


Updated July 2026
Compliance with the EU AI ActThe EU Artificial Intelligence Act was approved by the EU Council on 21 March 2024. A world-first comprehensive AI law, intended to harmonise rules for the development, deployment, and use of artificial intelligence systems across the EU. requires ongoing action. Meeting requirements should be part of how AI systems are selected, developed, used and reviewed, rather than being approached as a one-off exercise.
For many organisations, the challenge is turning broad regulatory requirements into a workable approach across different systems, teams and use cases. This guide explores five areas organisations should address as part of a structured compliance programme:
Under the AI Act, Providers and Deployers must support the AI literacy of staff and others who operate or use AI systems on their behalf. This applies to all AI systems, not only those classified as high-risk.
The level of training should reflect each person’s role, existing knowledge, the way the system is used and its potential impact. For most organisations, this means providing general guidance for AI users alongside more detailed training for those who develop, approve, manage or oversee higher-risk systems.
Staff training should cover:
Employees responsible for the human oversight of high-risk AI systems will need the knowledge, authority and support to intervene effectively. Organisations should keep a record of the training and guidance provided.
For organisations who provide or deploy AI systems classified as high-risk or General Purpose AI (GPAI), a foundation of strong corporate governance is essential to demonstrate and maintain compliance.
Without certain elements in place, organisations may struggle to meet specific requirements of the AI Act and maintain the necessary compliance documentation.
Key areas to address include:
The AI Act does not require organisations to appoint an AI OfficerAn individual responsible for overseeing the ethical, legal, and effective use of Artificial Intelligence (AI) within an organisation. or Chief AI Officer. However, some organisations are creating these roles in-house or using outsourced support to provide central oversight, lead AI governanceThe framework of policies, processes, and roles that ensure Artificial Intelligence (AI) is developed and used responsibly, ethically, and in compliance with applicable laws, societal expectations, and corporate values. projects, and put the right structures and processes in place.
The AI Act requires organisations to consider whether AI systems are sufficiently secure, robust and resilient for how they are used. These requirements are most detailed for high-risk systems, but strong cybersecurity controls are relevant to all AI use.
Key measures include:
Security should be reviewed before deployment and whenever the system, supplier or use case changes.
Where an AI system processes personal data of EU individuals, the General Data Protection RegulationRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). (GDPR) applies alongside the AI Act, and organisations must comply with both laws. The AI Act does not replace existing data protection obligations.
Key data protection considerations include:
Data protection should be considered before an AI system is developed, purchased or deployed, rather than once it is already in use.
The assessments required under the AI Act depend on the system, its risk level and your organisation’s role
Key assessment requirements include:
A Fundamental Rights Impact Assessment applies to specific deployers, including public bodies, private organisations providing public services and certain organisations using high-risk AI for credit or insurance decisions. It should complement any required DPIA rather than duplicate it.
Even where the AI Act does not require a formal assessment, an AI Impact AssessmentA structured process used to identify, assess, and mitigate potential risks associated with an AI system before and during its deployment. An AIIA evaluates factors such as fairness, transparency, privacy, and accountability, helping organisations demonstrate compliance with AI regulations and responsible innovation practices. can also help organisations consider wider risks such as accuracyIn data protection terms, the concept of ensuring data is not incorrect or misleading., bias, transparency, human oversight, cybersecurity and potential harm.
Assessments should be completed before an AI system is developed, purchased or deployed, and reviewed when the system, data or intended use changes.
There are certain resources available to support your compliance journey.
The EU AI Act Compliance Checker is a tool designed to help organisations verify that AI system aligns with the regulatory requirements.
However, the nuances of the AI Act are complex, and we urge all organisations uncertain of the extent of their obligations to seek professional advice.
_____________________________________________________________________________________________________________________________
The DPO Centre’s AI governance services can help you understand your obligations, assess AI risks and put appropriate oversight in place. This includes AI Impact Assessments and support from an Outsourced AI Officer.
_____________________________________________________________________________________________________________________________
In case you missed it…
______________________________________________________________________________________________________________________________
For more news and insights about data protection and AI governance follow The DPO Centre on LinkedIn
Fill in your details below and we’ll get back to you as soon as possible