AI compliance for Claude: AI Act, GDPR, NIS2 matrix
AI compliance for Claude via API, Bedrock or Google Cloud: which AI Act, GDPR and NIS2 duty applies to whom, which evidence to keep, and the 24h and 72h deadlines.
TL;DR
AI compliance for Claude means three laws at once. GDPR applies as soon as prompts contain personal data: processor contract, records, DPIA, 72-hour breach notice. NIS2 applies only if your company is an essential or important entity: supplier risk, 24-hour early warning. The AI Act adds AI literacy, transparency and, from December 2027, high-risk deployer duties.
Which laws apply when your company runs Claude?
GDPR applies to every Claude workload that touches personal data, whichever route you use. The AI Act applies to every company using Claude professionally, but most duties depend on the use case. NIS2 applies only to medium-sized and larger companies in the sectors listed in its Annexes I and II, and then covers Claude as part of their IT.
The three laws answer different questions. GDPR asks what happens to personal data. The AI Act asks what the AI system is used for. NIS2 asks whether your services stay secure and available. A Claude-based support assistant at an energy supplier can trigger all three. The same assistant at a 40-person agency usually triggers GDPR and the AI Act basics only.
Scope checks we would run first:
| Law | Applies to you if | Typical Claude trigger |
|---|---|---|
| GDPR (Reg. 2016/679) | You process personal data in prompts, files, logs | Customer emails, HR documents, CRM data in a prompt |
| AI Act (Reg. 2024/1689, amended by 2026/1744) | You use an AI system under your authority in a professional context | Any internal assistant, coding tool, chatbot |
| NIS2 (Dir. 2022/2555) | You are an Annex I or II entity, medium-sized or larger (Art. 2(1)) | Claude in a service whose outage or leak hits your customers |
NIS2 is a directive, so national law decides the details. In Germany the implementation act entered into force on 6 December 2025, and the BSI estimates around 29,500 affected companies. Check your own Member State’s transposition before you assume the directive’s wording applies one to one.
The obligations matrix: who must do what, with which evidence
The matrix below maps each duty to the party that owes it and the document an auditor will ask for. For a company calling Claude through the Anthropic API, Amazon Bedrock or Google Cloud, almost every line is owed by you, not by the model or cloud provider. Providers deliver inputs to your evidence, not the evidence itself.
| Law and article | Who is obliged | What to do | Evidence to keep |
|---|---|---|---|
| GDPR Art. 28 | You (controller) and the provider (processor) | Sign a processor contract covering instructions, subprocessors, deletion, audits | Signed or incorporated DPA, subprocessor list, date of last review |
| GDPR Art. 30 | You | Record each Claude processing activity: purposes, data categories, recipients, transfers, erasure periods, security measures | Record of processing entry per use case |
| GDPR Art. 35 | You | DPIA before high-risk processing | DPIA document, DPO advice, sign-off |
| GDPR Art. 33 | You; the processor must tell you without undue delay (Art. 33(2)) | Notify the authority within 72 hours; document every breach | Breach register with facts, effects, remedial action |
| AI Act Art. 4 | You as deployer (and provider, if you built the system) | Take measures to support AI literacy of staff using Claude | Training plan per role, attendance |
| AI Act Art. 50 | Provider of the system, or you as deployer for deep fakes and published text | Tell people they talk to an AI; disclose AI text on matters of public interest unless editorially reviewed | Screenshot of the notice, editorial review rule |
| AI Act Art. 26 (high-risk only, from 2 Dec 2027) | You as deployer | Human oversight, monitoring, logs of at least six months, worker information | Oversight assignment, log retention setting, works council record |
| NIS2 Art. 20 | Your management body | Approve risk measures, oversee them, follow training | Board minutes, training certificates |
| NIS2 Art. 21(2)(d) | You | Supply chain security, including your direct service providers | Supplier risk assessment for Anthropic, AWS or Google |
| NIS2 Art. 23 | You | Report significant incidents: 24h, 72h, one month | Incident tickets with timestamps, submitted reports |
Two points the table hides. First, on the AI Act, building your own assistant on the Claude API makes you the provider of that AI system, which shifts Article 50(1) onto you. Our EU AI Act guide for LLM deployers covers the role question and the full timeline. Second, NIS2 Article 20(1) states that management bodies “can be held liable” for breaches of Article 21. That is a personal exposure no contract with a provider removes.
Fines differ by law. GDPR breaches of Articles 28 to 39 reach EUR 10 million or 2% of worldwide turnover (Art. 83(4)). Breaches of the AI Act deployer and transparency duties reach EUR 15 million or 3% (Art. 99(4)). NIS2 requires Member States to set maximum fines of at least EUR 10 million or 2% for essential entities and EUR 7 million or 1.4% for important ones (Art. 34(4) and (5)).
When does a Claude project need a DPIA?
A DPIA is required before processing that is “likely to result in a high risk”, and Article 35(3) names three cases. For Claude, the realistic triggers are automated evaluation of people with legal or similar effects, such as CV screening, and large-scale processing of health or other Article 9 data. Your authority’s published list adds more.
How we would run the screening for each new Claude use case:
- Describe the processing. Purpose, data categories, route (API, Bedrock, Google Cloud), region, retention. This is also your Article 30 entry.
- Check Article 35(3). Automated evaluation with legal effects (a), large-scale special category or criminal data (b), systematic monitoring of public areas (c).
- Check your authority’s list. Article 35(4) requires each supervisory authority to publish one. Employee monitoring and new technologies often appear there.
- Check the AI Act overlap. If the use case falls under Annex III, Article 26(9) tells deployers to use the provider’s Article 13 information for the DPIA. Since the Omnibus, Article 27(4) lets the fundamental rights impact assessment cross-reference the DPIA instead of duplicating it.
- Document the result, including a negative one. A short note explaining why no DPIA was needed is evidence too.
The records duty has an exemption that rarely helps here. Article 30(5) frees organisations with fewer than 250 employees, but not if the processing “is not occasional”. A Claude assistant used daily is, in our reading, not occasional. Keep the record regardless of headcount.
Which contract applies on each route, and what the providers retain, is covered in our Claude data privacy guide for businesses. Use it as the source for the “recipients” and “transfers” fields of the record.
Incident deadlines: 24, 48, 72 hours and 15 days
A leaked prompt log with customer data is a GDPR breach: 72 hours to the authority. If the same incident significantly disrupts an essential or important entity, NIS2 adds an early warning within 24 hours. Anthropic must tell API customers within 48 hours. Your clock starts when you become aware, not when the provider writes.
| Clock | Source | Trigger | Recipient |
|---|---|---|---|
| 24 hours | NIS2 Art. 23(4)(a) | Significant incident | CSIRT or competent authority |
| 48 hours | Anthropic DPA | Security breach at Anthropic | You, in writing |
| 72 hours | GDPR Art. 33(1) | Personal data breach, unless unlikely to result in a risk | Supervisory authority |
| 72 hours | NIS2 Art. 23(4)(b) | Same significant incident, initial assessment | CSIRT or competent authority |
| 15 days | AI Act Art. 73(2) | Serious incident with a high-risk AI system | Market surveillance authority (provider reports; deployer informs provider immediately, Art. 26(5)) |
| One month | NIS2 Art. 23(4)(d) | After the 72-hour notification | Final report |
The Anthropic DPA, effective 24 February 2025, commits Anthropic to notify “within 48 hours” after becoming aware of a security breach. For a NIS2 entity, that is longer than your 24-hour window. Plan for the case where your own monitoring sees the incident first. Google’s Cloud Data Processing Addendum promises notice “promptly and without undue delay”, with no fixed hour count. AWS documents its terms in the AWS DPA within the Service Terms.
In Germany, reports go through the BSI portal. The BSI reporting page confirms the 24-hour, 72-hour and one-month stages and states that the obligation applies from 6 December 2025.
Which evidence do Bedrock and Google Cloud give you?
Both clouds give you controls, not finished evidence. On Bedrock, model invocation logging is off by default, and AWS states that model providers cannot see your prompts. On Google Cloud, abuse-monitoring logs for some Claude models stay up to 30 days in your selected region. You must switch on, export and retain the rest yourself.
What the providers document, read on 1 October 2026:
- Bedrock, provider access. The data protection page says model providers “don’t have access to Amazon Bedrock logs or to customer prompts and completions”.
- Bedrock, retention modes. The data retention page defines modes from
nonetoaws_review. Claude Fable 5 and Fable 5.1 requireaws_review: inputs and outputs stay inside AWS for up to 30 days and may be reviewed by AWS, without being shared with Anthropic. With cross-region inference, retained data sits in the destination Region. - Bedrock, invocation logs. Invocation logging is disabled by default, writes only to S3 or CloudWatch Logs in the same account and Region, and does not capture calls on
bedrock-mantle. - Google Cloud, abuse monitoring. For models designated “Advanced AI” (Claude Mythos, Claude Fable), Google logs prompts and responses for up to 30 days in the customer’s region. For Fable 5 and Mythos 5 you must enable sharing that data with Anthropic.
- Google Cloud, contract. The same page states that Anthropic models there are governed by Anthropic’s Commercial Terms of Service. Add Anthropic to your record as a party, not only Google.
A minimal evidence pull on Bedrock, Frankfurt Region:
# Is invocation logging on, and where does it write?
aws bedrock get-model-invocation-logging-configuration --region eu-central-1
# Which retention mode applies to the account in this Region? (AWS documents the endpoint with us-east-1)
curl https://bedrock.eu-central-1.amazonaws.com/data-retention -H "Authorization: Bearer $AWS_BEARER_TOKEN_BEDROCK"
Store both outputs with a date in your compliance folder each quarter. Logs stay until you delete the configuration, so match an S3 lifecycle rule to the erasure period in your Article 30 record. Region choice, EU inference profiles and pricing are in our Claude on AWS Bedrock EU guide.
Run it yourself or outsource?
Running Claude compliance in-house means owning recurring work, not a one-time project: watching subprocessor notices, updating records for each new use case, keeping logs and retention aligned, and meeting a 24-hour reporting clock if NIS2 applies. Outsourcing operations can cover the routine. It never moves the legal duty off your company.
The recurring tasks, by role:
| Role | Recurring task | Rhythm (our estimate) |
|---|---|---|
| Data protection officer | Article 30 entries, DPIA screening per new use case, breach register | Per change, plus yearly review |
| Information security (ISMS) | Supplier risk for Anthropic, AWS or Google; incident runbook with 24h and 72h stages | Quarterly, plus drills |
| Platform engineering | Logging config, retention mode, log lifecycle, evidence export | Monthly check |
| Legal or procurement | Subprocessor notices within Anthropic’s 15-day objection window, contract renewals | On notice |
| Management | NIS2 approval and training (Art. 20) | Yearly |
When outsourcing makes sense: you run several Claude workloads, have no 24/7 security operations, and are a NIS2 entity that cannot staff a 24-hour clock. When it does not: one internal assistant with no personal data, or a regulated company with a working ISMS that already covers cloud suppliers. Then the overhead of another processor outweighs the gain.
What to demand from an operator for this topic:
- Breach notice shorter than your own clock. If you are a NIS2 entity, a 48-hour clause is too slow for you. Ask for notice in hours, inside your 24-hour window.
- A DPA under GDPR Article 28 with a current subprocessor list that names the model route (Anthropic API, Bedrock, Google Cloud) and Region.
- An access model you can audit. No standing access to prompts or logs, break-glass access logged and reported.
- Evidence delivery. Monthly export of logging and retention configuration, plus the operator’s own audit reports.
- NIS2 status of the operator. Managed service providers are themselves listed in NIS2 Annex I, point 9. Ask whether they are registered and how they report.
- Exit. Return of logs and configuration in a usable format, and deletion with a date. Anthropic’s own DPA sets 30 days after termination as a benchmark.
This article is editorial information, not legal advice.
FAQ
What can a compliance failure with Claude cost?
It depends on the law breached. GDPR breaches of processor, records, DPIA or breach-notification duties reach EUR 10 million or 2% of worldwide turnover. AI Act deployer and transparency breaches reach EUR 15 million or 3%. NIS2 fines for essential entities must go up to at least EUR 10 million or 2%.
DPIA vs fundamental rights impact assessment: which do we need?
A GDPR DPIA is needed for high-risk processing of personal data, whatever the AI use. The AI Act fundamental rights impact assessment under Article 27 applies only to certain deployers of high-risk systems, such as public bodies or credit scoring. Since the Omnibus, the second may cross-reference the first.
Does NIS2 apply to us because we use Claude?
No. Using Claude does not bring you into scope. NIS2 applies if your company is in a sector of Annex I or II and is at least medium-sized. If it does apply, Claude falls under your risk management like any other supplier, and incidents involving it can trigger the 24-hour early warning.
GDPR 72 hours vs NIS2 24 hours: which deadline wins?
Both run in parallel and go to different recipients. GDPR’s 72 hours go to the data protection authority for a personal data breach. NIS2’s 24-hour early warning and 72-hour notification go to the CSIRT or competent authority for a significant incident. One event can require all of them.
Does using Bedrock or Google Cloud make AWS or Google responsible for our compliance?
No. They are processors and must support you, for example by notifying breaches and keeping data in the Region you choose. Your company stays controller under GDPR, deployer under the AI Act and, where applicable, the NIS2 entity. Bedrock logging is even disabled by default.
Do companies under 250 employees need records for Claude?
Usually yes. The Article 30(5) exemption does not apply when processing is not occasional, is likely to result in a risk, or includes special category data. A Claude tool used every working day is, in our reading, not occasional, so we recommend keeping the record.
Sources
- EUR-Lex: Regulation (EU) 2016/679 (GDPR) (1 October 2026)
- EUR-Lex: Directive (EU) 2022/2555 (NIS2) (1 October 2026)
- EUR-Lex: Regulation (EU) 2024/1689 (AI Act) (1 October 2026)
- EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI) (1 October 2026)
- BSI: NIS-2 FAQ (1 October 2026)
- BSI: NIS-2 reporting obligation (1 October 2026)
- Anthropic: Data Processing Addendum (1 October 2026)
- Anthropic Privacy Center: processor or controller (1 October 2026)
- AWS: Amazon Bedrock data protection (1 October 2026)
- AWS: Amazon Bedrock data retention (1 October 2026)
- AWS: Bedrock model invocation logging (1 October 2026)
- Google Cloud: Abuse monitoring (1 October 2026)
- Google Cloud: Cloud Data Processing Addendum (1 October 2026)