In our first episode of (Medical) Crimes and (Data) Misdemeanours, Marc Dautlich and Alex Denoon write to the European Commission’s AI Act Service Desk.
Any High-Risk AI System (and these are the most interesting AI Systems and the focus of the EU AI Act) must be the subject of a Declaration of Conformity prepared by the “provider” (the entity with primary regulatory responsibility for the AI System). This is a living document that confirms that the System (for example, a medical device that integrates some AI) complies with the AI Act (and any other applicable legislation). For this podcast, the relevant provision is Annex V, point 5. The DoC must include a statement that the AI System “complies with GDPR”. Sounds easy, but what does it mean in practice?
Note: All information was correct at the time of recording.

/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2025-09-29-13-48-10-128-68da8e1af6347a2c4b96de4e.png)
/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2026-08-05-08-40-27-259-6a72f6fbc042009cf382fc1b.png)
/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/60f148b6e5416b0cfcadea94/2024-03-04-12-09-13-241-65e5b9e9047da683cd0a078c.png)
/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2024-08-23-11-31-07-354-66c872fb971eecc249d83d40.png)