DPO · Compliance · Legal

EU AI Act 2026: what your DPO isn't telling you yet

Your DPO masters GDPR. The EU AI Act is a different law, with different obligations, different risk logic, and different consequences. Here are the 3 blind spots that internal compliance teams consistently miss — and why it's structural, not a failure of your DPO.

First: GDPR ≠ AI Act

This seems obvious. It isn't. In practice, most organisations treat AI Act compliance as an extension of their GDPR programme. They ask their DPO to "handle it." The DPO adds a few AI-related items to their data mapping. A checkbox is ticked. The board is reassured.

The problem: the AI Act has a fundamentally different logic. GDPR protects individuals from how their data is processed. The AI Act regulates what the AI system does — its design, its outputs, its technical architecture, and its governance. A system can be fully GDPR-compliant and massively non-compliant with the AI Act. These are orthogonal regimes.

GDPR — what it covers

  • Lawful basis for data processing
  • Data subject rights (access, erasure, portability)
  • Data minimisation and retention
  • DPIA for high-risk processing
  • DPO appointment
  • Cross-border transfers (Schrems II)

AI Act — what it covers

  • Risk classification of the AI system (Annex III)
  • Quality management system (Art. 9)
  • Training data governance (Art. 10)
  • Technical documentation (Art. 11, Annex IV)
  • Human oversight mechanisms (Art. 14)
  • Accuracy, robustness, cybersecurity (Art. 15)

Your DPO was trained for the left column. The right column requires a different skillset: model risk management, technical architecture review, operational controls. These are closer to what a Model Risk Management team or an AI Risk practice does. Not what a privacy lawyer does.

Your DPO is not wrong. The situation is structurally misaligned.

Blind spot 1: the classification question nobody asked

1

Is your AI system actually high-risk under Annex III?

Most companies have never formally answered this question. They know they use AI. They don't know whether it's classified as high-risk under Article 6 and Annex III of the AI Act.

The question is not about the technology. It's about the use case. A standard LLM used to screen CVs is high-risk (Annex III §4 — employment). The same LLM used to write marketing copy is minimal risk. Same model. Different classification. Different obligations.

What your DPO typically does: treats the AI system as a "processing activity" under GDPR and adds it to the data register. Does not assess the Annex III classification.

What the AI Act requires: a documented classification decision, with legal reasoning, before the system is placed on the market or put into service (Art. 6 + Art. 11).

Blind spot 2: Art. 14 human oversight — the gap nobody sees

2

Human oversight is not a checkbox — it's an architecture requirement

Article 14 of the AI Act requires that high-risk AI systems be designed to allow human operators to understand outputs, monitor performance, and override or interrupt the system when necessary. This is not a policy. It's a technical requirement.

In practice, most AI-driven HR and credit systems do not have meaningful override mechanisms. A recruiter can technically reject a candidate ranked high by the algorithm — but the system doesn't log that override, doesn't learn from it, and doesn't report on the override rate. Under Art. 14, that's non-compliant.

What your DPO typically does: writes a policy that says "humans review AI outputs." Ticks the transparency box.

What the AI Act requires: documented HITL (human-in-the-loop) mapping per use case, tested override capability, override rate tracked in post-market surveillance logs (Art. 72).

Blind spot 3: the training data problem in Annex III §4 and §5

3

Where did your training data come from?

Article 10 of the AI Act imposes strict data governance obligations on high-risk systems: training datasets must be documented, biases identified, data quality controls in place, and the data governance practices described in the technical file.

For HR AI and credit AI — the two most common enterprise AI use cases in France and Europe — training data is rarely clean. CV screening models are often trained on historical hiring data that reflects past biases. Credit scoring models are trained on historical approval data that reflects socio-economic bias. Under Art. 10(2), this requires documented bias analysis and mitigation measures.

What your DPO typically does: ensures a lawful basis for processing the training data (GDPR Art. 6). Does not assess the bias documentation requirements of AI Act Art. 10(2).

What the AI Act requires: a data governance plan documenting training data origin, quality checks, bias analysis, and how the data was processed — all included in the technical file (Art. 11, Annex IV).

The consequence: a false sense of compliance

The dangerous outcome of this structural gap is not that companies are unaware of the AI Act. Most are. The dangerous outcome is that companies believe they are compliant — because their DPO has "handled it" — when their actual exposure under Articles 9–15 is material.

When the first enforcement actions arrive (the AI Office opened its first GPAI investigations in Q1 2026), the companies that will face the highest penalties are not the ones who ignored the law. They are the ones who misclassified their systems as lower risk and built an incomplete compliance programme on that misclassification.

ScenarioExposureTypical miss
HR AI screening tool classified as "minimal risk"Up to €15M or 3% turnoverAnnex III §4 not reviewed
Credit scoring model without human overrideUp to €15M or 3% turnoverArt. 14 treated as policy, not architecture
LLM deployed in health context, no technical fileUp to €15M or 3% turnoverArt. 11 / Annex IV never produced
GPAI model above 10²⁵ FLOPs, no adversarial testingUp to €15M or 3% turnoverArt. 55 systemic risk obligations missed

What to do: the 48-hour answer

The solution is not to replace your DPO. It's to give them the right tool. A D7™ score covers the seven dimensions that the AI Act actually requires — including the three blind spots above. It tells you, in 48 hours, where your exposure is, how material it is, and what to fix first.

The D7™ Standard covers all seven dimensions — regulatory exposure including AI Act classification (D1), model risk management (D2), data governance (D3), AI governance and human oversight (D4). It bridges the gap between your GDPR programme and what the AI Act actually requires. Delivered in 48–72h on public data. +RGPD™ module available.

Close the GDPR–AI Act gap in 48–72 hours

D7™ Standard: all seven dimensions, public data, structured report — defensible in M&A due diligence and RFP.
D7 Discovery™ screening also available · pricing on request.

Request a D7™ score View all products