AI and GDPR: Do we really need a second register?

No, the AI Act does not mandate a single "AI register" for all organizations. But simply adding an "AI" line to the GDPR register is also insufficient. The right approach lies in one formula: a common framework, separate documents.

Since generative AI tools have become commonplace in the workplace, DPOs, lawyers, and compliance officers have been asking the same question: Does the processing register maintained under the GDPR already cover AI? Or is it necessary to create a separate register dedicated to the European regulation on AI (RIA, or AI Act)?

The question is legitimate, as the two texts intersect without being identical. This article explains what each requires, where they converge, and how to organize an inventory that serves both without duplication.

Two texts, two objects

The GDPR and the AI Act do not look at the same thing. The former starts with the data, the latter starts with the tool.

GDPRAI Act (RIA)
What he framesThe processing of personal dataGeneral purpose AI systems and AI models
Inventory unitA treatment (a purpose)An AI system for a given use
What determines the obligationsThe purpose, the legal basis, the sensitivity of the dataThe level of risk associated with the use and the role of the organization (supplier, deployer, importer, distributor)
Central documentThe register of processing activities (Article 30)No general register: documentation that varies according to role and risk

A direct consequence of this is that the same tool can be absent from the GDPR register and yet subject to the AI Act. This is the case for an AI system that does not process any personal data, for example, a predictive maintenance model using sensor data. Conversely, a very traditional processing of personal data does not fall under the AI Act if it does not involve any AI system.

The key point is this: the RIA does not create a single AI register applicable to all structures. Its documentation requirements depend on who you are in relation to the system, and what you do with it.

What the AI Act really requires to be documented

The AI Act reasons by role and by risk level. Most companies that buy Copilot, ChatGPT Enterprise, or "augmented" HR software are deployers : they use a system under their authority, without having developed it.

SituationWhat the AI Act expectsApplicable since
Any organization that uses AITrain and raise awareness among staff (AI proficiency, Article 4); verify that no use falls under prohibited practices (Article 5)2th February 2025
Uses subject to transparency (chatbot, generated content, emotion recognition)Inform the persons concerned (Article 50)August 2, 2026
Deployer of a high-risk system (Annex III: recruitment, credit, education, access to essential services…)Use the system in accordance with its instructions, ensure human supervision, keep logs for at least six months, inform employees (Article 26)2th December 2027
Provider of a high-risk systemTechnical documentation, risk management system, conformity assessment, registration in the European database2th December 2027

The high-risk timetable shifted this summer. Regulation (EU) 2026/1744, known as the "Digital AI Omnibus Regulation," which entered into force on July 27, 2026, postponed the obligations for high-risk systems listed in Annex III from August 2, 2026, to December 2, 2027. However, the obligations regarding AI control, prohibition, and transparency remain unchanged.

None of these lines mention a "register." But all assume knowing which AI systems are running within the organization, what they are used for, and what their level of risk is. Without an inventory, it's impossible to answer these questions.

The meeting point: high-risk AI that processes personal data

It is in this case that the two texts fit together most closely. A candidate screening tool is a prime example: it is a high-risk system within the meaning of Annex III, and it inherently processes personal data.

The deployer must then carry out five interconnected actions:

  1. Register the processing in the GDPR register. The use of the tool is linked to an existing process (recruitment) or creates a new one.
  2. Conduct a data protection impact assessment (DPIA). Article 35 of the GDPR requires it as soon as the processing presents a high risk, which is very likely here.
  3. Use the information provided with the system. The AI Act requires the supplier to provide a user guide, and the deployer must use it, in particular to feed into its AIPD (section 26).
  4. Keep the newspapers under your control. Automatically generated logs must be kept for at least six months, unless otherwise provided by Union or national law.
  5. Analyze the impact on fundamental rights, if applicable. This analysis (Article 27) does not apply to all deployments: it is mandatory for public bodies, private entities providing a public service, and for certain uses such as creditworthiness assessments or pricing in life and health insurance. The AI Act stipulates that it can supplement the DPIA already carried out.

The link between the two texts is therefore explicit: the DPIA remains a GDPR document, but it relies on information required by the AI Act. Governing one without the other is to do the same work twice, or only half the job.

Best practice: a common map, separate documents

Rather than a separate, second register, the most robust method is to maintain a single map of AI uses, which then informs each regulatory document. The inventory is shared; the obligations remain separate.

For each use of AI, identify:

  • the system used and its supplier;
  • the intended use, described concretely ("pre-selection of CVs for technician positions", not "HR");
  • your role under the AI Act (deployer in the vast majority of cases, provider if you develop or substantially modify the system);
  • its level of risk (prohibited, high risk, transparency, minimal);
  • the planned human supervision and log management.

If personal data is processed, add:

  • the linking of the use to the processing concerned in the GDPR register;
  • the purposes, categories of data, persons concerned and actors (subcontractors, recipients);
  • the link to the DPIA and, if necessary, to the fundamental rights impact assessment.

In practice, this can take the form of a simple spreadsheet, with one row per use case and columns that link to the GDPR register and the AI Act documentation. The important thing is not the tool itself, but the discipline: every new use case must be reviewed on this form before being deployed.

Two common mistakes should be avoided. The first is to inventory the tools (“we have Copilot”) instead of their uses: the same tool can be used to write emails, which poses minimal risk, and to evaluate employees, which can pose high risk. The second is to lump everything together under the GDPR register and forget about AI systems that do not process any personal data.

The five-question test

To determine if your mapping is sound, take a random use case of AI in your organization and answer these five questions:

  1. What AI system is being used?
  2. For what purpose?
  3. With what data?
  4. Under what role under the AI Act?
  5. What level of risk is involved?

If even one answer is missing, your map needs updating. And if you can't even think of a use case, then the inventory still needs to be done.

In Summary

Should a second register be created? Not in the sense of a mandatory regulatory document: the AI Act doesn't require one for everyone. But an inventory of AI uses is necessary, distinct from the GDPR register in its purpose, and linked to it as soon as personal data is involved. Postponing the high-risk threshold until December 2027 allows time to properly develop it, provided we start now: AI governance and transparency are already in effect.

sources: Regulation (EU) 2024/1689 on artificial intelligence (EUR-Lex) ; The new timetable for the AI Act following the AI ​​omnibus (donneespersonnelles.fr) ; the register of processing activities (CNIL).

To learn more: our article on the Claude's security and compliance in business (GDPR, AI Act and governance) apply these principles to a concrete tool.

Back to top
The entire NextStart.AI libraryEight consulting missions, seven pillars, around twenty formats, fifteen professions, five tools
Nine detailed customer case studiesLarge groups, public agencies and networks: from acculturation to production

Insurance and social protection

Health and life sciences

Public sector and research

The NextStart.AI collectiveConsultants, trainers and industry experts: more than 4,850 professionals trained since 2023
All free resourcesDiagnostics, comparison tool, Finders, charter template, Word templates and industry-specific kits
The NextStart.AI blogComparisons of tools, practices, agents, governance: analyses and feedback from the field
Let's talk about your AI projectResponse within 24 business hours, written quote after initial discussion
AI agents in businessUnderstanding, choosing the tool, training the teams, deploying
Delegate entire tasksClaude Cowork, Copilot Cowork, ChatGPT Work, Vibe Work