The six questions asked most often at the intersection of the EU AI Act and GDPR — each paired with the ready-to-fill document that answers it.
Each guide explains one legal question and ends with the blank template that answers it. The order is a suggestion — the scope test determines which of the others you actually need.
Who do the transparency obligations bind? A four-question scope test drawn from Article 2, followed by a six-document dossier: scoping assessment, disclosure texts in three languages, synthetic-content policy, supplier addendum, employee policy and a compliance register.
02Who is liable when an employee pastes company data into ChatGPT? Shadow AI, a classified tool list, prohibited input categories and a data-leakage incident protocol.
03Is your software high-risk under Art. 6 and Annex III? Scope, role and classification, with the Art. 6(3) derogation and the Art. 99 fine thresholds.
04Does what the agent agreed bind the company? An authority matrix, human approval thresholds, disclosure text for counterparties and a rollback protocol.
05Can you sell the images, text and code you generate? Ownership, provider terms, the record of human contribution, and infringement screening for each output type.
06Who does your screening system screen out? Profiling determination, indirect discrimination proxies, pass-rate measurement, human oversight and a candidate notice.
07Korea's Framework Act on AI applies from 22 January 2026, with extraterritorial reach. A high-impact classification test, generative-AI labelling, the domestic representative and an obligations register.
08Since March 2024, a right to refuse fully automated decisions and to demand an explanation. A disclosure notice, an automated-decision register and a request-handling workflow.
09Article 9 changed on 1 June 2024. A tiered decision map — adequacy, standard contract, binding corporate rules and the narrow exceptional cases — with the 5-day notification.
10AI runs on personal data and KVKK already applies. Lawful basis, special categories, profiling and transparency — aligned with the prospective Turkish AI Act.
In an audit, or on an EU corporate buyer's supplier form, the first question is not whether a breach occurred but whether the company holds a written record of the measures it took beforehand. The templates in these guides exist to produce exactly that record.
They are all blank frameworks: without the bracketed fields and the classification sections completed for your company, they do no work. The places where they are most often filled in wrongly are set out in each guide's § 04.
Yes. All six guides and their templates download without registering or giving an email address. The documents also sit on the page as copyable text, and download in markdown, Word and Excel formats.
The scope test is the most efficient starting point. Until you establish whether the Regulation binds you, you cannot tell which of the other documents you need. If you are in scope, the next step is role determination: provider, deployer, or deemed provider under Art. 25.
As a framework yes, as a final document no. The bracketed fields and classification sections have to be completed for your company. They also need checking against your existing client and supplier agreements.
Yes. The Regulation applies even where the provider or deployer is established in a third country, provided the system's output is used within the Union (Art. 2(1)(c)). The data protection and employment law obligations covered also apply independently of any EU connection.
The application date for high-risk obligations was postponed. But the Article 50 transparency obligations stayed outside that postponement, and data protection obligations already apply today and call for substantially the same records.
In a twenty-minute preliminary call we work out together which document applies to you. If you're out of scope, we tell you that clearly too.
Reserve your spot for an online call The call is online · the documents are yours either way