[{"data":1,"prerenderedAt":756},["ShallowReactive",2],{"blog-dpia-llm-feature-worked-example-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":14,"about":23,"sources":36,"cover":81,"og":82,"expertise":83,"locales":84,"lang":85,"title":88,"description":89,"coverAlt":90,"metaTitle":91,"takeaways":92,"faq":98,"toc":114,"blocks":142,"others":452},"dpia-llm-feature-worked-example","2026-10-01",12,"security",[9,10,11,12,13],"DPIA","GDPR","LLM security","Data protection","AI Act",[15,16,17,18,19,20,21,22],"DPIA for LLM features","data protection impact assessment AI assistant","GDPR Article 35 AI","DSFA-V Austria AI","LLM customer support GDPR","prompt injection data leak GDPR","AI Act Article 50 chatbot","DPIA template LLM",[24,27,30,33],{"name":25,"url":26},"General Data Protection Regulation","https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:32016R0679",{"name":28,"url":29},"WP29 guidelines on data protection impact assessment (WP248 rev.01)","https:\u002F\u002Fec.europa.eu\u002Fnewsroom\u002Farticle29\u002Fitems\u002F611236\u002Fen",{"name":31,"url":32},"OWASP LLM01:2025 Prompt Injection","https:\u002F\u002Fgenai.owasp.org\u002Fllmrisk\u002Fllm01-prompt-injection\u002F",{"name":34,"url":35},"Regulation (EU) 2024\u002F1689 (AI Act)","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj",[37,39,41,44,47,50,53,56,59,62,64,67,70,73,76,78],{"title":38,"url":26},"Regulation (EU) 2016\u002F679 (GDPR), EUR-Lex",{"title":40,"url":29},"WP29 guidelines on DPIA, WP248 rev.01 (European Commission item page)",{"title":42,"url":43},"WP248 rev.01 PDF, adopted 4 April 2017 and revised 4 October 2017","https:\u002F\u002Fec.europa.eu\u002Fnewsroom\u002Fjust\u002Fdocument.cfm?doc_id=47711",{"title":45,"url":46},"EDPB Guidelines 07\u002F2020 on the concepts of controller and processor","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2023-10\u002Fedpb_guidelines_202007_controllerprocessor_final_en.pdf",{"title":48,"url":49},"EDPB Opinion 28\u002F2024 on AI models, adopted 17 December 2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2024-12\u002Fedpb_opinion_202428_ai-models_en.pdf",{"title":51,"url":52},"EDPB news release on Opinion 28\u002F2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fnews\u002Fedpb-opinion-on-ai-models-gdpr-principles-support-responsible-ai_en",{"title":54,"url":55},"EDPB, Report of the work undertaken by the ChatGPT Taskforce, 23 May 2024","https:\u002F\u002Fwww.edpb.europa.eu\u002Fsystem\u002Ffiles\u002F2024-05\u002Fedpb_20240523_report_chatgpt_taskforce_en.pdf",{"title":57,"url":58},"DSFA-V, BGBl. II Nr. 278\u002F2018 (RIS)","https:\u002F\u002Fwww.ris.bka.gv.at\u002Feli\u002Fbgbl\u002FII\u002F2018\u002F278",{"title":60,"url":61},"DSFA-AV, BGBl. II Nr. 108\u002F2018 (RIS)","https:\u002F\u002Fwww.ris.bka.gv.at\u002Feli\u002Fbgbl\u002FII\u002F2018\u002F108",{"title":63,"url":32},"OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection",{"title":65,"url":66},"OWASP Top 10 for LLM Applications 2025: LLM02 Sensitive Information Disclosure","https:\u002F\u002Fgenai.owasp.org\u002Fllmrisk\u002Fllm022025-sensitive-information-disclosure\u002F",{"title":68,"url":69},"OpenAI, Data controls in the OpenAI platform","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fyour-data",{"title":71,"url":72},"Commission Implementing Decision (EU) 2023\u002F1795 on the EU–US Data Privacy Framework","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Fdec_impl\u002F2023\u002F1795\u002Foj\u002Feng",{"title":74,"url":75},"CJEU, Case C-184\u002F20, OT v Vyriausioji tarnybinės etikos komisija","https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:62020CJ0184",{"title":77,"url":35},"Regulation (EU) 2024\u002F1689 (AI Act), EUR-Lex",{"title":79,"url":80},"Regulation (EU) 2026\u002F1744 (Digital Omnibus on AI), EUR-Lex","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj","\u002Fimages\u002Fblog\u002Fdpia-llm-feature-worked-example\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fdpia-llm-feature-worked-example\u002Fog.jpg","ai-engineer",[85,86,87],"en","de","hu","DPIA for an LLM support assistant: a worked example under GDPR Art. 35","A worked DPIA under GDPR Art. 35 for an AI assistant that drafts customer email replies from order data: when it is needed, the risks and owners.","Cover art for a DPIA of an LLM support assistant: a pipeline of six steps, from the high-risk test to the review date.","DPIA for an LLM support assistant · Balázs Csorba",[93,94,95,96,97],"Start from the high-risk test, not from the word AI. Article 35(1) and the WP29 criteria decide, and a feature that reads customer emails and joins them with order data can meet several of them at once.","In Austria, read the DSFA-AV whitelist first. Customer administration can be exempt there, but the DSFA-V blacklist names artificial intelligence, so get a legal view before you rely on the exemption.","The LLM risks are concrete: hallucinated personal data, instructions hidden in a customer’s email, provider logs and transfers outside the EU.","Give every measure an owner and a residual risk. Mask what the model does not need, have a person approve each reply, and take the retention and training terms from the contract, not from a web page.","The AI Act does not replace the DPIA. It brings its own duties, such as telling people they are talking to an AI system, and high-risk rules for listed uses such as credit scoring.",[99,102,105,108,111],{"q":100,"a":101},"Does every customer support chatbot need a DPIA?","No. Article 35(1) GDPR requires one only where processing is likely to result in a high risk, and the WP29 criteria help decide that. A template that fills a reply from one field may meet none of them. An assistant that reads emails, joins them with order data and sends them to an outside provider can meet several, so the assessment is worth doing and writing down.",{"q":103,"a":104},"Is a DPIA mandatory for AI features in Austria?","It can be. Section 2 of the DSFA-V (BGBl. II Nr. 278\u002F2018) requires a DPIA where one of six criteria applies, and criterion Z 4 names artificial intelligence. Processing that the DSFA-AV (BGBl. II Nr. 108\u002F2018) exempts does not need one, and customer administration is on that list. Whether the exemption fits the exact processing is a question for counsel, so get a legal view before you rely on it.",{"q":106,"a":107},"What must a DPIA contain?","Article 35(7) GDPR asks for four things: a systematic description of the processing and its purposes, including any legitimate interest; an assessment of necessity and proportionality; an assessment of the risks to data subjects; and the measures planned to address those risks, including safeguards and security.",{"q":109,"a":110},"When do I have to consult the supervisory authority?","Under Article 36, when the DPIA shows that the processing would still be high risk after the measures you have planned. You consult the supervisory authority before the processing starts.",{"q":112,"a":113},"Does the EU AI Act replace the DPIA?","No. The AI Act sets its own duties, such as telling people that they are talking to an AI system, and high-risk rules for listed uses. The GDPR duty to assess the risk to people’s data still applies alongside it.",[115,118,121,124,127,130,133,136,139],{"id":116,"title":117},"when-required","When a DPIA is required",{"id":119,"title":120},"austria","Austria: the blacklist and the whitelist",{"id":122,"title":123},"example","The worked example: an assistant for a support inbox",{"id":125,"title":126},"systematic-description","Systematic description, necessity and proportionality",{"id":128,"title":129},"risks","Risks to the people who write in",{"id":131,"title":132},"measures","Measures, owners and residual risk",{"id":134,"title":135},"ai-act","How the EU AI Act fits in",{"id":137,"title":138},"first-steps","What I would do first",{"id":140,"title":141},"sources","Sources",[143,147,150,157,160,163,166,191,194,203,204,207,210,213,216,217,220,227,230,231,234,237,240,243,244,250,262,272,282,288,294,295,298,369,372,373,381,384,385,400,401],{"type":144,"content":145},"paragraph",[146],"A support assistant that reads customer emails, looks up the order and drafts a reply sounds like a small feature. For data protection it is not small. The email is free text that can contain anything, the order record is personal data, the model runs at a provider, and the output goes back to a customer. This article works through a data protection impact assessment (DPIA) for exactly that feature – for a made-up shop – and ends with the risk table I would put in front of a data protection officer.",{"type":144,"content":148},[149],"My answer up front: do the assessment before the first live reply. The GDPR requires a DPIA only where processing is likely to result in a high risk, but the WP29 guidance recommends one wherever that is unclear. In Austria, check the national lists first. A whitelist can exempt customer administration, while the blacklist names artificial intelligence, so the way you describe the processing decides which list applies.",{"type":151,"variant":152,"title":153,"body":154},"callout","note","Not legal advice",[155],[156],"This is an engineer’s worked example, not legal advice. The shop, the provider and my reading of the Austrian lists are assumptions for illustration. Check the whitelist question and the transfer mechanism with your data protection officer or a lawyer before you launch.",{"type":158,"level":159,"id":116,"text":117},"heading",2,{"type":144,"content":161},[162],"Article 35(1) GDPR requires a DPIA before processing that is likely to result in a high risk to the rights and freedoms of natural persons, in particular where it uses new technologies. Article 35(3) names three cases where a DPIA is required in particular: a systematic and extensive evaluation of personal aspects based on automated processing, on which decisions are based that significantly affect people; large-scale processing of special categories or criminal data; and systematic monitoring of a publicly accessible area on a large scale. A support assistant fits none of these by itself, so the question becomes the general high-risk test.",{"type":144,"content":164},[165],"The WP29 guidelines WP248 rev.01, adopted on 4 April 2017 and revised on 4 October 2017, turn that test into nine criteria. Where it is not clear whether a DPIA is required, the WP29 recommends carrying one out nonetheless. Four of the nine criteria matter here.",{"type":167,"ordered":168,"items":169},"list",false,[170,176,181,186],[171,175],{"tag":172,"children":173},"strong",[174],"Sensitive data or data of a highly personal nature."," The guidelines name personal documents and emails explicitly as data that can fall under this criterion, not only the Article 9 categories.",[177,180],{"tag":172,"children":178},[179],"Matching or combining datasets."," Support emails and order records are collected for different purposes. Joining them is the point of the feature, and it can go beyond what customers expect.",[182,185],{"tag":172,"children":183},[184],"Innovative use of new technology."," The guidelines say that the use of a new technology can trigger the need for a DPIA, and an LLM feature is new technology for most support teams.",[187,190],{"tag":172,"children":188},[189],"Data processed on a large scale."," This depends on the number of people, the volume and range of data, the duration of processing and its geographic extent. A shop with many customers, long retention and national reach may meet several of these factors.",{"type":144,"content":192},[193],"The guidelines say that a processing operation meeting two criteria would in most cases require a DPIA, and that one criterion can sometimes be enough. On my reading, this feature meets at least three of the four, so the assessment is not a close call. The decision flow below shows the order of questions I use.",{"type":195,"attrs":196,"inner":200,"caption":201},"diagram",{"viewBox":197,"role":198,"aria-labelledby":199},"0 0 720 400","img","d1-dpia-t d1-dpia-d","\u003Ctitle id=\"d1-dpia-t\">DPIA decision flow\u003C\u002Ftitle>\u003Cdesc id=\"d1-dpia-d\">A decision flow. If the processing is not likely to be high risk, or a national exemption applies, the controller documents the reasons. Otherwise it carries out the DPIA under Article 35(7). If the residual risk stays high, it consults the supervisory authority before processing under Article 36. If not, it reviews the assessment whenever the risk changes, under Article 35(11).\u003C\u002Fdesc>\u003Ctext x=\"700\" y=\"22\" text-anchor=\"end\" class=\"d-label\">Read top to bottom\u003C\u002Ftext>\u003Crect x=\"20\" y=\"30\" width=\"300\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"170\" y=\"52\" text-anchor=\"middle\" class=\"d-text\">Likely high risk?\u003C\u002Ftext>\u003Ctext x=\"170\" y=\"70\" text-anchor=\"middle\" class=\"d-small\">Art. 35(1); AT: DSFA-V § 2\u003C\u002Ftext>\u003Cpath d=\"M170 82 V101\" class=\"d-line\" \u002F>\u003Cpath d=\"M170 110 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"180\" y=\"98\" class=\"d-label\">yes\u003C\u002Ftext>\u003Crect x=\"400\" y=\"30\" width=\"300\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"550\" y=\"52\" text-anchor=\"middle\" class=\"d-text\">Document the reasons\u003C\u002Ftext>\u003Ctext x=\"550\" y=\"70\" text-anchor=\"middle\" class=\"d-small\">WP248: justify, record the DPO view\u003C\u002Ftext>\u003Cpath d=\"M320 56 H392\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M400 56 l-9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Ctext x=\"332\" y=\"50\" class=\"d-label\">no\u003C\u002Ftext>\u003Crect x=\"20\" y=\"110\" width=\"300\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"170\" y=\"132\" text-anchor=\"middle\" class=\"d-text\">Exempt by a national list?\u003C\u002Ftext>\u003Ctext x=\"170\" y=\"150\" text-anchor=\"middle\" class=\"d-small\">Art. 35(5); AT: DSFA-AV\u003C\u002Ftext>\u003Cpath d=\"M320 136 H360 V72 H392\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M400 72 l-9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Ctext x=\"332\" y=\"130\" class=\"d-label\">yes\u003C\u002Ftext>\u003Cpath d=\"M170 162 V181\" class=\"d-line\" \u002F>\u003Cpath d=\"M170 190 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"180\" y=\"176\" class=\"d-label\">no\u003C\u002Ftext>\u003Crect x=\"20\" y=\"190\" width=\"300\" height=\"52\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"170\" y=\"212\" text-anchor=\"middle\" class=\"d-text\">Carry out the DPIA\u003C\u002Ftext>\u003Ctext x=\"170\" y=\"230\" text-anchor=\"middle\" class=\"d-small\">Art. 35(7): describe, risks, measures\u003C\u002Ftext>\u003Cpath d=\"M170 242 V261\" class=\"d-line\" \u002F>\u003Cpath d=\"M170 270 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Crect x=\"20\" y=\"270\" width=\"300\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"170\" y=\"292\" text-anchor=\"middle\" class=\"d-text\">Residual high risk?\u003C\u002Ftext>\u003Ctext x=\"170\" y=\"310\" text-anchor=\"middle\" class=\"d-small\">Art. 36: consult before processing\u003C\u002Ftext>\u003Cpath d=\"M320 296 H392\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M400 296 l-9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Ctext x=\"332\" y=\"290\" class=\"d-label\">no\u003C\u002Ftext>\u003Crect x=\"400\" y=\"270\" width=\"300\" height=\"52\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"550\" y=\"292\" text-anchor=\"middle\" class=\"d-text\">Review when the risk changes\u003C\u002Ftext>\u003Ctext x=\"550\" y=\"310\" text-anchor=\"middle\" class=\"d-small\">Art. 35(11): new provider or data\u003C\u002Ftext>\u003Cpath d=\"M170 322 V333\" class=\"d-line\" \u002F>\u003Cpath d=\"M170 342 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"180\" y=\"334\" class=\"d-label\">yes\u003C\u002Ftext>\u003Crect x=\"20\" y=\"342\" width=\"300\" height=\"40\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"170\" y=\"366\" text-anchor=\"middle\" class=\"d-text\">Consult the supervisory authority\u003C\u002Ftext>",[202],"Read top to bottom. The national lists are checked before the DPIA step, and the reasons are documented whenever no DPIA is carried out, as the guidelines ask.",{"type":158,"level":159,"id":119,"text":120},{"type":144,"content":205},[206],"Austria makes the question concrete. Under section 2(1) of the DSFA-V (BGBl. II Nr. 278\u002F2018), a DPIA is required where the processing is lawful under Articles 6, 9 and 10 GDPR and no exemption under the DSFA-AV applies. Section 2(2) lists six criteria, and one is enough. Criterion Z 4 covers processing that uses new or novel technologies and names artificial intelligence explicitly.",{"type":144,"content":208},[209],"Section 2(3) adds a second route: two or more of five criteria trigger a DPIA. They cover large-scale special category data, large-scale criminal data, location data, vulnerable people, and the matching of datasets. The assistant could meet the matching criterion as well.",{"type":144,"content":211},[212],"The whitelist is the twist. The DSFA-AV (BGBl. II Nr. 108\u002F2018) exempts the processing listed in its annex from the DPIA duty under Article 35(1) and (5). Its entry DSFA-A01 covers customer administration, accounting, logistics and bookkeeping. In my reading of the German text, it covers personal data processed in any business relationship with customers and suppliers, which describes a shop’s support mailbox well. The exclusion is aimed at businesses whose activity is processing data about third parties who are not their customers. An email that mentions a gift recipient is not obviously within that, but a reviewer may still ask whether the mailbox holds such data, so the reasoning belongs in the record.",{"type":144,"content":214},[215],"So the honest answer for an Austrian shop is this. The whitelist may cover the basic support mailbox. The assistant is more than that mailbox: it adds a technology the blacklist names, and it sends personal data to a provider outside the shop’s own systems. I would not switch the assessment off on the strength of the whitelist. I would record the reasoning for the exemption, put it to counsel or to the Austrian data protection authority, and run the full analysis anyway, because the risks below apply whichever list is right.",{"type":158,"level":159,"id":122,"text":123},{"type":144,"content":218},[219],"The example shop sells household goods online and receives support emails in one shared inbox. An assistant reads each new email, extracts the order number, calls the order system for the status, items and shipping city, and asks an LLM provider to draft a reply in the customer’s language. A person on the support team edits the draft and sends it. Prompts and drafts are logged for quality review. The provider processes data in the United States. That is an assumption for this example, and you should check your own provider.",{"type":195,"attrs":221,"inner":224,"caption":225},{"viewBox":222,"role":198,"aria-labelledby":223},"0 0 720 260","d2-flow-t d2-flow-d","\u003Ctitle id=\"d2-flow-t\">Data flow of the example assistant\u003C\u002Ftitle>\u003Cdesc id=\"d2-flow-d\">A customer email enters the shared inbox and reaches the assistant, which masks it and looks up the order in the shop’s own systems. Only the prompt crosses the dashed line to the LLM provider outside the EU, and its draft returns to the support team. A person on the team edits and sends the reply, and nothing reaches the customer before that step.\u003C\u002Fdesc>\u003Crect x=\"20\" y=\"40\" width=\"130\" height=\"56\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"85\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">Customer\u003C\u002Ftext>\u003Ctext x=\"85\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">writes in\u003C\u002Ftext>\u003Cpath d=\"M150 68 H178\" class=\"d-line\" \u002F>\u003Cpath d=\"M186 68 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"190\" y=\"40\" width=\"130\" height=\"56\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"255\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">Shared inbox\u003C\u002Ftext>\u003Ctext x=\"255\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">support mail\u003C\u002Ftext>\u003Cpath d=\"M320 68 H348\" class=\"d-line\" \u002F>\u003Cpath d=\"M356 68 l-9 -5 v10 z\" class=\"d-head\" \u002F>\u003Crect x=\"360\" y=\"40\" width=\"150\" height=\"56\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"435\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">Assistant\u003C\u002Ftext>\u003Ctext x=\"435\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">mask, look up order\u003C\u002Ftext>\u003Cpath d=\"M510 68 H538\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M546 68 l-9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Cpath d=\"M528 16 V218\" class=\"d-dash\" \u002F>\u003Ctext x=\"640\" y=\"24\" text-anchor=\"middle\" class=\"d-label\">outside the EU\u003C\u002Ftext>\u003Crect x=\"548\" y=\"40\" width=\"152\" height=\"56\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"624\" y=\"64\" text-anchor=\"middle\" class=\"d-text\">LLM provider\u003C\u002Ftext>\u003Ctext x=\"624\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">drafts the reply\u003C\u002Ftext>\u003Cpath d=\"M624 96 V186\" class=\"d-line\" \u002F>\u003Cpath d=\"M624 194 l-5 -9 h10 z\" class=\"d-head\" \u002F>\u003Crect x=\"548\" y=\"200\" width=\"152\" height=\"52\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"624\" y=\"222\" text-anchor=\"middle\" class=\"d-text\">Support team\u003C\u002Ftext>\u003Ctext x=\"624\" y=\"240\" text-anchor=\"middle\" class=\"d-small\">edits and sends\u003C\u002Ftext>\u003Cpath d=\"M548 226 H158\" class=\"d-line-accent\" \u002F>\u003Cpath d=\"M150 226 l9 -5 v10 z\" class=\"d-head-accent\" \u002F>\u003Ctext x=\"350\" y=\"216\" text-anchor=\"middle\" class=\"d-label\">reply after approval\u003C\u002Ftext>\u003Crect x=\"20\" y=\"200\" width=\"130\" height=\"52\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"85\" y=\"222\" text-anchor=\"middle\" class=\"d-text\">Customer\u003C\u002Ftext>\u003Ctext x=\"85\" y=\"240\" text-anchor=\"middle\" class=\"d-small\">gets the reply\u003C\u002Ftext>\u003Crect x=\"360\" y=\"130\" width=\"150\" height=\"52\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"435\" y=\"152\" text-anchor=\"middle\" class=\"d-text\">Order system\u003C\u002Ftext>\u003Ctext x=\"435\" y=\"170\" text-anchor=\"middle\" class=\"d-small\">status, items, city\u003C\u002Ftext>\u003Cpath d=\"M435 130 V105\" class=\"d-line\" \u002F>\u003Cpath d=\"M435 96 l-5 9 h10 z\" class=\"d-head\" \u002F>\u003Ctext x=\"425\" y=\"118\" text-anchor=\"end\" class=\"d-label\">lookup\u003C\u002Ftext>",[226],"Personal data crosses the boundary twice: the prompt goes out and the draft comes back. A person is the last step before a customer sees anything.",{"type":144,"content":228},[229],"Two design choices shape everything else. The model only drafts. It has no tool that sends mail, changes an order or issues a refund. And the prompt carries the order fields the reply needs, not the whole customer record.",{"type":158,"level":159,"id":125,"text":126},{"type":144,"content":232},[233],"Article 35(7)(a) and (b) GDPR ask for a systematic description of the processing and its purposes, and for an assessment of necessity and proportionality. I keep this in the record of processing that Article 30(1) requires, and I write it as structured data rather than prose, so that it can be compared when the feature changes. A minimal entry for the example looks like this:",{"type":235,"code":236},"code","# one entry per feature: the Article 30 record and the Article 35(7)(a) description\nprocessing: support-email-drafts\npurpose: draft a reply to an order enquiry; a person reviews and sends it\nlegal_basis:\n  - Art. 6(1)(b): answering an enquiry about an existing order\nprompt_fields:\n  - order number, status, items, shipping city\n  - email text with card and bank numbers masked\nnot_in_prompt:\n  - full order history, account notes, marketing profile\nrecipients:\n  - LLM provider as processor (Art. 28), documented instructions only\n  - transfer to the United States: DPF certification or SCCs (Art. 46)\nretention:\n  - provider abuse logs: up to 30 days by default (provider documentation)\n  - own prompt and draft log: \u003CN> days, set by the data protection officer\nreview: new provider, new prompt field or any use of emails for training (Art. 35(11))",{"type":144,"content":238},[239],"Three things follow from the entry. First, answering an enquiry about an existing order rests on Article 6(1)(b), which covers processing necessary for a contract or for steps requested before one. Second, keeping drafts to improve quality is a different purpose. It needs a legitimate interest under Article 6(1)(f), and the balancing test is the real work. The EDPB’s Opinion 28\u002F2024 on AI models sets out a three-step test for legitimate interest that I would apply here: identify a lawful, clearly articulated, real and present interest; check that the processing is necessary for it; then balance it against the rights of the people concerned, taking account of what they reasonably expect. Third, the privacy notice must say when data goes to a third country and which safeguard applies, as Article 13(1)(f) requires.",{"type":144,"content":241},[242],"Two special cases need their own line in the description. First, emails can contain health or other special-category data, and an order can reveal it indirectly. The Court of Justice held in case C-184\u002F20 that processing which reveals sensitive information indirectly, through deduction or cross-referencing, falls under Article 9(1). An order for a product that reveals a health condition can be enough, so the prompt should not carry product history beyond the current order. Second, Article 22(1) protects people against decisions based solely on automated processing that significantly affect them. A refund decided by the model would be a candidate. In this design a person reads every reply before it goes out, and the model decides nothing.",{"type":158,"level":159,"id":128,"text":129},{"type":144,"content":245},[246,249],{"tag":172,"children":247},[248],"Hallucinated personal data."," A model can state a delivery date, a name or an address that is not in the order record. The EDPB’s ChatGPT Taskforce report notes that the purpose of training is not necessarily accurate information, and that end users are likely to take the outputs as factually accurate. The accuracy principle in Article 5(1)(d) still applies. In the example the defence is structural: personal facts in a draft come only from the order record in the prompt, and a person checks the reply before it goes out.",{"type":144,"content":251},[252,255,256,261],{"tag":172,"children":253},[254],"Prompt injection through the email itself."," The email body is untrusted input. OWASP describes indirect prompt injection as the case where an LLM accepts input from external sources, such as websites or files. A customer, or someone who forwards a message, can include an instruction to ignore the rules and list other orders from the same city. OWASP’s prevention list includes segregating and identifying external content, enforcing least privilege, and requiring human approval for high-risk actions. Here the model has no access to other customers’ records at all, and the person handling the case sees the email and the draft side by side. For the wider patterns, see my note on ",{"tag":257,"to":258,"children":259},"link","\u002Fblog\u002Fprompt-injection-lethal-trifecta-patterns",[260],"prompt injection defence",".",{"type":144,"content":263},[264,267,268,261],{"tag":172,"children":265},[266],"Leakage through the output."," OWASP’s entry on sensitive information disclosure names personal identifiable information and health records among the data that can leak, and it recommends strict access controls based on least privilege. The worst case is a reply to customer A that contains customer B’s order, which is a personal data breach. Article 32(1)(b) asks for the ongoing confidentiality and integrity of processing systems and services. Article 33 expects notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, as recital 85 explains. Masking before the call is covered in my note on ",{"tag":257,"to":269,"children":270},"\u002Fblog\u002Fpii-redaction-llm-pipelines",[271],"PII redaction in LLM pipelines",{"type":144,"content":273},[274,277,278,261],{"tag":172,"children":275},[276],"Retention at the provider."," As of October 2026, the OpenAI data controls page says that abuse monitoring logs are kept for up to 30 days by default, and that Zero Data Retention needs prior approval from OpenAI. The same page says that, since March 2023, API data is not used for training unless the customer opts in. These are provider defaults that can change, so the contract, not the web page, has to say which applies. Article 28(3)(a) requires a processor to act only on documented instructions, including for transfers, and the EDPB’s Guidelines 07\u002F2020 say a processor must not process data otherwise than on the controller’s instructions. For the wider options, see my note on ",{"tag":257,"to":279,"children":280},"\u002Fblog\u002Fgdpr-llm-api-eu-data-residency",[281],"GDPR and LLM API data residency",{"type":144,"content":283},[284,287],{"tag":172,"children":285},[286],"Transfers."," The Commission’s adequacy decision 2023\u002F1795 of 10 July 2023 finds that the United States ensures an essentially equivalent level of protection for organisations certified under the EU–US Data Privacy Framework. If the provider is not certified, standard contractual clauses adopted by the Commission under Article 46 are the fallback, as recital 108 describes. The adequacy decision can be suspended, amended or repealed if protection is no longer ensured, so the clauses should be ready before you need them.",{"type":144,"content":289},[290,293],{"tag":172,"children":291},[292],"Training on customer emails."," The EDPB’s Opinion 28\u002F2024 says that whether an AI model trained on personal data is anonymous must be assessed case by case, because personal data can sometimes be extracted from it, directly or through queries. It also says a model developed on unlawfully processed personal data can affect the lawfulness of its later deployment, unless the model is properly anonymised. The feature should therefore not use customer emails for fine-tuning. Any plan to do so is a new purpose that needs its own assessment.",{"type":158,"level":159,"id":131,"text":132},{"type":144,"content":296},[297],"The table lists each risk with my before and after ratings and the measure that changes the rating. Owners are roles rather than names, so the register survives staff changes. The ratings are my judgement for this example, not measured figures.",{"type":299,"head":300,"rows":309},"table",[301,303,305,307],[302],"Risk and basis",[304],"Before",[306],"Measure and owner",[308],"After",[310,319,327,336,345,354,361],[311,313,315,317],[312],"Hallucinated personal data in a draft (Art. 5(1)(d))",[314],"High likelihood, medium impact",[316],"Facts only from the order record in the prompt; a person approves every reply (support lead, ML engineer)",[318],"Low",[320,322,324,326],[321],"Customer B’s data in customer A’s reply (Art. 32, Art. 33)",[323],"Medium likelihood, high impact",[325],"Lookup scoped to the verified sender; cross-customer leak test before every release (backend lead)",[318],[328,330,332,334],[329],"Instructions hidden in the email (OWASP LLM01)",[331],"High likelihood, high impact",[333],"No tools that send mail or change orders; email text handled as data; red-team set run before release (security engineer)",[335],"Medium, caught at review",[337,339,341,343],[338],"Provider logs and retention (Art. 28, Art. 5(1)(e))",[340],"Likely by default, medium impact",[342],"Processor terms with documented instructions; written retention period; Zero Data Retention only if approved (legal and procurement)",[344],"Low to medium",[346,348,350,352],[347],"Transfer to a provider outside the EU (Art. 13(1)(f), Art. 46)",[349],"Certain, medium impact",[351],"Check DPF certification or sign SCCs; transfer statement in the privacy notice (data protection officer)",[353],"Low, reviewed when the adequacy decision changes",[355,357,358,360],[356],"Special-category inference from order history (Art. 9(1))",[323],[359],"Only the current order goes into the prompt; product history that could reveal health is excluded (support lead)",[318],[362,364,366,368],[363],"Emails used for training (Art. 6(1)(f), Opinion 28\u002F2024)",[365],"Low likelihood, high impact",[367],"Contract excludes training on API data; no fine-tuning on emails without a new assessment (product owner)",[318],{"type":144,"content":370},[371],"No row stays high after the measures, so on these assumptions prior consultation under Article 36 is not needed. Two rows keep a residual risk above low: prompt injection and retention at the provider. I would accept and record both, with the data protection officer’s view.",{"type":158,"level":159,"id":134,"text":135},{"type":144,"content":374},[375,376,380],"The AI Act does not replace the DPIA, and the two run in parallel. The Regulation applies from 2 August 2026 under Article 113. For a support assistant, the transparency duty I would check first is the one recital 132 describes: people should be notified that they are interacting with an AI system, unless that is obvious to a reasonably well-informed person. For the developer side of those duties, see my ",{"tag":257,"to":377,"children":378},"\u002Fblog\u002Feu-ai-act-article-50-developer-checklist",[379],"Article 50 checklist",". Recital 20 also stresses AI literacy for providers, deployers and affected persons, which is a second thing to plan for.",{"type":144,"content":382},[383],"High-risk obligations are a different question. Annex III point 5(b) lists AI systems used to evaluate the creditworthiness of natural persons or to establish a credit score, with an exception for fraud detection. A support assistant is not on that list. Regulation (EU) 2026\u002F1744 of 8 July 2026, the Digital Omnibus on AI, moves the application dates of the Annex III high-risk rules to 2 December 2027 and those for Annex I systems to 2 August 2028. Its recital 40 keeps 2 August 2026 as the general date of application. The amendment did not postpone the Article 50 transparency duties: they apply from 2 August 2026.",{"type":158,"level":159,"id":137,"text":138},{"type":167,"ordered":386,"items":387},true,[388,390,392,394,396,398],[389],"Write the purpose, the prompt fields and the retention in one record, and send it to the data protection officer before the first pilot.",[391],"Put the whitelist reasoning in writing, and get counsel’s view on DSFA-A01 and on third-party data in forwarded emails.",[393],"Limit the prompt to the order fields and a masked email, and log only what the quality review needs.",[395],"Build a red-team set from real emails, including injected instructions, and make it part of the release check.",[397],"Sign processor terms with the provider, and take the retention and training settings from the contract, not from a web page.",[399],"Set the review triggers in the record: a new provider, a new prompt field, and any use of emails for training.",{"type":158,"level":159,"id":140,"text":141},{"type":167,"ordered":386,"items":402},[403,407,410,413,416,419,422,425,428,431,434,437,440,443,446,449],[404],{"tag":405,"href":26,"children":406},"a",[38],[408],{"tag":405,"href":29,"children":409},[40],[411],{"tag":405,"href":43,"children":412},[42],[414],{"tag":405,"href":46,"children":415},[45],[417],{"tag":405,"href":49,"children":418},[48],[420],{"tag":405,"href":52,"children":421},[51],[423],{"tag":405,"href":55,"children":424},[54],[426],{"tag":405,"href":58,"children":427},[57],[429],{"tag":405,"href":61,"children":430},[60],[432],{"tag":405,"href":32,"children":433},[63],[435],{"tag":405,"href":66,"children":436},[65],[438],{"tag":405,"href":69,"children":439},[68],[441],{"tag":405,"href":72,"children":442},[71],[444],{"tag":405,"href":75,"children":445},[74],[447],{"tag":405,"href":35,"children":448},[77],[450],{"tag":405,"href":80,"children":451},[79],[453,554,628,710],{"slug":454,"published":455,"minutes":456,"category":7,"tags":457,"keywords":463,"about":472,"sources":482,"cover":548,"og":549,"expertise":83,"locales":550,"lang":85,"title":551,"description":552,"coverAlt":553},"coding-agent-secrets-hygiene","2026-10-08",11,[458,459,460,461,462],"AI agents","Secrets management","Claude Code","Pre-commit scanning","CI security",[464,465,466,467,468,469,470,471],"coding agent secrets","keep secrets away from AI agents","Claude Code deny read .env","gitleaks pre-commit hook","GitHub push protection secrets","OIDC GitHub Actions short-lived credentials","rotate a leaked API key","MCP server token scope",[473,476,479],{"name":474,"url":475},"Principle of least privilege","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrinciple_of_least_privilege",{"name":477,"url":478},"Model Context Protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_Context_Protocol",{"name":480,"url":481},"Git","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGit",[483,486,489,492,495,498,501,504,507,510,513,516,519,522,525,528,531,534,537,540,543,545],{"title":484,"url":485},"Claude Code: permissions","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fpermissions",{"title":487,"url":488},"Claude Code: sandboxed Bash","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsandboxing",{"title":490,"url":491},"Claude Code: hooks","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fhooks",{"title":493,"url":494},"Claude Code: data usage","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fdata-usage",{"title":496,"url":497},"Claude Code: settings","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fsettings",{"title":499,"url":500},"Claude Code: MCP servers","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fmcp",{"title":502,"url":503},"Codex: configuration reference","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fconfig-reference",{"title":505,"url":506},"Codex: agent approvals and security","https:\u002F\u002Flearn.chatgpt.com\u002Fdocs\u002Fagent-approvals-security",{"title":508,"url":509},"Codex: advanced configuration","https:\u002F\u002Flearn.chatgpt.com\u002Fdocs\u002Fconfig-file\u002Fconfig-advanced",{"title":511,"url":512},"GitHub: about push protection","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcode-security\u002Fsecret-scanning\u002Fintroduction\u002Fabout-push-protection",{"title":514,"url":515},"GitHub: security hardening with OIDC","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-for-github-actions\u002Fsecurity-hardening-your-deployments\u002Fabout-security-hardening-with-openid-connect",{"title":517,"url":518},"GitHub: OpenID Connect reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Freference\u002Fsecurity\u002Foidc",{"title":520,"url":521},"GitHub: using secrets in Actions","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-guides\u002Fusing-secrets-in-github-actions",{"title":523,"url":524},"GitHub: secure use reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Factions\u002Fsecurity-for-github-actions\u002Fsecurity-guides\u002Fsecurity-hardening-for-github-actions",{"title":526,"url":527},"GitHub: removing sensitive data","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fauthentication\u002Fkeeping-your-account-and-data-secure\u002Fremoving-sensitive-data-from-a-repository",{"title":529,"url":530},"gitleaks: README and latest release","https:\u002F\u002Fgithub.com\u002Fgitleaks\u002Fgitleaks",{"title":532,"url":533},"TruffleHog: README","https:\u002F\u002Fgithub.com\u002Ftrufflesecurity\u002Ftrufflehog",{"title":535,"url":536},"detect-secrets: README and latest release","https:\u002F\u002Fgithub.com\u002FYelp\u002Fdetect-secrets",{"title":538,"url":539},"Model Context Protocol: security best practices","https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002F2025-06-18\u002Fbasic\u002Fsecurity_best_practices",{"title":541,"url":542},"OWASP: Secrets Management Cheat Sheet","https:\u002F\u002Fcheatsheetseries.owasp.org\u002Fcheatsheets\u002FSecrets_Management_Cheat_Sheet.html",{"title":544,"url":66},"OWASP: LLM02 sensitive information disclosure",{"title":546,"url":547},"Git: git-add documentation","https:\u002F\u002Fgit-scm.com\u002Fdocs\u002Fgit-add","\u002Fimages\u002Fblog\u002Fcoding-agent-secrets-hygiene\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fcoding-agent-secrets-hygiene\u002Fog.jpg",[85,86,87],"Coding agents and secrets: keep keys out of context, logs and commits","How secrets leak through coding agents, and the controls that stop them: deny reads, a sandbox, pre-commit scans, push protection, OIDC and rotation.","Cover art for coding agents and secrets: a shield of six layered controls, from deny rules and a sandbox to rotation.",{"slug":555,"published":556,"minutes":456,"category":7,"tags":557,"keywords":562,"about":571,"sources":583,"cover":622,"og":623,"expertise":83,"locales":624,"lang":85,"title":625,"description":626,"coverAlt":627},"works-council-ai-tools-austria-germany","2026-10-02",[558,559,560,10,561],"Works council","AI coding tools","Employee monitoring","Co-determination",[563,564,565,566,567,568,569,570],"works council AI tools","AI coding tools works council","Betriebsrat KI Mitbestimmung","§ 87 BetrVG Überwachung","§ 96 ArbVG Kontrollmaßnahmen","AI usage logs employee monitoring","works agreement for AI tools","GDPR Article 88 employee data",[572,574,577,580],{"name":25,"url":573},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2016\u002F679\u002Foj\u002Feng",{"name":575,"url":576},"EU Artificial Intelligence Act (Regulation (EU) 2024\u002F1689)","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj\u002Feng",{"name":578,"url":579},"Arbeitsverfassungsgesetz (Austrian Labour Constitution Act)","https:\u002F\u002Fwww.ris.bka.gv.at\u002FGeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10008329",{"name":581,"url":582},"Betriebsverfassungsgesetz (German Works Constitution Act), § 87","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbetrvg\u002F__87.html",[584,586,588,591,594,595,598,599,601,604,607,610,613,616,619],{"title":585,"url":579},"Arbeitsverfassungsgesetz (ArbVG), §§ 96 and 96a, consolidated text of 10 October 2026, RIS",{"title":587,"url":582},"Betriebsverfassungsgesetz (BetrVG), § 87, gesetze-im-internet.de",{"title":589,"url":590},"Betriebsverfassungsgesetz (BetrVG), § 90, gesetze-im-internet.de","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbetrvg\u002F__90.html",{"title":592,"url":593},"Bundesdatenschutzgesetz (BDSG), § 26, gesetze-im-internet.de","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fbdsg_2018\u002F__26.html",{"title":38,"url":573},{"title":596,"url":597},"GDPR Article 5(1)(e), storage limitation, gdpr-info.eu","https:\u002F\u002Fgdpr-info.eu\u002Fart-5-gdpr\u002F",{"title":77,"url":576},{"title":600,"url":80},"Regulation (EU) 2026\u002F1744, EUR-Lex",{"title":602,"url":603},"AI Act Article 26, AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F26\u002F",{"title":605,"url":606},"AI Act Annex III, AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Fannex\u002F3\u002F",{"title":608,"url":609},"BAG, 1 ABR 16\u002F23 (July 2024), headset system, gesetze.co","https:\u002F\u002Fgesetze.co\u002Furteile\u002F1_ABR_16-23",{"title":611,"url":612},"ArbG Hamburg, 24 BVGa 1\u002F24: law-firm summary by CMS","https:\u002F\u002Fcms.law\u002Fde\u002Fdeu\u002Flegal-updates\u002Fkein-mitbestimmungsrecht-des-betriebsrats-bei-chatgpt-co",{"title":614,"url":615},"ArbG Hamburg, 24 BVGa 1\u002F24: law-firm summary by Gleiss Lutz","https:\u002F\u002Fwww.gleisslutz.com\u002Fde\u002Fknow-how\u002Farbeitsgericht-hamburg-zu-chatgpt-kein-mitbestimmungsrecht-des-betriebsrats",{"title":617,"url":618},"Claude Code documentation: monitoring usage","https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fmonitoring-usage",{"title":620,"url":621},"GitHub Docs: Copilot metrics data reference","https:\u002F\u002Fdocs.github.com\u002Fen\u002Fcopilot\u002Freference\u002Fmetrics-data","\u002Fimages\u002Fblog\u002Fworks-council-ai-tools-austria-germany\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fworks-council-ai-tools-austria-germany\u002Fog.jpg",[85,86,87],"AI coding tools and the works council: when usage logs count as monitoring","Usage logs can make an AI coding tool a monitoring system. What Austria (§ 96 ArbVG) and Germany (§ 87 BetrVG) require, and what to agree before rollout.","Cover art for works councils and AI tools: usage logs pass a consent gate before any developer seat is switched on.",{"slug":629,"published":630,"minutes":6,"category":7,"tags":631,"keywords":636,"about":647,"sources":657,"cover":704,"og":705,"expertise":83,"locales":706,"lang":85,"title":707,"description":708,"coverAlt":709},"eu-ai-act-gpai-high-risk-2026","2026-09-24",[632,633,634,635],"EU AI Act","GPAI","High-risk AI","AI compliance",[637,638,639,640,641,642,643,644,645,646],"EU AI Act high-risk deadline","AI Act digital omnibus","AI Act GPAI obligations","AI Act provider vs deployer","EU AI Act 2 December 2027","GPAI code of practice","AI literacy Article 4","AI Act compliance checklist","AI Act OpenAI API provider deployer","AI Act mid-size company",[648,651,654],{"name":649,"url":650},"Artificial Intelligence Act","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FArtificial_Intelligence_Act",{"name":652,"url":653},"General-purpose artificial intelligence","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FFoundation_model",{"name":655,"url":656},"European Commission","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FEuropean_Commission",[658,659,660,663,666,669,672,675,678,681,683,686,689,692,695,698,701],{"title":77,"url":35},{"title":79,"url":80},{"title":661,"url":662},"AI Act Explorer: Digital Omnibus on AI, full amending text","https:\u002F\u002Fartificialintelligenceact.eu\u002Fai-act-explorer\u002Fdigital-omnibus\u002F",{"title":664,"url":665},"European Commission: AI Act regulatory framework and timeline","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai",{"title":667,"url":668},"European Commission: Guidelines for providers of general-purpose AI models","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fguidelines-gpai-providers",{"title":670,"url":671},"European Commission: Q&A on the guidelines for GPAI providers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fguidelines-obligations-general-purpose-ai-providers",{"title":673,"url":674},"European Commission: The General-Purpose AI Code of Practice","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcontents-code-gpai",{"title":676,"url":677},"European Commission: AI literacy Questions and Answers","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffaqs\u002Fai-literacy-questions-answers",{"title":679,"url":680},"AI Act Article 25: Responsibilities along the AI value chain","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F25\u002F",{"title":682,"url":603},"AI Act Article 26: Obligations of deployers of high-risk AI systems",{"title":684,"url":685},"AI Act Article 27: Fundamental rights impact assessment","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F27\u002F",{"title":687,"url":688},"AI Act Article 53: Obligations for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F53\u002F",{"title":690,"url":691},"AI Act Article 99: Penalties","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F99\u002F",{"title":693,"url":694},"AI Act Article 101: Fines for providers of general-purpose AI models","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F101\u002F",{"title":696,"url":697},"Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines (27 May 2026)","https:\u002F\u002Fwww.gibsondunn.com\u002Feu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes\u002F",{"title":699,"url":700},"Orrick: EU AI Act Update, Digital Omnibus finalizes 8 compliance changes (29 July 2026)","https:\u002F\u002Fwww.orrick.com\u002Fen\u002FInsights\u002F2026\u002F07\u002FEU-AI-Act-Update-Digital-Omnibus-Finalizes-8-Compliance-Changes",{"title":702,"url":703},"K&L Gates: EU Digital Omnibus on AI enters into force (31 July 2026)","https:\u002F\u002Fwww.klgates.com\u002FEU-Digital-Omnibus-on-AI-Enters-Into-Force-7-31-2026","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fcover.webp","\u002Fimages\u002Fblog\u002Feu-ai-act-gpai-high-risk-2026\u002Fog.jpg",[85,86,87],"EU AI Act beyond Article 50: GPAI, high-risk dates and what to do now","The AI Act after the Digital Omnibus: GPAI duties, high-risk dates (2 Dec 2027 and 2 Aug 2028), provider vs deployer on OpenAI and Anthropic APIs, AI literacy.","Diagram: the AI Act timeline from February 2025 to August 2028, fanning out into GPAI duties, high-risk systems, provider and deployer roles and AI literacy.",{"slug":711,"published":712,"minutes":6,"category":7,"tags":713,"keywords":719,"about":728,"sources":735,"cover":750,"og":751,"expertise":83,"locales":752,"lang":85,"title":753,"description":754,"coverAlt":755},"eu-ai-act-article-50-developer-checklist","2026-09-22",[632,714,715,716,717,718],"Article 50","AI transparency","Digital Omnibus","AI literacy","Compliance",[632,720,721,722,723,724,725,726,643,727],"EU AI Act developers","Article 50 AI Act","AI transparency obligations","AI Act chatbot disclosure","Digital Omnibus AI Act","AI Act Article 50(2) watermarking","AI Act deepfake labelling","does the AI Act apply to my app",[729,730,732],{"name":649,"url":650},{"name":731,"url":80},"Regulation (EU) 2026\u002F1744",{"name":733,"url":734},"AI Act Explorer","https:\u002F\u002Fartificialintelligenceact.eu\u002Fai-act-explorer\u002F",[736,739,742,745,747],{"title":737,"url":738},"Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F50\u002F",{"title":740,"url":741},"Regulation (EU) 2026\u002F1744 (Digital Omnibus on AI), Official Journal, 24 Jul 2026","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj\u002Feng",{"title":743,"url":744},"Faegre Drinker: Commission confirms Transparency Code of Practice as adequate and publishes final Article 50 Guidelines (30 Jul 2026)","https:\u002F\u002Fwww.faegredrinker.com\u002Fen\u002Finsights\u002Fpublications\u002F2026\u002F7\u002Feu-ai-act-commission-confirms-transparency-code-of-practice-as-adequate-and-publishes-final-version-of-its-guidelines-on-transparency-obligations",{"title":746,"url":697},"Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines and other key changes (27 May 2026)",{"title":748,"url":749},"RTR KI-Servicestelle: AI Act (Austria)","https:\u002F\u002Fwww.rtr.at\u002Frtr\u002Fservice\u002Fki-servicestelle\u002Fai-act\u002F","\u002Fimages\u002Fblog\u002Feu-ai-act-article-50-developer-checklist\u002Fcover.webp","\u002Fimages\u002Fblog\u002Feu-ai-act-article-50-developer-checklist\u002Fog.jpg",[85,86,87],"EU AI Act Article 50: what developers must do from 2 August 2026","EU AI Act Article 50 transparency duties for developers: AI interaction disclosure, machine-readable marking, deepfakes, provider versus deployer and a checklist.","A six-step timeline from February 2025 to August 2028 covering the AI Act milestones, with the Article 50 step in August 2026 highlighted.",1791636875220]