GovCompass
ReferencePrivacy

Art. 26.9 EU AI Act: DPIA obligation for high-risk AI

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 26.9 links the EU AI Act to the GDPR: where a data protection impact assessment (DPIA) is required under GDPR Art. 35, deployers of high-risk AI must use the information from the provider's documentation to support that assessment.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Updated: June 2026

Introduction: two frameworks, one impact assessment

Art. 26(9) creates an explicit link between the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → and the GDPRGDPRRegulation (EU) 2016/679, the General Data Protection Regulation, the EU's law on the processing of personal data. It applies to AI wherever personal data enters training, inputs, outputs, or logs, and it operates alongside the EU AI Act rather than being replaced by it. See controller, processor, lawful basis, DPIA.Open full entry →: a deployerdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → that is already required to carry out a data protection impact assessmentimpact assessmentA structured evaluation, carried out in the plan-and-design stage, of the harms an AI system could cause and the risk those harms carry, before the system is built. The first place the governance chain is run, and the cheapest point in the life cycle to reduce risk. The anchor artifact of the planning stage; under the EU AI Act, a fundamental-rights impact assessment is required for certain high-risk deployers. See harm, risk, life cycle.Open full entry → under Art. 35 GDPR uses the information the providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → supplies under Art. 13 to help fulfill that obligation, rather than duplicating the analysis.

This provision does not create a new standalone obligation, it extends the existing GDPR Art. 35 DPIADPIAData Protection Impact Assessment: required before likely-high-risk processing (systematic profiling with significant effects, large-scale special categories, public monitoring); AI development triggers it constantly.Open full entry → framework to encompass the AI-specific elements required by the EU AI Act. For organizations already conducting DPIAs for AI-related processing, this means expanding the scope of those assessments.

When is a DPIA required?

Under GDPR Art. 35, a DPIA is required when processing is likely to result in "high riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry →" to individuals' rights and freedoms. The EDPB has identified specific types of processing that always require a DPIA, including:

  • Systematic and extensive profilingprofilingAutomated processing of personal data to evaluate or predict aspects of a person, such as performance, behavior or location, as defined in the GDPR.Open full entry → with significant effects
  • Large-scale processing of special categories of data
  • Systematic monitoring of publicly accessible areas

High-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → under the EU AI Act will frequently trigger DPIA obligations under one or more of these criteria. A CV screening AI (Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry →, point 4) involves systematic profiling with significant effects on employment. A credit scoring system involves profiling with significant financial effects.

What to include in the integrated DPIA

An AI Act-integrated DPIA should cover, in addition to the standard GDPR elements:

  • AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → classification: Risk class and classification rationale (Art. 6)
  • Technical characteristics: System architecture, training datatraining dataThe data used to fit an AI model's parameters; its quality, lawful rights and representativeness are central governance concerns.Open full entry → provenanceprovenanceThe documented origin and history of data or content, used to establish where it came from and whether it can be trusted or lawfully used.Open full entry →, performance metrics
  • Oversight arrangements: How human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → is implemented (Art. 26.2)
  • BiasbiasA systematic skew in data, model behavior, or outcomes that treats one group differently from another without justification. Bias usually enters through training data that reflects historical patterns. For high-risk AI systems, Article 10 of the EU AI Act requires examination of datasets for possible biases and measures to detect, prevent, and mitigate them. See fairness, proxy discrimination.Open full entry → risk assessment: Analysis of potential demographic disparities in AI outputs
  • Input data quality measures: Data quality controlscontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry → (Art. 26.4)
  • Retention of AI logs: Log retention policy (Art. 26.6)
  • Fundamental rights impact: For systems also requiring a FRIAFRIAFundamental Rights Impact Assessment: required of public bodies and certain private deployers before using some high-risk AI systems under the EU AI Act.Open full entry → under Art. 27, the analyses may be combined

Relationship with the FRIA

For public sector deployers of high-risk AI, Art. 27 also requires a Fundamental Rights Impact Assessmentfundamental rights impact assessmentAn assessment that certain deployers of high-risk AI must perform to identify and mitigate the system's risks to people's fundamental rights.Open full entry → (FRIA). The DPIA and FRIA overlap significantly. Best practice is to conduct a combined DPIA/FRIA that satisfies both requirements simultaneously, with clearly labeled sections for each framework.

Compliance checklist

  1. Have you identified all high-risk AI systems that also process personal data (triggering GDPR jurisdiction)?
  2. Has a DPIA been conducted for each such system?
  3. Does the DPIA include the EU AI Act-specific elements listed above?
  4. Has the DPO been consulted in the DPIA process?
  5. Is the DPIA reviewed and updated when the AI system or its use case changes?
  6. Is the DPIA documented and accessible for supervisory review?
Legal referencesArt. 26
Share Share on LinkedIn