Skip to main content
Praxikon

Knowledge base

Search the GDPR and the AI Act in context

One search across both laws: articles and recitals, rulings, guidelines and fines, obligations and evidence, and the themes where the GDPR and the AI Act meet.

Direct answer

How do the GDPR and the AI Act relate to each other?

This falls under Article 27: FRIA. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.

This could go the other way

  • In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.

First step: Map the affected groups and their specific risks of harm.

You describe: Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet. Likely role: deployer (the organisation).

The conclusion and your first steps

This applies now

Coming up

Depends on your situation

These provisions only apply once the stated fact is established. The locator says which provision settles it.

Both regimes apply side by side: the GDPR protects personal data, the AI Act regulates the system and its use, even without personal data. A DPIA does not replace a FRIA or vice versa, but they overlap; the Omnibus anchors that the FRIA may connect to the DPIA. Practically: reuse your GDPR processing register as the starting point for the AI register, but keep the assessments separately traceable.

Your first actions

  1. Map the affected groups and their specific risks of harm. Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.
  2. Assign human oversight and give those people a mandate. Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.
  3. Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Shareable version of this answer

Does this answer your question?

Results for “article 22 gdpr”

48 results

GDPR articles

12

GDPR legislation in motion

7

GDPR and AI Act side by side

3

AI Act obligations and evidence

2

GDPR guidelines

6

GDPR case law

11

GDPR recitals

1

GDPR enforcement and fines

6