Resources
Regulatory compliance
This pillar positions your AI uses against the EU AI Act and the GDPR: what is prohibited, what is high-risk, the obligations already in force and those coming next, and what you must be able to prove. It does not replace the advice of a lawyer.
General recommendations: the assessment selects those that match your situation and ranks them by priority.
AI Act mapping of your uses
The AI Act does not apply in the same way to every use: some are prohibited, a closed list (Annex III) is “high-risk”, systems that interact with people carry transparency obligations, and the rest is unrestricted. Everything starts with classifying each line of the register of uses. In the vast majority of SMEs, no use is high-risk; you still need to have checked it and be able to show it.
What we recommend
- Add two columns to the register of uses, “AI Act category” and “role (deployer / provider)”, and fill them in using the classification tree provided; mark doubtful cases “to be confirmed”.
- Have a lawyer confirm the classification of potentially high-risk uses and whether the Article 6(3) exemptions apply; keep the written analysis (it can be requested during an inspection).
- Repeat the classification for every new use and at least once a year: the Commission can amend Annex III and your uses change.
Obligations already in force
Three obligations already apply to every organisation that uses AI: not using prohibited practices (since February 2025), ensuring AI literacy among staff (Article 4, February 2025) and informing people who interact with an AI or receive generated content (Article 50, August 2026). Training and transparency are assessed in the Security pillar; this topic checks prohibited practices and the labelling of content.
What we recommend
- Check each use in the register against the list of prohibited practices provided; immediately stop any doubtful use pending legal advice. Document the check (date, person, conclusion).
- Define a rule for labelling generated content published externally (notice, metadata or watermark depending on the medium) and build it into the policy and publishing tools.
High-risk deployer obligations
If you use a high-risk system (for example a CV screening or credit scoring tool), Article 26 imposes a set of concrete obligations on you as a deployer: follow the provider's instructions, assign human oversight to competent people, ensure input data is relevant, monitor operation, keep logs, and inform employees and affected people. Deadline: 2 December 2027. Some organisations must also carry out a fundamental rights impact assessment (Article 27).
What we recommend
- Ask each provider of a high-risk system for its instructions for use and its declaration of conformity (or its timetable); file the answers with the register.
- Build the deployer compliance plan (Art. 26) using the checklist provided and set milestones up to 2 December 2027; it is a cross-functional project (HR, legal, IT) that benefits from being scoped by a specialist.
- Carry out the fundamental rights impact assessment (Art. 27) using the template provided, combining it with the GDPR DPIA when personal data is processed, and notify the market surveillance authority.
GDPR and AI
The GDPR applies in full as soon as an AI tool processes personal data: lawful basis and purpose, information to individuals, contract with the provider, impact assessment for high-risk processing, and safeguards around fully automated decisions. The CNIL has published practical guides that answer most questions.
What we recommend
- Complete the record of processing activities with each AI use that processes personal data (purpose, lawful basis, data categories, retention period, provider); the DPO or GDPR lead can do this from the register of AI uses.
- Update privacy notices (privacy policy, candidate notice, employee information) to mention the use of AI tools and the related rights, using the template paragraphs provided.
- Carry out (or update) the DPIA for high-risk AI uses following the CNIL method and PIA tool; for uses that are high-risk under the AI Act, combine it with the fundamental rights impact assessment.
- Have the DPO or a lawyer assess each AI-assisted decision under Article 22 and document the real human involvement (who, when, with what decision-making latitude).
Sector-specific obligations
In regulated sectors, other rules add to the AI Act and the GDPR: certified health data hosting and medical devices in healthcare, DORA and supervisory expectations in finance, algorithmic transparency and administrative law in the public sector, and NIS 2 for essential and important entities. This topic checks that you have identified them.
What we recommend
- Draw up the list of sector-specific rules that apply to your AI uses using the sector sheet provided and have it validated by your lawyer or supervisory authority; attach it to the register.
- Check the certified health data hosting (HDS) status of each AI tool host that processes health data and the CE marking of tools with a medical purpose; suspend non-compliant uses.
- Add AI providers to the DORA register of information and apply the third-party risk management process (due diligence, contractual clauses, exit strategy).
Documentation and evidence
A customer, an auditor, the data protection authority or the AI Act supervisory authority will not ask whether you are compliant, but for proof. This topic checks that the evidence exists, can be found and is up to date. It is also the foundation for a possible ISO/IEC 42001 certification, which is becoming a selling point in tenders.
What we recommend
- Create an “AI governance” evidence file (folder structure provided) and store what already exists in it now; each action in the plan adds its deliverable.
- Set up an annual AI governance review (register, policy, incidents, training, providers) presented to management and recorded in minutes.
- Carry out an ISO/IEC 42001 gap analysis based on this assessment to decide whether to pursue certification; if you already hold ISO 27001, much of the management system can be reused.
Frameworks
- AI Act
- GDPR
- AI Controls Matrix (CSA)
Disclaimer
The information in this pillar is provided for guidance only and does not constitute legal advice. How a use is classified under the AI Act and the GDPR must be confirmed by a lawyer or your DPO.
Where does your organisation stand?
The assessment evaluates these points for your organisation and ranks the actions by priority. Free, about 15 minutes, no account needed.