Praxikon
All answers
Depth
The conclusion and your first steps

Direct answer

How do the GDPR and the AI Act relate to each other?

You describe: Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet. Likely role: deployer (the organisation).

This applies now

Coming up

Both regimes apply side by side: the GDPR protects personal data, the AI Act regulates the system and its use, even without personal data. A DPIA does not replace a FRIA or vice versa, but they overlap; the Omnibus anchors that the FRIA may connect to the DPIA. Practically: reuse your GDPR processing register as the starting point for the AI register, but keep the assessments separately traceable.

Your first actions

  1. Map the affected groups and their specific risks of harm. Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.
  2. Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
  3. Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Execution

Carry out the FRIA in a structured way

A FRIA touches DPIA, register and human oversight. Embed AI runs the assessment together with your team and delivers the evidence file.

See the Embed AI approach
Does this answer your question?