Direct answer
How do the GDPR and the AI Act relate to each other?
You describe: Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet. Likely role: deployer (the organisation).
This applies now
- Article 4: AI literacyApplicable
Coming up
- Article 27: FRIAfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
Both regimes apply side by side: the GDPR protects personal data, the AI Act regulates the system and its use, even without personal data. A DPIA does not replace a FRIA or vice versa, but they overlap; the Omnibus anchors that the FRIA may connect to the DPIA. Practically: reuse your GDPR processing register as the starting point for the AI register, but keep the assessments separately traceable.
Your first actions
- Perform a FRIA before deployment. Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.
- Classify the use case and document the outcome. Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Record this
- FRIA report and notification
- Article 6 and Annex III classification record
- AI literacy measures record
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationFollow-up questions
Execution
Carry out the FRIA in a structured way
A FRIA touches DPIA, register and human oversight. Embed AI runs the assessment together with your team and delivers the evidence file.
See the Embed AI approach