{"answer_id":"praxikon:eu:ai-act:answer:avg-en-ai-act","canonical_page":"https://www.praxikon.com/en/antwoord/avg-en-ai-act","query":"How do the GDPR and the AI Act relate to each other?","lang":"en","view":"full","mode":"scenario","question":"How do the GDPR and the AI Act relate to each other?","situation":"Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet.","likely_role":"Deployer (the organisation)","note":"Both regimes apply side by side: the GDPR protects personal data, the AI Act regulates the system and its use, even without personal data. A DPIA does not replace a FRIA or vice versa, but they overlap; the Omnibus anchors that the FRIA may connect to the DPIA. Practically: reuse your GDPR processing register as the starting point for the AI register, but keep the assessments separately traceable.","matched_terms":[],"dataset":{"id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","version":"2.2.0","schema_version":"1.5.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","last_reviewed_at":"2026-08-08T00:00:00.000Z","licence":"https://www.praxikon.com/nl/legal/terms","canonical_url":"https://www.praxikon.com/api/v1/entities"},"obligations":[{"slug":"article-27-fria","label":"Article 27: FRIA","summary":"Fundamental rights impact assessment before deploying certain high-risk AI systems.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-27-fria","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended application schedule and Article 27 DPIA cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment on DPIA inclusion or cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}]},{"slug":"article-26-deployer-obligations","label":"Article 26: obligations of deployers of high-risk AI systems","summary":"Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 26 imposes twelve paragraphs on deployers of high-risk AI systems. Paragraph 1 requires appropriate technical and organisational measures to ensure use in accordance with the accompanying instructions for use. Paragraph 2 requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 3 leaves other obligations and the freedom to organise one's own resources unaffected. Paragraph 4 requires, to the extent the deployer exercises control over the input data, that such data is relevant and sufficiently representative in view of the intended purpose. Paragraph 5 requires monitoring on the basis of the instructions for use and informing the provider in accordance with Article 72; where there is reason to consider that use may result in a risk within the meaning of Article 79(1), the deployer shall without undue delay inform the provider or distributor and the relevant market surveillance authority and suspend use, and upon identifying a serious incident shall immediately inform first the provider and then the importer or distributor and the market surveillance authorities. Paragraph 6 requires keeping the automatically generated logs under the deployer's control for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise. Paragraph 7 requires deployers who are employers to inform workers' representatives and the affected workers, before putting into service or using the system at the workplace, that they will be subject to its use. Paragraph 8 imposes the registration obligations of Article 49 on public authorities and Union institutions, bodies, offices and agencies and prohibits use of a system not registered in the EU database referred to in Article 71. Paragraph 9 links the information provided under Article 13 to the data protection impact assessment under Article 35 of Regulation (EU) 2016/679. Paragraph 10 sets additional conditions for post-remote biometric identification in law enforcement. Paragraph 11 opens with the words without prejudice to Article 50 of this Regulation and requires deployers of Annex III systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system; for high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 applies. The transparency obligations of Article 50 have applied since 2 August 2026 and are separate from the date on which paragraph 11 starts to apply. Paragraph 12 requires cooperation with the competent authorities.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"The 2 December 2027 date invites postponement, but two elements are preparation work today. Paragraph 7 requires you to inform workers' representatives and the affected workers before the system is put into service at the workplace, and that information is provided, where applicable, in line with existing rules and practice on informing workers. That touches employee participation, and such a process takes months rather than weeks in practice, so a system that must go live in 2027 is discussed in 2026. Paragraph 2 also connects to the human oversight that Article 14 imposes on system design: you must designate natural persons with competence, training, authority and support. That is emphatically not the same as the measures obligation in Article 4. Article 4 requires measures supporting AI literacy and does not require you to guarantee a particular level for individuals; Article 26(2) requires identifiable overseers with a mandate. Conflating the two leaves you believing a generic e-learning is enough while still having no overseer with room to decide. A third underestimated element is paragraph 11: informing the people about whom an Annex III system makes or helps make decisions is visible customer or candidate communication that you have to design across your own organisation.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Draw up now a list of the systems likely to qualify as high-risk from 2 December 2027 and add three columns: who exercises human oversight and with what mandate, when you will inform the works council and the affected workers, and how the persons concerned will receive the notice under paragraph 11. Plan the employee participation process a year ahead.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-4-ai-literacy","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null},{"kind":"recommended_action","statement":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}]},{"slug":"annex-iii-high-risk","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-10-data-governance","label":"Article 10: data and data governance","summary":"Quality and governance requirements for training, validation and test data of high-risk AI.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-10-data-governance","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 10 requires datasets appropriate to the intended purpose, with governance over origin and composition, attention to representativeness, errors and completeness, and examination of possible bias with appropriate measures.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113 application dates","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Today’s dataset choices determine whether compliance is feasible later: data bought or collected today without provenance records cannot be repaired in 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Record origin and assumptions per dataset and include data quality as a requirement in every AI or data procurement contract.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 10(1)-(6)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]}],"conditional":[{"slug":"article-61-informed-consent","id":"praxikon:eu:ai-act:obligation:article-61-informed-consent","label":"Article 61: informed consent of test subjects for testing in real world conditions","status":"possibly_applies","source_locator":"Article 60(4), point (i), with Article 61(1)","addressee":"reader","human_page":"https://www.praxikon.com/en/verplichtingen/article-61-informed-consent"}],"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":"EU Artificial Intelligence Act 2024/1689","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":"Digital Omnibus on AI 2026/1744","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":"AI literacy questions and answers","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":"Draft guidelines on the classification of high-risk AI systems","publisher":"European Commission (AI Office)","canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":"CEN-CENELEC JTC 21: European standards under standardisation request M/613","publisher":"CEN-CENELEC JTC 21","canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:iso-iec-jtc1-sc42","title":"ISO/IEC JTC 1/SC 42: international standards for artificial intelligence","publisher":"ISO/IEC JTC 1/SC 42","canonical_url":"https://www.iso.org/committee/6794475.html","eli":null,"source_version":"catalogue-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z"}],"first_actions":[{"label":"Map the affected groups and their specific risks of harm","summary":"Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13."},{"label":"Assign human oversight and give those people a mandate","summary":"Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside."},{"label":"Take role- and context-specific AI literacy measures","summary":"Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate."}],"evidence":[{"label":"Notification to the market surveillance authority with the completed template","summary":"The sent notification through which you report the assessment results to the market surveillance authority, with the completed template attached, plus date of dispatch and acknowledgement of receipt.","url":null},{"label":"Deployment dossier: logs, worker information and information to affected persons","summary":"The dossier that shows you retain the logs, that you informed workers and their representatives in time, and that the people about whom decisions are made are aware of it.","url":null},{"label":"AI literacy measures record","summary":"Versioned record of roles, context, measures, participation or instruction and review moments.","url":null}],"guidance":[{"label":"No mandatory course format, no certificate, no exam and no AI officer","statement":"The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)"},{"label":"Article 4 reaches beyond your own staff, and the national supervisor enforces it","statement":"The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)"},{"label":"Article 6 has two separate routes to high-risk","statement":"The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)"},{"label":"Broadly positioned and general purpose AI systems: a disclaimer is not enough","statement":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)"}],"examples":[{"label":"Awarding social assistance in a municipality: the FRIA and the notification","situation":"A municipality wants to deploy an AI system that sorts applications for social assistance benefits and indicates which files merit extra scrutiny before a case worker decides. The application is already listed in the public algorithm register. The question is what has to be in place before the first citizen passes through this system.","outcome":"Article 27(1) requires deployers which are bodies governed by public law, or private entities providing public services, to perform an assessment of the impact on fundamental rights that the use of a high-risk AI system referred to in Article 6(2) may produce, prior to deploying it, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment covers, among other elements, the categories of natural persons and groups likely to be affected, the specific risks of harm to those categories, the implementation of human oversight measures, and the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(3) provides that once the assessment has been performed, the deployer shall notify the market surveillance authority of its results and submit the filled-out template referred to in paragraph 5 as part of that notification, and that in the case referred to in Article 46(1) deployers may be exempt from that obligation to notify. Article 27(5) provides that the AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.","lesson":"We read Article 27 as making the municipality the most obvious deployer here, and as requiring the assessment to be complete before the first application runs through the system, not as an account rendered afterwards. That duty does depend first on whether this system is high-risk at all: does it help decide entitlement to social assistance, or does it stay within a preparatory or narrowly procedural task under Article 6(3), which closes its own exception again once the system profiles citizens? Answer that question before you start on paragraph 1. An entry in the public algorithm register is on our reading something different from the assessment under paragraph 1, and it does not replace notifying the market surveillance authority of the results. In practice it pays to record the citizen's complaint route and the case worker's room to depart from the signal in the same file, because paragraph 1 asks for precisely those two elements.","source_locator":"Article 27(1), (3) and (5)","provenance":"editorial"},{"label":"Recidivism scoring in police work: when the assessment must be redone","situation":"A police service deploys an AI system that estimates the recidivism risk of a suspect, as an aid to the judgements later made by the prosecution service and the court. The model is subsequently retrained on newer investigative data and use is extended to a second region. The question is whether the assessment made for first use remains adequate.","outcome":"Article 27(1) requires deployers which are bodies governed by public law to perform, prior to deploying a high-risk AI system referred to in Article 6(2), an assessment of the impact on fundamental rights that its use may produce, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the processes in which the system will be used, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm taking into account the information given by the provider pursuant to Article 13, of the implementation of human oversight measures according to the instructions for use, and of the measures to be taken if those risks materialise. Article 27(2) provides that the obligation applies to the first use, that previously conducted impact assessments or existing assessments carried out by the provider may be relied on in similar cases, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(3) provides that the results are notified to the market surveillance authority together with the filled-out template, and that in the case referred to in Article 46(1) an exemption from that notification duty may apply.","lesson":"We read Article 27 as covering a police service as a body governed by public law under paragraph 1, and as an assessment that does not stop at first use: retraining on newer investigative data or extending use to a second region touches the elements of paragraph 1 and, on our reading, calls for updating the record. That retraining also raises a question Article 27 itself does not answer, namely whether the change goes far enough to count as a substantial modification, which would make you a provider in your own right under Article 25. Bear in mind as well that the exception in paragraph 3 concerns, on our reading, the notification and not the assessment itself. Finally, start that assessment only after establishing that the deployment as such is permitted, because Article 5 rules out certain predictive applications in criminal investigation.","source_locator":"Article 27(1)-(3)","provenance":"editorial"},{"label":"Selection at student admission: a DPIA is not yet a FRIA","situation":"A university of applied sciences has an AI system rank applications for a vocational programme, using the exam results of earlier students to calibrate that ranking. A data protection impact assessment already exists for this processing. The question the school asks is whether that also covers the fundamental rights side of admission.","outcome":"Article 27(1) provides that deployers which are bodies governed by public law, or private entities providing public services, and deployers of high-risk AI systems referred to in points 5(b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the deployer's processes in which the system will be used in line with its intended purpose, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm to those categories, of the implementation of human oversight measures, and of the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(2) provides that the obligation applies to the first use, that the deployer may in similar cases rely on previously conducted impact assessments or existing assessments carried out by the provider, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(4) provides that where an obligation under this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the assessment under paragraph 1 complements that data protection impact assessment.","lesson":"We read Article 27 as placing the education institution that runs this selection itself in the deployer role, but that alone does not settle the duty. Paragraph 1 names bodies governed by public law and private entities providing public services, and whether a state-funded or a private university of applied sciences answers to either description is the question you have to settle first. If it does, an existing data protection impact assessment is on our reading the starting point rather than the last word: paragraph 4 has the fundamental rights assessment sit alongside it, and since Regulation (EU) 2026/1744 that assessment may incorporate or cross-refer to relevant parts of it, so the real question is which elements of paragraph 1 are still missing. For you that means recording which groups of students may be affected, how the admissions committee or the teacher can correct an outcome, and where a rejected applicant can lodge a complaint. If the selection rule or the assessment component underpinning the ranking changes, that is on our reading the moment to update the record, rather than the start of the next academic year.","source_locator":"Article 27(1), (2) and (4)","provenance":"editorial"},{"label":"Health insurer using AI for risk assessment: public or private makes no difference","situation":"A health insurer uses AI for risk assessment and pricing of health and life insurance. The question is whether this falls under point 5(c) of Annex III, and with that whether the Article 27 FRIA duty comes into play.","outcome":"The Commission draft guidelines of 19 May 2026 state that the health and life insurance in point 5(c) may be offered on a private or a public basis: a health insurer governed by public law also falls within it, so long as the system is intended for risk assessment or pricing with regard to natural persons. Privately serviced health insurance counts as an essential private service, even in a Member State with a public healthcare system. Unlike point 5(b), point 5(c) provides no exception for fraud detection. The document is a consultation version: non-binding and not yet final.","lesson":"For the FRIA question point 5(c) counts twice: it makes the system high-risk and it makes you, as deployer, one of the parties Article 27 names. A public-law form or a public healthcare system in your Member State changes nothing there. Do not count on the fraud-detection exception from point 5(b) either: it does not apply here, and a fraud feature alongside risk assessment does not take the system out.","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (319) to (321)","provenance":"official"}],"standards":[{"label":"ISO/IEC 5259 series: data quality for analytics and machine learning","summary":"The five-part international series on data quality, in practice the most usable structure for the Article 10 data governance dossier.","statement":"The ISO/IEC 5259 series (Artificial intelligence: Data quality for analytics and machine learning) comprises five parts: part 1 (overview, terminology and examples), part 2 (data quality measures), part 3 (data quality management requirements and guidelines) and part 4 (data quality process framework), all published in 2024, plus part 5 (data quality governance framework), published in February 2025. CEN-CENELEC has adopted parts as European standards, including EN ISO/IEC 5259-4:2025 and EN ISO/IEC 5259-3:2025. No part is cited in the Official Journal, so no presumption of conformity under Article 40 arises. The deliverable intended to do so for Article 10 is prEN 18284."},{"label":"prEN 18284: quality and governance of datasets in AI","summary":"The draft European standard operationalising the Article 10 data governance requirements for training, validation and testing data.","statement":"prEN 18284 (Artificial intelligence: Quality and governance of datasets in AI) is the JTC 21 deliverable under M/613 for Article 10 of the AI Act, which sets requirements for the training, validation and testing datasets of high-risk AI systems. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal."}],"definitions":[],"answer_page":"https://www.praxikon.com/en/antwoord/avg-en-ai-act","follow_up_questions":[{"question":"We are a public-sector organisation using AI. What needs to be in place?","url":"https://www.praxikon.com/en/antwoord/overheid-ai-gebruik"},{"question":"Do we need to perform a FRIA and how do we approach it?","url":"https://www.praxikon.com/en/antwoord/fria-uitvoeren"},{"question":"We use AI for creditworthiness or insurance pricing. What applies?","url":"https://www.praxikon.com/en/antwoord/kredietscore-verzekering"}],"disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}