AI Act, Article 26(9) (using Article 13 information for a data protection impact assessment)
Regulation (EU) 2024/1689, Article 26(9)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
An AI governance rule binding public and private bodies.
As of 24 September 2026.
What it requires
- This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
- If you are the deployer of a high-risk AI system and you are separately required to carry out a data protection impact assessment under the General Data Protection Regulation (GDPR) or the Law Enforcement Directive, use the information the provider supplies you under Article 13 in that assessment.
If you get it wrong
Private right of actionNo
Penalty structure
Article 99(4)(e): non-compliance with the obligations of deployers under Article 26 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.
- Rule
- Lower of for SME
- As of
- 24 September 2026
- Currency
- EUR
- Fixed cap
- 15,000,000
- Turnover percentage cap
- 3
What it reaches
How the hook was established
express
What makes it apply
Operator establishment, Place of effect
Obligation class
DPIA
What it makes you log
Logging duty
Article 26(9) requires a deployer to use Article 13 information in a data protection impact assessment it is already required to carry out; the impact-assessment duty itself, and any record it produces, arises under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, outside this Regulation, so this row does not code that duty's own record-keeping requirement.
- Kind
- None
- As of
- 24 September 2026
Who checks it
Audit expectation
none
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Where applicable, a deployer of a high-risk AI system must use the information the provider supplies under Article 13 to comply with the deployer's own duty to carry out a data protection impact assessment under Article 35 of the General Data Protection Regulation or Article 27 of the Law Enforcement Directive.
Article 26(9) does not itself create the impact-assessment duty, which is a data-protection duty owed under those instruments; it obligates a deployer already subject to one to draw on the provider's Article 13 disclosure when carrying it out.
Article 26 sits in Chapter III, Section 3, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for one classified under Article 6(1) and Annex I.
When LexLint raises it
high_risk_decisions
Read the law
official consolidated Official Journal text, EUR-Lex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.