All news
Tech & AI May 8, 2026 10 min

AI Act August 2026: high-risk systems deadline. Mandatory DPIA for enterprise LLMs

EDPB confirms LLMs rarely meet GDPR anonymization standards. Italian Garante's record EUR 5M fine to Replika opens preventive enforcement

UPDATE (July 2026): this calendar has changed

The Digital Omnibus package, adopted by Parliament on 16 June 2026 and by the Council on 29 June 2026, deferred the high-risk obligations: 2 December 2027 for Annex III (stand-alone systems) and 2 August 2028 for Annex I (AI embedded in regulated products). The Article 50 transparency duties remain confirmed for 2 August 2026. The text below is the version published before the amendment and is kept for documentary continuity.

TL;DR for the DPO

August 2026 triggers AI Act obligations for high-risk systems (Annex III). EDPB has clarified that LLMs (ChatGPT, Claude, Gemini) rarely meet GDPR anonymization standards: integrating them into business processes requires Art. 35 GDPR DPIA. The Italian Garante has anticipated enforcement with EUR 5M to Luka (Replika). DPO priorities: mapping AI use across clients, preventive DPIA, AI vendor due diligence, user training.

The regulatory framework

The AI Act (EU Regulation 2024/1689) entered into force on August 1, 2024 with progressive application. Key deadlines:

  • February 2, 2025 - Ban on unacceptable risk systems (social scoring, behavioral manipulation, real-time biometric identification in public spaces, etc.)
  • August 2, 2025 - Obligations for GPAI (general-purpose AI) models and codes of conduct
  • August 2, 2026 - OBLIGATIONS for high-risk AI systems (Annex III): conformity assessment, technical documentation, quality management, EU registration, CE marking, human oversight, robustness, accuracy, transparency
  • August 2, 2027 - Full application to AI systems integrated into already-regulated products
Aug 2026
High-risk systems deadline
35M / 7%EUR or revenue
Maximum AI Act fine

AI Act and GDPR apply together

The AI Act does NOT replace GDPR. AI systems processing personal data must comply with BOTH. EDPB Opinion 28/2024 clarified that LLMs rarely meet GDPR anonymization standards: user prompts and model responses are processing of personal data, subject to legal basis, minimization principle, Art. 13 GDPR transparency, etc.

Official source:AI Act - Regulation EU 2024/1689Official source:EDPB Opinion 28/2024 - LLM and GDPR

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free