Skip to main content
Praxikon

Free template · Word · English and Dutch

AI board report template: quarterly management briefing on the EU AI Act and GDPR

A quarterly AI and privacy board report is a fixed one-page briefing in which the board sees each quarter which AI the organisation uses, which EU AI Act and GDPR obligations apply now, where the risks lie and which decisions are needed. It makes the obligations of provider, deployer and controller governable at board level.

Last checked against the law
Editor
, jurist, privacy and AI
Version and template ID
2.0 · praxikon:template:management-briefing
Legal basis
Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; Regulation (EU) 2016/679 (GDPR)

Who is this template for?

  • Executive, board of directors or supervisory boardTakes the decisions requested (chapter 3) and accepts residual risks (chapter 4); as controller, the organisation must be able to demonstrate compliance with the GDPR (Article 5(2) and Article 24(1) GDPR)
  • AI governance owner or compliance officerPrepares the report from the AI register and records the role for each application: provider or deployer (Article 3(3) and (4) and Article 25(1) AI Act)
  • Data protection officer (DPO)Reports directly to the highest management level (Article 38(3) GDPR) and advises on the DPIA (Article 35(2) GDPR); this report supplements that reporting
  • HR and employee representativesMeasures for AI literacy (Article 4), informing workers about high-risk AI in the workplace (Article 26(7), from 2 December 2027) and any national rights of the works council, such as consent in the Netherlands (Article 27(1) WOR)
  • Procurement and contract managementData processing agreements (Article 28(3) GDPR) and the information you need from suppliers for Article 26 and Article 50

What is inside

  • How to use this template: six steps per quarter and a status legend in which green means ‘on schedule’, not a finding of compliance
  • Chapter 1: a dashboard with eleven fixed lines, from the AI register and prohibited practices to personal data breaches, supplier contracts and open decisions
  • Section 1.1: counting rules for each line, with role, article and source, so that you count the same way every quarter
  • Chapter 2: legal dates as of 6 October 2026, split into what already applies and what is coming, with the role for each obligation and the maximum fines in Article 99
  • Chapter 3: decisions requested, with options, a recommendation, a deadline and a table to record the outcome after the meeting
  • Chapter 4: a risk acceptance log, what the board cannot accept and a checklist before every acceptance
  • Chapter 5: a fully worked fictional example for the third quarter of 2026, with dashboard, legal dates, three decisions and three acceptances

How to use the template

  1. Record the counting rules in section 1.1 once, and collect the figures at the reference date from the AI register, the breach register, the incident overview, the DPIAs and the contracts.
  2. Fill in the dashboard and give each line a status; for amber and red, state the action, the owner and the date.
  3. Update the legal dates in chapter 2 and indicate for each date whether it applies to your organisation; add the national implementing rules of your Member State.
  4. Formulate no more than three decisions with options and a recommendation, and update the risk acceptance log.
  5. Send the report a few working days before the meeting and afterwards record the decisions with the date of the minutes.

Common mistakes

  • Reading green as ‘meets the law’. Green only means the organisation is on schedule according to its own plan.
  • Accepting a legal obligation as a risk. A prohibited practice (Article 5), a missing Article 50 disclosure, continuing where Article 26(5) requires suspension, or not notifying a notifiable personal data breach cannot be accepted by the board.
  • Counting differently every quarter, for example per licence instead of per application. Quarters then cannot be compared, and AI features that suppliers switch on through an update go unnoticed.
  • Reporting Article 50 as a future obligation. It has applied since 2 August 2026; only the machine-readable marking in paragraph 2 has a transitional period until 2 December 2026, for systems placed on the market before 2 August 2026.
  • Requiring a fundamental rights impact assessment for every high-risk application. From 2 December 2027, Article 27 only covers the deployers listed in Article 27(1), such as bodies governed by public law and deployers that assess creditworthiness.

When do you need legal advice?

  • The board wants to accept a risk that touches a legal limit. For example continuing to use a high-risk system despite signs of a risk (deployer, Article 26(5), for Annex III from 2 December 2027), or processing with a high residual risk after the DPIA (controller, Article 36 GDPR).
  • A supplier switches on an AI feature that assesses people. Such as a score for employee behaviour or a ranking of applicants. Annex III may then apply, and with your own name, a substantial modification (Article 3(23)) or a different purpose you may become the provider yourself (Article 25(1)).
  • A personal data breach or incident involves an AI application. Deadlines can then run in parallel: the supervisory authority within 72 hours (Article 33(1) GDPR) and, where the risk is high, the data subjects too (Article 34(1) GDPR), both as controller; and if it is also a serious incident with high-risk AI (Article 3(49)), the provider and the market surveillance authority (deployer, Article 26(5), for Annex III from 2 December 2027).

Frequently asked questions

Does the EU AI Act require a report to the board?

No. The AI Act places obligations on the organisation in its role, as provider or deployer, and does not prescribe board reporting. The GDPR does require the controller to be able to demonstrate compliance (Article 5(2) and Article 24(1) GDPR), and a DPO reports directly to the highest management level (Article 38(3) GDPR). A fixed quarterly report is a practical way to organise both.

Which EU AI Act obligations already apply (as of 6 October 2026)?

The prohibited practices (Article 5) and AI literacy (Article 4) have applied since 2 February 2025; since 27 July 2026, Article 4 is a duty to take measures that support AI literacy, without a guaranteed level per person. Obligations for providers of general-purpose AI models have applied since 2 August 2025, transparency (Article 50) since 2 August 2026. On 2 December 2026 new prohibitions follow (Article 5(1), points (ba) and (bb)) and the transitional period for Article 50(2) ends. High-risk rules follow on 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

Can the board accept an AI risk?

A residual risk after all measures, yes, if the board records it with an owner, conditions and a review date. An acceptance does not suspend any legal obligation. A prohibited practice, a missing Article 50 disclosure, continuing with a high-risk system where Article 26(5) requires suspension, processing without a lawful basis or not notifying a notifiable breach cannot be accepted.

What fines apply under the EU AI Act?

Article 99 sets maximums that Member States must lay down in their own rules: up to EUR 35 million or 7% of total worldwide annual turnover for a prohibited practice, up to EUR 15 million or 3% for most other obligations and up to EUR 7.5 million or 1% for incorrect information. Not every Member State has adopted these rules yet; the Netherlands, for example, had not done so by 6 October 2026. Under the GDPR, supervisory authorities can already impose fines (Article 83 GDPR).

Can I use this template outside the Netherlands?

Yes. The report follows the EU AI Act and the GDPR, which apply in every Member State. Supervision, penalties and employee participation are partly national, so the template refers to ‘your supervisory authority’ and ‘the works council or other employee representatives’. The worked example is a fictional Dutch company, which is why it mentions the Dutch Data Protection Authority and the Dutch Works Councils Act.

May I adapt the template and share it within my organisation?

Yes. You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place. The template is a tool, not legal advice for your situation.

Use and credit

You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.

How to cite this template: Source: Praxikon, AI board report template: quarterly management briefing on the EU AI Act and GDPR, version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/management-briefing

This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.

Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597