Brussels Previews GDPR/AI Act Joint Guidelines: What to Do Now

The EDPB Just Signaled Its Next Move — Counsel Should Map Now
The interplay between the GDPR and the EU AI Act is about to get regulator-authored clarity, and privacy counsel should not wait for the final text to prepare. At IAPP AI Governance Global Europe 2026 in Dublin, EDPB Legal Officer Gintarė Pažereckaitė previewed forthcoming joint EDPB-Commission guidelines on how EU data protection law and the AI Act fit together, as reported by IAPP.
According to that preview, a first draft could come soon, with the final version expected by end of 2026. That is a near-term deadline for anyone deploying AI systems that process personal data of individuals in the EU.
Here is what changed and what you must do this quarter. Two regulators — the European Data Protection Board and the Commission's AI Office — are aligning positions on questions that have divided practitioners since the AI Act entered into force. Start your data-flow inventory now so the draft does not catch you flat-footed.
Two Regulations, One Overlap: The Legal Anchors
You cannot analyze the interplay without the citations straight. The GDPR is Regulation (EU) 2016/679, published in OJ L 119 on 4 May 2016, and applicable in all EU Member States since 25 May 2018.
The AI Act is Regulation (EU) 2024/1689, published in OJ L, 2024/1689, on 12 July 2024, and entered into force on 1 August 2024. Under Article 113, prohibited practices and AI literacy requirements applied from 2 February 2025, and general-purpose AI model obligations from 2 August 2025.
The overlap is unavoidable. An AI system that classifies, scores, or profiles individuals in the EU triggers both regimes at once — the GDPR governs the personal data going in and out, and the AI Act governs the system's risk classification, oversight, and logging. When two regulations regulate the same activity, the compliance answer is not 'pick one.' It is a mapped data flow with a documented legal basis for each processing step.
Why This Preview Matters: A Precedent for Joint Guidance
The DMA/GDPR precedent tells you what to expect
This is not the EDPB's first coordination exercise with the Commission. On 9 October 2025, the EDPB and the European Commission endorsed the first-ever joint guidelines — on the interplay between the Digital Markets Act and the GDPR — and opened a public consultation that ran until 4 December 2025.
That model matters. It signals that the GDPR/AI Act guidelines will likely follow the same path: draft, public consultation, then a final endorsed text. Counsel who want to shape the outcome should watch for the consultation window and file comments.
What the guidance will probably have to resolve
- Legal basis for training data — how controllers justify processing personal data to train and fine-tune models under Article 6 of the GDPR.
- Automated decision-making — the interaction between Article 22 GDPR and the AI Act's human-oversight requirements for high-risk systems.
- Roles and accountability — whether an AI provider, deployer, or both act as controller or processor for a given processing step.
Do not assume the guidelines will hand you a safe harbor. Regulator guidance narrows discretion; it rarely widens it.
The Moving Deadline: Digital Omnibus Shifts High-Risk Timing
There is a second reason to act now: the compliance calendar moved. The Digital Omnibus on AI — procedure 2025/0359(COD), based on Commission proposal COM(2025) 836 final of 19 November 2025 — was provisionally agreed on 7 May 2026, formally adopted by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, and signed on 8 July 2026. It awaits publication in the Official Journal before entering into force.
What the Omnibus changes. It postpones the high-risk AI obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I from 2 August 2027 to 2 August 2028, per Bird & Bird's analysis.
What did not move. The Article 50 transparency obligations remain due on 2 August 2026 as originally scheduled. That is the trap: extra runway on high-risk classification does not buy you extra time on transparency duties. If your system generates synthetic content or interacts with people, that clock is still running.
Action Items for This Quarter
Treat the forthcoming guidelines as an inventory-forcing event. You cannot govern what you have not mapped.
- Build an AI-processing register. List every AI system that processes personal data of individuals in the EU, with the processing purpose, the categories of data, and the GDPR legal basis for each step.
- Classify each system under the AI Act. Tag prohibited, high-risk (Annex I or Annex III), limited-risk (Article 50 transparency), and minimal-risk. Note the revised deadlines from the Digital Omnibus against each classification.
- Meet Article 50 transparency by 2 August 2026. Do not let the high-risk extension distract you. Confirm disclosures for AI interaction and synthetic content are live on schedule.
- Reconcile roles. Document, per system, whether you are provider, deployer, controller, or processor — and align your DPAs and vendor contracts to match.
- Prepare consultation comments. When the draft joint guidelines open for public consultation, have your positions ready. The DMA/GDPR track ran a consultation to 4 December 2025; expect a comparable window here.
That won't fly with a regulator: a boilerplate privacy notice that does not name your AI processing, or a risk classification that lives only in a slide deck. Supervisory authorities expect a data map, a retention schedule, and an audit trail on day one of an inquiry.
Key Takeaways and Next Steps
The signal from Dublin is clear: regulator-authored answers to the GDPR/AI Act overlap are coming, and the prudent move is to prepare the record before the draft lands.
- Joint guidelines are forthcoming, not final — a first draft could come soon with the final expected by end of 2026, per the EDPB's Dublin preview; do not cite content that does not exist yet.
- Expect a consultation window — the 9 October 2025 DMA/GDPR joint guidelines opened a consultation that ran to 4 December 2025, and this track will likely mirror it.
- Transparency deadlines did not move — Article 50 obligations remain due on 2 August 2026, even though the Digital Omnibus pushed high-risk Annex III to 2 December 2027 and Annex I to 2 August 2028.
- Inventory first, notices second — map every AI system that processes EU personal data, classify it under the AI Act, and align roles before you touch a privacy notice or DPA.
Rikka Law helps companies operationalize privacy and AI governance — from AI-processing registers and risk classification to vendor diligence and board-ready policies. If you deploy AI that touches personal data of individuals in the EU, contact our team to build the record before the guidelines arrive, and see more at fintechlaw.ai.
Disclaimer: This post is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship. Consult qualified counsel about your specific facts.