Here's a whole article on the subject [1] and HN discussion thread [2] . Any machine learning application that utilizes automated decision making - which is the entire point of machine learning - is forbidden under the GDPR. This can be overcome with explicit consent for that specific application of ML, but getting that in most circumstances will be a low percentage shot.
There are no additional risks imposed by GDPR; all of those risks already exist in other privacy directives.
Fines of up to 20 million EUR are a significant and new risk.
[1] https://www.oreilly.com/ideas/how-will-the-gdpr-impact-machi...
From https://www.oreilly.com/ideas/how-will-the-gdpr-impact-machi...