If you already run a GDPR programme, you have done more of the EU AI Act than you think - and the parts you haven't done are not the ones people warn you about. This page maps the two regimes against each other, so you can work out what genuinely needs new work and what is your existing evidence under a different heading.
The single most useful reframing: GDPR asks whether you may process the data. The AI Act asks whether you may put the system on the market and how it must behave. They overlap heavily in evidence and almost not at all in trigger.
What your GDPR work already covers
| AI Act requirement | Your GDPR equivalent | Gap |
|---|---|---|
| Article 10 - data governance for training and test sets | Art 5 principles, records, minimisation, accuracy | Adds bias examination and representativeness of datasets |
| Article 13 - transparency to deployers | Arts 13-14 transparency to data subjects | Different audience: your customer, not the data subject |
| Article 14 - human oversight design | Art 22 safeguards on automated decisions | Broader - applies even where no Art 22 decision occurs |
| Article 12 - logging | Accountability, security logging | Prescribed retention and traceability for high-risk |
| Article 9 - risk management system | DPIA | Continuous over the lifecycle, not a point-in-time assessment |
| FRIA for public-sector deployers | DPIA | Genuinely additional, and wider than data protection |
| Article 4 - AI literacy | Staff training obligations | Trivially close - extend your existing programme |
A DPIA is not a FRIA and does not discharge Article 27, but the underlying evidence - data flows, necessity and proportionality reasoning, safeguards, consultation - carries across substantially.
Four places DPOs consistently get caught
1. Scope has nothing to do with personal data. An AI system can be high-risk while processing no personal data at all - critical infrastructure safety components, for instance. Conversely, a system awash in personal data can be minimal risk. If you triage AI Act exposure by "does it touch personal data", you will miss things in both directions.
2. Role is a separate analysis from controllership. Provider/deployer under the AI Act does not map onto controller/processor. You can be a processor under GDPR and the provider under the AI Act simultaneously. Working out one does not tell you the other. The AI Act test.
3. The live obligations are not the high-risk ones. Everyone is planning for December 2027. Meanwhile Article 50, Article 4 and Article 5 have been enforceable since 2 August 2026, and they apply to organisations with no high-risk systems whatsoever.
4. Article 5 is not a risk to be mitigated. Prohibited practices cannot be documented, consented or DPIA'd into acceptability. Emotion inference in the workplace is the one that turns up in ordinary organisations - usually bundled into an HR analytics or productivity tool nobody flagged.
A triage order that works
- Inventory. Your Article 30 records are the starting point, but they will miss AI systems that process no personal data. Ask teams what they've shipped, not what they've registered.
- Article 5 sweep first. Prohibitions are the only thing that can require ripping a feature out. Do this before tiering anything.
- Role per system - provider or deployer. This decides which obligation set can apply at all.
- Tier per system, then the Article 6(3) exemption for anything landing in Annex III. Profiling closes it absolutely.
- Close the live three - Articles 4, 5, 50 - this quarter.
- Only then scope Chapter III work, and only for systems that are genuinely high-risk.
The mistake worth avoiding is running the AI Act as a second, parallel programme. Most of the cost is duplication: two inventories, two risk assessments, two sets of records describing the same systems. One register with both lenses is materially cheaper to maintain and easier to defend.
Reglynn's reports flag GDPR overlaps explicitly for this reason - where one control satisfies both regimes, the report says so rather than presenting it as new work. The methodology is published, so you can check the reasoning rather than take the output on trust.
Triaging an AI inventory?
The free check runs role, GPAI status, tier and the Article 6(3) exemption per system - in the order that actually saves work.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.