Your DPO masters GDPR. The EU AI Act is a different law, with different obligations, different risk logic, and different consequences. Here are the 3 blind spots that internal compliance teams consistently miss — and why it's structural, not a failure of your DPO.
This seems obvious. It isn't. In practice, most organisations treat AI Act compliance as an extension of their GDPR programme. They ask their DPO to "handle it." The DPO adds a few AI-related items to their data mapping. A checkbox is ticked. The board is reassured.
The problem: the AI Act has a fundamentally different logic. GDPR protects individuals from how their data is processed. The AI Act regulates what the AI system does — its design, its outputs, its technical architecture, and its governance. A system can be fully GDPR-compliant and massively non-compliant with the AI Act. These are orthogonal regimes.
Your DPO was trained for the left column. The right column requires a different skillset: model risk management, technical architecture review, operational controls. These are closer to what a Model Risk Management team or an AI Risk practice does. Not what a privacy lawyer does.
Your DPO is not wrong. The situation is structurally misaligned.
Most companies have never formally answered this question. They know they use AI. They don't know whether it's classified as high-risk under Article 6 and Annex III of the AI Act.
The question is not about the technology. It's about the use case. A standard LLM used to screen CVs is high-risk (Annex III §4 — employment). The same LLM used to write marketing copy is minimal risk. Same model. Different classification. Different obligations.
What your DPO typically does: treats the AI system as a "processing activity" under GDPR and adds it to the data register. Does not assess the Annex III classification.
What the AI Act requires: a documented classification decision, with legal reasoning, before the system is placed on the market or put into service (Art. 6 + Art. 11).
Article 14 of the AI Act requires that high-risk AI systems be designed to allow human operators to understand outputs, monitor performance, and override or interrupt the system when necessary. This is not a policy. It's a technical requirement.
In practice, most AI-driven HR and credit systems do not have meaningful override mechanisms. A recruiter can technically reject a candidate ranked high by the algorithm — but the system doesn't log that override, doesn't learn from it, and doesn't report on the override rate. Under Art. 14, that's non-compliant.
What your DPO typically does: writes a policy that says "humans review AI outputs." Ticks the transparency box.
What the AI Act requires: documented HITL (human-in-the-loop) mapping per use case, tested override capability, override rate tracked in post-market surveillance logs (Art. 72).
Article 10 of the AI Act imposes strict data governance obligations on high-risk systems: training datasets must be documented, biases identified, data quality controls in place, and the data governance practices described in the technical file.
For HR AI and credit AI — the two most common enterprise AI use cases in France and Europe — training data is rarely clean. CV screening models are often trained on historical hiring data that reflects past biases. Credit scoring models are trained on historical approval data that reflects socio-economic bias. Under Art. 10(2), this requires documented bias analysis and mitigation measures.
What your DPO typically does: ensures a lawful basis for processing the training data (GDPR Art. 6). Does not assess the bias documentation requirements of AI Act Art. 10(2).
What the AI Act requires: a data governance plan documenting training data origin, quality checks, bias analysis, and how the data was processed — all included in the technical file (Art. 11, Annex IV).
The dangerous outcome of this structural gap is not that companies are unaware of the AI Act. Most are. The dangerous outcome is that companies believe they are compliant — because their DPO has "handled it" — when their actual exposure under Articles 9–15 is material.
When the first enforcement actions arrive (the AI Office opened its first GPAI investigations in Q1 2026), the companies that will face the highest penalties are not the ones who ignored the law. They are the ones who misclassified their systems as lower risk and built an incomplete compliance programme on that misclassification.
| Scenario | Exposure | Typical miss |
|---|---|---|
| HR AI screening tool classified as "minimal risk" | Up to €15M or 3% turnover | Annex III §4 not reviewed |
| Credit scoring model without human override | Up to €15M or 3% turnover | Art. 14 treated as policy, not architecture |
| LLM deployed in health context, no technical file | Up to €15M or 3% turnover | Art. 11 / Annex IV never produced |
| GPAI model above 10²⁵ FLOPs, no adversarial testing | Up to €15M or 3% turnover | Art. 55 systemic risk obligations missed |
The solution is not to replace your DPO. It's to give them the right tool. A D7™ score covers the seven dimensions that the AI Act actually requires — including the three blind spots above. It tells you, in 48 hours, where your exposure is, how material it is, and what to fix first.
The D7™ Standard covers all seven dimensions — regulatory exposure including AI Act classification (D1), model risk management (D2), data governance (D3), AI governance and human oversight (D4). It bridges the gap between your GDPR programme and what the AI Act actually requires. Delivered in 48–72h on public data. +RGPD™ module available.
D7™ Standard: all seven dimensions, public data, structured report — defensible in M&A due diligence and RFP.
D7 Discovery™ screening also available · pricing on request.