Blog

Regulatory analysis of the AI Act and the GDPR for SMEs

Financial services: high risk is in your business, but narrower than you'd think

Annex III.5 reaches creditworthiness assessment and life and health insurance pricing. Three carve-outs in the literal wording itself — natural persons only, and fraud detection expressly excluded — leave out much of what is feared.

When FRIA and DPIA overlap: Article 27(4) lets you reuse, not skip one

The text lets the deployer cross-reference the relevant sections of the DPIA, or include parts of it, in the fundamental rights assessment. Reusing is not skipping — and before you get there, it's worth checking whether the FRIA even applies to you, because its list of subjects is short.

Advisory firms and law practices: the Annex III point you fear isn't about you

Law firms look at Annex III.8 and see their own name in it. The literal text says something else: it covers systems used by a judicial authority. The only high risk a professional firm is likely to have sits in the software it uses to hire.

What you can ask your tax advisor about AI — and what's not in their power to give you

For most Spanish SMEs, the tax advisor is the first place they ask. Some things it handles well, others depend on information only you have, and one thing no outsider can take on.

AI in logistics and transport: telematics, fatigue and the two boundaries you need to know

Routes, warehouse, ETA, telematics: the technological core of a logistics operator is minimal risk under the AI Act. The two boundaries that do need watching — the employment use of telematics and the fatigue camera — each have their own pathway, timeline and nuance.

The Digital Omnibus is now in force: what changes in the AI Act and what stays the same

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July and has been in force since the 27th. It defers the high-risk obligation dates against the 2024 calendar — December 2027 and August 2028 — and leaves the Article 50 transparency ones untouched, still due on 2 August 2026.

Your company's high risk probably isn't in your business: it's in HR

Almost everyone looks for high risk in the AI they use to produce. Annex III of the AI Act puts it somewhere else: in the systems that select staff and evaluate performance. And HR bought those, not operations.

How much does it cost to comply with the AI Act? The right question is what determines the cost

It isn't determined by company size or turnover. Three things determine it: how many AI systems you have, what each one's classification requires, and how much of that is already documented.

The AI Act doesn't require you to keep an inventory. It's the precondition for almost everything that does

The word "inventory" doesn't appear once in the Regulation. And yet every obligation on deployers is written per system — none of them can be applied to a fleet nobody knows about.

The two new Article 5 prohibitions aren't 'category 9'

The Digital Omnibus added two prohibited practices concerning non-consensual intimate images and child sexual abuse material. They aren't appended at the end of the list: they're inserted as points (ba) and (bb), and their internal numbering isn't the Regulation's.