GDPR and the EU AI Act: what changes for a DPO in 2026

Direct answer: in 2026 the GDPR and the EU AI Act (Regulation (EU) 2024/1689) overlap whenever an AI system processes personal data: the AI Act regulates the system (risk management, data governance, human oversight, transparency) and the GDPR regulates the processing of personal data that system performs. The nearest key date is 2 August 2026, when the transparency obligations of Article 50 apply (artificialintelligenceact.eu). High-risk obligations for Annex III systems were originally set for the same date, but a political agreement (the “Digital Omnibus”) is expected to postpone them (to December 2027 for stand-alone Annex III systems), a change that still has to be formally adopted and published. For the DPO this means transparency arrives now, and high-risk should be watched closely because its date is in motion.

How do the GDPR and the AI Act overlap?

They overlap because they regulate different layers of the same fact: the GDPR protects the people whose data is processed; the AI Act regulates the AI system that does the processing. When an AI system handles personal data - and almost every high-risk one does - both regulations apply simultaneously and both must be met.

In practice, the split is this:

  • The AI Act imposes obligations on the system: risk classification, risk management, governance of training data, technical documentation, human oversight, robustness and, for certain systems, transparency towards the user.
  • The GDPR still governs the processing of personal data: lawful basis, minimisation, information to data subjects, rights (access, erasure, objection to automated decisions under Article 22) and, where there is high risk, a data protection impact assessment (DPIA).

The mistake to avoid is treating them as separate boxes. A single project may need both the AI Act assessment and the GDPR DPIA, and both feed on the same information about the system.

What is the obligations timeline that affects 2026?

The timeline relevant to 2026 has one firm date and one in motion. It is worth telling them apart, because putting a wrong date in a compliance calendar is exactly the kind of error that damages a DPO’s credibility.

  • 2 August 2026 (firm): Article 50 transparency obligations. From that date, systems within the scope of Article 50 must inform users that they are interacting with AI and mark generated or manipulated content (text, image, audio, video) in machine-readable format. It applies regardless of when the system was placed on the market, with a transition until 2 December 2026 for certain generative systems already on the market (Article 50(2)). Source: Article 50, artificialintelligenceact.eu.
  • High risk (Annex III) - date in motion. The original date for the obligations of stand-alone high-risk Annex III systems was also 2 August 2026. However, the political agreement known as the “Digital Omnibus” is expected to postpone that application (to 2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for AI embedded in regulated products under Annex I). This change will only take effect once formally adopted and published in the Official Journal; until then, the exact date must be confirmed before committing it to a plan. [VERIFY the final adoption status of the Digital Omnibus before fixing the high-risk date]

The takeaway for the DPO: transparency is a 2026 obligation to prepare for now; high risk is something to actively monitor, because its calendar depends on a text still going through the legislative process.

How does the DPO’s role change?

The DPO’s role expands in practice, even though the AI Act does not name them as responsible for its compliance. The AI Act allocates responsibilities between providers and deployers and creates governance roles, but in any organisation that already has a DPO, that person best understands the system’s data processing and therefore ends up central to AI governance.

In practice, the DPO increasingly has to:

  • Identify which of the organisation’s (or client’s) AI systems process personal data and under which lawful basis.
  • Ensure that GDPR DPIAs cover the specific risks of the AI system (bias, automated decisions, training data).
  • Coordinate with whoever runs the AI Act assessment so that both documents are consistent.
  • Safeguard data-subject rights over the system: information, objection to automated decisions (Article 22 GDPR), erasure.

It is not that the DPO “inherits” the AI Act; it is that the overlap makes it impossible to separate data protection from AI governance.

What changes in day-to-day practice?

What changes in practice are mainly DPIAs and the documentation of lawful bases. Two concrete shifts:

  • DPIAs on AI systems. When a client deploys an AI system that processes personal data with a likely high risk, the DPIA stops being a formality and has to address the system’s own risks: quality and representativeness of training data, the possibility of automated decisions with legal effects, explainability and effective human oversight.
  • Lawful bases under pressure. Training or fine-tuning a model with personal data requires pinning down the legal basis (legitimate interest with its balancing test, or whichever applies) and documenting purpose compatibility if the data was collected for something else. This is where the overlap with the AI Act shows: the same decision you justify in the GDPR DPIA underpins the AI Act’s data governance.

Which 2025 EDPB guidelines should be on your radar?

The most relevant 2025 EDPB guidelines for this overlap are three, all verifiable on the EDPB’s official site. The detail to watch is their status: several were adopted as a version for public consultation, and the final criterion may change when the final version is published.

  • Guidelines 01/2025 on pseudonymisation. Adopted on 16 January 2025 and open for public consultation until 28 February 2025; they clarify what counts as pseudonymisation and when pseudonymised data is still personal data. Relevant for healthcare, research, banking/insurance and HR, and for any DPIA that presents pseudonymisation as its main safeguard. Status of the final version: [VERIFY whether the final version has been adopted]. Source: EDPB, Guidelines 01/2025 (PDF).
  • Guidelines 02/2025 on processing personal data through blockchain technologies. Adopted in April 2025, with public consultation until 9 June 2025. The central recommendation is not to store personal data directly on a blockchain, because its immutability conflicts with the rights to rectification and erasure (Articles 16 and 17) and with storage limitation; where unavoidable, use off-chain storage, encryption or hashing with a secret salt. Relevant for fintech, crypto/Web3 and traceability. Status of the final version: [VERIFY]. Source: EDPB, Guidelines 02/2025 (PDF).
  • Guidelines 3/2025 on the interplay between the DSA and the GDPR. The first on how the Digital Services Act and the GDPR fit together: recommender systems that must respect purpose limitation, a ban on profiling-based advertising targeted at minors and data minimisation in age verification. Relevant for platforms, marketplaces and ecommerce with recommenders or audiences that include minors. Status of the final version: [VERIFY]. Source: EDPB, Guidelines 3/2025 (PDF).

How do I know when an EDPB or AI Act development changes a specific client’s lawful basis?

You know by cross-referencing each development against each client’s processing profile, not by reading the whole newsletter. A pseudonymisation guideline only “changes something” for the client that relies on pseudonymisation as a security measure; a blockchain one, for the client designing an immutable architecture with personal data; an AI Act date, for the client deploying a high-risk system.

The practical method is:

  1. Tag, for each client, which processing operations and technologies they use (pseudonymisation, blockchain, recommenders, high-risk AI systems) and under which lawful basis.
  2. When the EDPB adopts a final version or the AI Act moves a date, identify which profiles are affected.
  3. Record the date you reviewed it and what you decided, so there is an audit trail for the file.

That is what Vigía DPO automates: you tag in your client book the clients each EDPB criterion or AI Act milestone affects, and we alert you if it changes, with the official source linked and ready for your file.

Frequently asked questions

How do the GDPR and the EU AI Act overlap in a DPO’s work?

The AI Act regulates the AI system (risk management, training data, human oversight, transparency), while the GDPR regulates the processing of personal data that system performs. When an AI system processes personal data, both apply at once: the DPO remains the reference figure for data protection and must assess DPIAs and the lawful bases for processing, now including AI systems.

When do the EU AI Act obligations take effect in 2026?

From 2 August 2026, the transparency obligations of Article 50 apply (informing people they are interacting with AI and marking AI-generated content). High-risk obligations for Annex III systems were originally set for the same date, but a political agreement (the “Digital Omnibus”) is expected to postpone them; confirm the final adoption status before fixing a date in a compliance calendar.

Is the DPO responsible for AI Act compliance?

Not automatically. The AI Act does not designate the DPO as responsible for its compliance, but where the AI system processes personal data the DPO keeps their GDPR functions and, in practice, becomes a central piece of AI governance: reviewing DPIAs, lawful bases, data minimisation and data-subject rights over the system.

Which 2025 EDPB guidelines should a DPO know?

The most relevant are Guidelines 01/2025 on pseudonymisation, Guidelines 02/2025 on processing personal data through blockchain technologies, and Guidelines 3/2025 on the interplay between the DSA and the GDPR. They set criteria on security measures, immutable architectures and online platforms, and are worth cross-referencing against the clients they affect.