AI governance for legal and DPOs: records someone can check.
For the people who advise on the law, write the assessments and answer the regulator: the AI-specific law next to the law that already applies, each duty with the artefact that evidences it.
Who this is for.
You read the law, settle the organisation's role and sign off the assessments. The risk is that the advice stays in a memo the pipeline never reads. This route reads the EU AI Act, data protection and the law that already applies to AI (consumer, equality, intellectual property, product liability) as a list of obligations, and shows the record each one expects, so the advice ends up where a gate can check it.
- In-house counsel
- Data protection officers
- Privacy and compliance leads
- Contract and procurement managers
On the learning path, start at Law-reading, Risk tiers and intake or Policy-as-code with OPA.
New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.
Three questions you bring.
Each one answered in brief here, and in full in the Body of Knowledge.
-
Which role do we hold, and for which system?
Provider, deployer, importer or distributor is settled per system, and it can move: putting your name or trademark on a high-risk system, modifying it substantially, or changing the intended purpose of a system so that it becomes high-risk makes you its provider (Art. 25(1)) 1.
-
How do the FRIA and the DPIA fit together?
Where a DPIA already meets an obligation of Article 27, the fundamental rights impact assessment complements that DPIA (Art. 27(4)) 1. One assessment record, cross-referenced, can serve both, instead of two documents that drift apart.
-
What must we tell the people affected?
People are told when they interact with an AI system, and synthetic content is marked (Art. 50) 1. Deployers of Annex III systems that decide or help decide about people inform them (Art. 26(11)), and explain the system’s role when a person subject to a decision with legal or similarly significant effects asks (Art. 86) 1. GDPR Articles 13 to 15 and 22 apply alongside 2.
Your route through the site.
In reading order: chapters at the section that matters, then the patterns, tools, templates, datasets and figures that turn them into work.
Read the law
- The EU AI Act in one pass Chapter 18 · Scope, the risk ladder, roles, duties and the post-Omnibus dates.
- The risk ladder Chapter 18 · Prohibited, high-risk through products or use, transparency cases, minimal risk.
- Data protection law applied to AI Chapter 19 · Lawful basis, DPIAs, automated decisions and rights against trained models.
- Other law that already applies Chapter 20 · Intellectual property, non-discrimination, consumer protection and product liability.
- AI laws around the world Chapter 21 · Korea, the US federal and state layers, Japan, China, the UK and more.
- Topic crosswalk Reference · One topic per row, read across the instruments down to the article.
Assess and contract
- EU AI Act risk classification checker Tool · A first reading of role and risk class for one system, as a document you keep.
- FRIA-as-Code Pattern · The impact assessment as versioned data, with the triggers that reopen it.
- Impact assessment schema Template · One record for the FRIA and the DPIA, cross-referenced.
- Impact assessment builder Tool · Draft the assessment in the browser and export it.
- Where control moves when you buy Figure · Where control moves when you buy instead of build.
- Contract clauses Reference · AI contract and licence clauses: red flags, fallbacks and the evidence to keep.
- AI contract clause checklist Template · What to secure from a supplier, each term tied to the obligation it answers.
Keep the evidence
- The obligation register Reference · Every obligation with a stable id, its date, its status and its artefact.
- Obligations and deadlines planner Tool · Turn the dates that apply to you into a plan and a calendar file.
- Framework Crosswalk Pattern · Map once and reuse the same evidence across instruments.
- Obligations (CSV) Dataset · The register as a spreadsheet for your own tracker.
- Who enforces, and the ceilings Figure · Who enforces what, and the fine ceilings.
Start this week.
- Record your role (provider, deployer or both) for each AI system, with the reason. The EU operator roles
- Check each AI use against the Article 5 list and file the result, even when it is "none". Art. 5 prohibited practices
- Merge the DPIA and the FRIA into one assessment record with cross-references. Impact assessment schema
- Take the AI clause checklist into your next supplier negotiation. AI contract clause checklist
- Put the next three EU AI Act dates in the legal calendar. What applies now
The obligations that matter most.
The duties where legal judgement decides the rest: prohibitions, classification, roles along the value chain, deployer duties, the FRIA, transparency, bias-detection data, and two automated-decision regimes outside the EU.
| Obligation | Applies | Evidence |
|---|---|---|
| EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) AIGE-OBL-EUAIA-ART5 | In force · | Policy-as-code blocklist; input/output guardrails; refusal and abuse detection |
| EU AI Act Art. 6 classification of high-risk AI systems (incl. the Annex III route) AIGE-OBL-EUAIA-ART6 | Deferred · | Risk-tiering as code; high-risk classification decision record; register entry flagging Annex III status |
| EU AI Act Art. 25 responsibilities along the AI value chain AIGE-OBL-EUAIA-ART25 | Deferred · | Value-chain due-diligence gate; provider/deployer responsibility allocation; AIBOM and model/data cards collected from upstream providers |
| EU AI Act Art. 26 deployer obligations for high-risk systems AIGE-OBL-EUAIA-ART26 | Deferred · | Deployment registry; monitoring hooks; assigned oversight and logging retention |
| EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA) AIGE-OBL-EUAIA-ART27 | Deferred · | FRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA |
| EU AI Act Art. 50 transparency for certain AI systems AIGE-OBL-EUAIA-ART50 | In force · | Content labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner |
| EU AI Act Art. 4a lawful basis for special-category data in bias detection AIGE-OBL-EUAIA-ART4A | In force · | Data governance controls; pseudonymisation and retention-as-code; data card noting basis and deletion |
| UK DUAA · UK GDPR Arts. 22A–22D permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025) AIGE-OBL-UK-ADM | In force · | ADM safeguards: meaningful-human-review path, contest and representation channel, decision notice |
| Colorado ADMT · Colorado SB 26-189 automated decision-making technology (replaces the Colorado AI Act, SB 24-205; effective 2027-01-01) AIGE-OBL-USCO-AIACT | Applies later · | ADMT inventory; developer documentation pack; notice and adverse-outcome explanation templates; human-review queue; three-year record store |
Sources
- [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Arts. 25(1), 26(11), 27(4), 50 and 86). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
- [2] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 13 to 15 and 22). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
Other routes.
- For engineers ML, platform, MLOps, application and security engineers who build and run AI systems.
- For CISOs and risk leads CISOs, heads of risk, model risk managers, internal audit and third-party risk managers.
- For executives and boards Board members, executive committees, and chief AI, data and technology officers.
- For the public sector Public bodies and operators of public services: CIOs, service owners, procurement and oversight.
- For SMEs and start-ups Small and medium-sized companies and start-ups, most of them buying more AI than they build.
- AIGP candidates The public AIGP body of knowledge read against this site. Not affiliated with or endorsed by IAPP.
- Certifications Certifications and assessments in AI governance, and what each one evidences.
Start at the top of the route.
Step 01 is The EU AI Act in one pass. Each step after it builds on the one before.