Responsible AI Platform
All answers

Direct answer

How do the GDPR and the AI Act relate to each other?

You describe: Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet. Likely role: deployer (the organisation).

This applies now

Coming up

Both regimes apply side by side: the GDPR protects personal data, the AI Act regulates the system and its use, even without personal data. A DPIA does not replace a FRIA or vice versa, but they overlap; the Omnibus anchors that the FRIA may connect to the DPIA. Practically: reuse your GDPR processing register as the starting point for the AI register, but keep the assessments separately traceable.

Your first actions

  1. Perform a FRIA before deployment. Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.
  2. Classify the use case and document the outcome. Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
  3. Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.

Record this

  • FRIA report and notification
  • Article 6 and Annex III classification record
  • AI literacy measures record

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Execution

Carry out the FRIA in a structured way

A FRIA touches DPIA, register and human oversight. Embed AI runs the assessment together with your team and delivers the evidence file.

See the Embed AI approach