AI governance for legal and DPOs: records someone can check.

For the people who advise on the law, write the assessments and answer the regulator: the AI-specific law next to the law that already applies, each duty with the artefact that evidences it.

Who this is for.

You read the law, settle the organisation's role and sign off the assessments. The risk is that the advice stays in a memo the pipeline never reads. This route reads the EU AI Act, data protection and the law that already applies to AI (consumer, equality, intellectual property, product liability) as a list of obligations, and shows the record each one expects, so the advice ends up where a gate can check it.

  • In-house counsel
  • Data protection officers
  • Privacy and compliance leads
  • Contract and procurement managers

On the learning path, start at Law-reading, Risk tiers and intake or Policy-as-code with OPA.

New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.

Three questions you bring.

Each one answered in brief here, and in full in the Body of Knowledge.

  1. Which role do we hold, and for which system?

    Provider, deployer, importer or distributor is settled per system, and it can move: putting your name or trademark on a high-risk system, modifying it substantially, or changing the intended purpose of a system so that it becomes high-risk makes you its provider (Art. 25(1)) 1.

  2. How do the FRIA and the DPIA fit together?

    Where a DPIA already meets an obligation of Article 27, the fundamental rights impact assessment complements that DPIA (Art. 27(4)) 1. One assessment record, cross-referenced, can serve both, instead of two documents that drift apart.

  3. What must we tell the people affected?

    People are told when they interact with an AI system, and synthetic content is marked (Art. 50) 1. Deployers of Annex III systems that decide or help decide about people inform them (Art. 26(11)), and explain the system’s role when a person subject to a decision with legal or similarly significant effects asks (Art. 86) 1. GDPR Articles 13 to 15 and 22 apply alongside 2.

Your route through the site.

In reading order: chapters at the section that matters, then the patterns, tools, templates, datasets and figures that turn them into work.

Start this week.

  1. Record your role (provider, deployer or both) for each AI system, with the reason. The EU operator roles
  2. Check each AI use against the Article 5 list and file the result, even when it is "none". Art. 5 prohibited practices
  3. Merge the DPIA and the FRIA into one assessment record with cross-references. Impact assessment schema
  4. Take the AI clause checklist into your next supplier negotiation. AI contract clause checklist
  5. Put the next three EU AI Act dates in the legal calendar. What applies now

The obligations that matter most.

The duties where legal judgement decides the rest: prohibitions, classification, roles along the value chain, deployer duties, the FRIA, transparency, bias-detection data, and two automated-decision regimes outside the EU.

Obligations for this route (Legal counsel and DPOs), with status, date and evidence
Obligation Applies Evidence
EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) AIGE-OBL-EUAIA-ART5 In force · Policy-as-code blocklist; input/output guardrails; refusal and abuse detection
EU AI Act Art. 6 classification of high-risk AI systems (incl. the Annex III route) AIGE-OBL-EUAIA-ART6 Deferred · Risk-tiering as code; high-risk classification decision record; register entry flagging Annex III status
EU AI Act Art. 25 responsibilities along the AI value chain AIGE-OBL-EUAIA-ART25 Deferred · Value-chain due-diligence gate; provider/deployer responsibility allocation; AIBOM and model/data cards collected from upstream providers
EU AI Act Art. 26 deployer obligations for high-risk systems AIGE-OBL-EUAIA-ART26 Deferred · Deployment registry; monitoring hooks; assigned oversight and logging retention
EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA) AIGE-OBL-EUAIA-ART27 Deferred · FRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA
EU AI Act Art. 50 transparency for certain AI systems AIGE-OBL-EUAIA-ART50 In force · Content labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner
EU AI Act Art. 4a lawful basis for special-category data in bias detection AIGE-OBL-EUAIA-ART4A In force · Data governance controls; pseudonymisation and retention-as-code; data card noting basis and deletion
UK DUAA · UK GDPR Arts. 22A–22D permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025) AIGE-OBL-UK-ADM In force · ADM safeguards: meaningful-human-review path, contest and representation channel, decision notice
Colorado ADMT · Colorado SB 26-189 automated decision-making technology (replaces the Colorado AI Act, SB 24-205; effective 2027-01-01) AIGE-OBL-USCO-AIACT Applies later · ADMT inventory; developer documentation pack; notice and adverse-outcome explanation templates; human-review queue; three-year record store

Every obligation in the register

Sources

  1. [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Arts. 25(1), 26(11), 27(4), 50 and 86). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
  2. [2] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 13 to 15 and 22). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)

Start at the top of the route.

Step 01 is The EU AI Act in one pass. Each step after it builds on the one before.