Law / European Union

AI Act, Article 26(9) (using Article 13 information for a data protection impact assessment)

Regulation (EU) 2024/1689, Article 26(9)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

An AI governance rule binding public and private bodies.

As of 24 September 2026.

What it requires

  • This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
  • If you are the deployer of a high-risk AI system and you are separately required to carry out a data protection impact assessment under the General Data Protection Regulation (GDPR) or the Law Enforcement Directive, use the information the provider supplies you under Article 13 in that assessment.

If you get it wrong

Private right of actionNo

Penalty structure

Article 99(4)(e): non-compliance with the obligations of deployers under Article 26 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.

Rule
Lower of for SME
As of
24 September 2026
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
3

What it reaches

How the hook was established

express

What makes it apply

Operator establishment, Place of effect

Obligation class

DPIA

What it makes you log

Logging duty

Article 26(9) requires a deployer to use Article 13 information in a data protection impact assessment it is already required to carry out; the impact-assessment duty itself, and any record it produces, arises under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, outside this Regulation, so this row does not code that duty's own record-keeping requirement.

Kind
None
As of
24 September 2026

Who checks it

Audit expectation

none

Also on the record

EEA status

Status
Pending
Source link
https://www.efta.int/eea-lex/32024r1689

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Where applicable, a deployer of a high-risk AI system must use the information the provider supplies under Article 13 to comply with the deployer's own duty to carry out a data protection impact assessment under Article 35 of the General Data Protection Regulation or Article 27 of the Law Enforcement Directive.

Article 26(9) does not itself create the impact-assessment duty, which is a data-protection duty owed under those instruments; it obligates a deployer already subject to one to draw on the provider's Article 13 disclosure when carrying it out.

Article 26 sits in Chapter III, Section 3, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for one classified under Article 6(1) and Annex I.

When LexLint raises it

  • high_risk_decisions

Read the law

official consolidated Official Journal text, EUR-Lex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app