Blog

Regulatory analysis of the AI Act and the GDPR for SMEs

When an agent chains actions, who's responsible? Article 26(2) answers with three words

The AI Act requires assigning human oversight to people with the necessary competence, training and authority. The third is the one that gets skipped, and it's the only one that matters once the system has already acted.

AI literacy: the free resources AESIA promotes, and how to turn them into evidence

Meeting Article 4 doesn't require buying expensive training. It requires training that's adequate to the context and, above all, demonstrable. A practical walkthrough: choosing a resource, adapting it to how your company actually uses AI, and keeping the record someone will one day ask for.

An agent with broad permissions can drift outside its intended purpose without anyone deciding it should

Article 26(1) requires adopting technical and organisational measures to use the system in accordance with its instructions. With a system that suggests, the person who decides upholds that. With one that acts, the permissions do.

Biometrics at work: verification isn't identification, and the difference changes everything

Clocking in with a fingerprint, opening doors with your face: workplace biometrics is best analysed through one distinction that orders everything else — one-to-one verification versus one-to-many identification — and a proportionality test the Spanish Data Protection Agency (AEPD) applies with growing rigour.

AI agents: what to log, and why Article 22 GDPR almost never applies

An agent that carries out actions leaves a different trail from a system that only suggests. Record-keeping under Article 26(6) of the AI Act and the right under Article 22 of the GDPR are two different things, and the second has a threshold that most actions never reach.

The AI inventory in a spreadsheet: why it stops working, and it's not about the number of rows

A spreadsheet works for making the list. The problem isn't making it: it's keeping it up to date. And the way it fails gives no warning — an outdated row looks exactly like a correct one.

High risk: what the Commission's classification guidelines aim to clarify

The question every company using AI in HR, credit or education asks itself — is my system high-risk? — will get official classification guidelines. The draft went to public consultation, and the final version is still pending.

Do you have to label all AI-written text? The editorial review route

No, you won't have to flag every paragraph an assistant has touched. The Article 50 obligation for text has a specific scope and a route designed for those who publish with human review and editorial responsibility. The key is being able to demonstrate it.

The EU's official icons for labelling AI content: how to use them and what they don't prove

The EU has published a free, downloadable set of icons for labelling AI-generated or AI-modified content. A practical guide for SMEs: when they make sense, where to place them, and the two nuances that keep you from using them wrong.

The code of practice on AI content transparency gets the green light: what it is and what it isn't

The Commission and the AI Board have confirmed the code of practice on AI-generated content as an adequate tool for demonstrating the transparency obligations. What signatories gain, and the nuance no signatory should forget.