New AI Governance Report: Procurement & supply chain risk

Access now

Contents

What Does the EU AI Act Mean for DPOs? 

Reading Time: 3 minutes
European Union flags in front of the blurred European Parliament in Brussels, Belgium
Authors: 
Trilateral Research |
Date: 29 October 2025

The EU AI Act is set to become the world’s first comprehensive regulation on artificial intelligence. For Data Protection Officers (DPOs), this legislation is not just another compliance challenge, but represents a significant expansion of responsibility. AI systems increasingly process personal data, influence decisions, and carry risks to individuals’ rights. As organisations begin to prepare, DPOs are uniquely positioned to guide ethical, lawful, and responsible AI use. 

This blog explains what the EU AI Act is, why it matters to DPOs, and what you need to know right now. 

What Is the EU AI Act? 

The EU AI Act is a horizontal regulation that applies to both public and private sector organisations developing, deploying, or using AI systems in the EU. Its goals are to: 

  • Ensure AI is safe and trustworthy 
  • Protect fundamental rights 
  • Promote transparency and accountability 
  • Harmonise rules across the EU 
  • Unlike sector-specific laws, the AI Act takes a cross-cutting approach and applies to a wide range of AI use cases and actors. It builds on principles similar to GDPR but focuses on the lifecycle of AI systems rather than data alone. 

In simple terms: The EU AI Act sets rules for how AI can be developed, used, monitored, and governed. 

Why DPOs Should Care: Your Role Is Expanding 

AI almost always involves personal data - whether directly or indirectly. The risks AI introduces (bias, discrimination, opacity, automated decisions) align closely with the risks DPOs already manage under GDPR. 

Key reasons DPOs are central to AI Act compliance: 

  • Similar accountability model to GDPR 
  • Strong focus on rights, fairness, and transparency 
  • Heavy emphasis on documentation and governance 
  • Overlap with DPIAs and risk management processes 
  • DPOs are the natural bridge between legal, data, technology, and ethics. With the AI Act, this role becomes even more strategic. 

Core Concepts DPOs Need to Understand 

The EU AI Act is built around a risk-based approach, where the higher the risk, the stricter the obligations. 

  1. Risk Categories:
  • Unacceptable risk (banned systems) 
  • High-risk AI (strict requirements) 
  • Limited risk (transparency obligations) 
  • Minimal risk (encouraged adoption of voluntary codes) 
  1. High-Risk Obligations:

 High-risk AI systems must meet requirements across: 

  • Risk management systems 
  • High-quality datasets 
  • Documentation & record-keeping 
  • Transparency 
  • Human oversight 
  • Accuracy, robustness, and cybersecurity 
  1. Transparency Requirements:

 Users must be informed when interacting with AI systems such as chatbots or deepfakes. 

  1. Human Oversight:

 AI decisions must not be fully automated without the ability for human intervention. 

  1. Data Governance & Quality:

 This is a major area for DPO involvement, as data integrity and bias prevention are central to responsible AI.  

Key Overlaps with GDPR (An Advantage for DPOs) 

The AI Act and GDPR are closely connected. Many AI compliance requirements mirror data protection obligations. 

Similarities include: 

  • Data protection by design → Responsible AI by design 
  • DPIAs → AI Impact Assessments (AIIAs) /Fundamental Rights Impact Assessments (FRIAs) for certain high risk systems. 
  • Documentation and record-keeping 
  • Risk-based approach 
  • Rights of individuals 

Key difference: GDPR regulates personal data; the AI Act regulates the AI system itself. 

For DPOs, this alignment means existing GDPR processes can be adapted to meet AI Act requirements - rather than starting from scratch. 

What Will Be Expected of DPOs in Practice 

DPOs will play a hands-on role in AI governance. Key responsibilities may include: 

  • Identifying AI use across the organisation 
  • Classifying AI systems by risk level 
  • Advising on legal and ethical implications 
  • Supporting or leading Fundamental Rights Impact Assessments 
  • Ensuring documentation and transparency 
  • Collaborating with IT, legal, ethics, and security teams 
  • Monitoring ongoing compliance and performance 

This role goes beyond data protection - it’s about shaping how AI is introduced, managed, and monitored throughout its lifecycle.  

Timelines & Enforcement: When DPOs Need to Act 

The AI Act will be phased in over several years: 

  • 2024 - 2025: Final text and preparation period 
  • 2025: Banned AI systems become illegal 
  • 2026: High-risk obligations apply 
  • 2027: Full implementation (most provisions) 

Penalties: Similar to GDPR, fines can reach up to €35 million or 7% of global annual turnover. 

Key takeaway: Early preparation reduces risk and avoids last-minute pressure. 

Where to Start: First Steps for DPOs 

DPOs can begin preparing now with practical, manageable steps: 

  1. Audit current AI use across the organisation 
  2. Map AI systems to risk levels under the Act 
  3. Clarify roles and accountability (who owns AI compliance?) 
  4. Establish or extend governance frameworks to include AI 
  5. Update data protection processes to integrate AI-specific risks 

Early action will help DPOs lead AI readiness and embed responsible practices. 

What’s Coming Next: Training and Practical Guidance 

The EU AI Act introduces new responsibilities and skill requirements. DPOs will need to understand: 

  • AI Impact Assessments 
  • Technical and operational AI risks 
  • How to work with data scientists and engineers 
  • How to monitor AI performance over time 

This is not just a legal or policy shift, but an operational change. DPOs will need practical tools, training, and cross-functional collaboration to succeed. 

Key Takeaways for DPOs 

The EU AI Act is a major regulatory shift - and a unique opportunity for DPOs. As organisations adopt AI, DPOs will become key advisors and leaders in responsible, rights-preserving innovation. 

By understanding the Act, aligning it with GDPR, and taking early action, DPOs can move from compliance guardians to strategic drivers of trustworthy AI. 

Responsible AI isn’t just a legal obligation - it’s essential for trust and accountability. 

Receive our latest articles

AI Governance & Compliance Services

Related Articles

Responsible AI for Leaders

Practical insights and thought leadership to help you understand, govern, and grow with AI.