them rather than just claiming "EU-based."
Data residency is not the same as data processing
This is the single most common mistake we see. A vendor says data is "stored in the EU," and everyone relaxes. But storage and processing are different things.
A concrete example from voice AI: you can keep every call recording in an EU data centre and still be non-compliant, because the moment a US-based transcription or AI service processes that audio during inference, personal data has left the EU. The recording sat in the EU. The processing did not.
So the question to ask a vendor is not "where is the data stored." It is "where is the data processed, end to end, including every model and API call in the pipeline."
Vandri's platform, vCore, is built EU-by-default: data stays in the EU and the processing stays in the EU too. That is a deliberate choice, not a marketing line.
The four things that make AI compliant
Based on current regulatory guidance, any AI system can be run compliantly if you cover these:
- Lawful basis and data minimisation. You need a clear legal reason to process the personal data, and you should feed the AI only the data it actually needs.
- EU processing and clear data agreements. Data processing agreements with every party in the chain, and processing kept in the EU wherever the data is personal.
- Transparency and security. People should know when they are dealing with AI and how their data is used, backed by real security controls, encryption, access control and logging.
- Governance where the AI Act applies. If your use case is classed as high-risk, there are extra duties (see below).
What the EU AI Act means in 2026
The EU AI Act adds a layer on top of GDPR. Full enforcement for high-risk AI systems began on 2 August 2026, covering categories such as hiring algorithms, credit scoring, biometric systems and emergency services. Penalties for non-compliance run up to 35 million euros or 7 percent of global annual revenue.
High-risk systems now require documented data governance, risk management maintained across the system's life, automatic logging with retention, and conformity assessments.
Most business assistants, RAG tools and customer-service voice agents are not high-risk. But the classification depends on the use case, not the technology, so it is worth checking early rather than assuming.
Where ISO 27001 fits
ISO 27001 is the international standard for information security management. It is not the same as GDPR, but it is fast becoming table stakes for selling to larger customers, especially in banking, health and insurance, where a large share of corporate RFPs in regulated sectors now require ISO 27001 or equivalent.
Following ISO 27001 principles (role-based access, audit logs, documented policies) means that when a customer's security questionnaire lands, you have real answers. Vandri builds to these principles across its systems.
A practical checklist before you deploy AI
Run any AI project, yours or a vendor's, through this:
- Is there a clear lawful basis for every category of personal data involved?
- Is the data processed in the EU at every step, including third-party models and APIs?
- Are there data processing agreements with every party in the chain?
- Are access control, encryption, audit logging and role-based access actually in place?
- Have you classified the use case against the AI Act (high-risk or not)?
- Can you show a security posture (ISO 27001 principles or certification) when a customer asks?
- Are people told when they are interacting with AI?
If you cannot answer one of these for a tool you are evaluating, that is the question to put to the vendor.
How Vandri approaches it
We build EU-by-default. Data stays in the EU, processing stays in the EU, and every system follows GDPR and ISO 27001 principles with role-based access and audit logs. When your legal or security team has questions, we would rather give them straight answers than a compliance badge that falls apart under a second question. See how this is built into our platform.
Talk it through
If you are weighing an AI project and compliance is a blocker, tell us the use case. We will tell you honestly where it sits, what safeguards it needs, and whether it is high-risk under the AI Act. Book a call or explore our solutions.
This article is general information, not legal advice. For a specific project, confirm with your data protection officer or legal counsel.