Blog

Regulatory analysis of the AI Act and the GDPR for SMEs

AI agents and data protection: what the AEPD says

An agent isn't a chatbot: it reasons in chains, remembers, acts on its own and connects to your systems. The AEPD has published guidance on what changes under the GDPR when AI stops responding and starts acting.

You're fine-tuning an open model: have you become a provider?

Using an AI model isn't the same as modifying it, and modifying it enough moves you into a different box under the AI Act. The Commission's guidelines put a concrete threshold on that line. What it means for a company fine-tuning Llama or Mistral with its own data.

Who must warn that your chatbot is an AI? The nuance in Article 50(1) that almost everyone gets wrong

The duty for a chatbot to disclose that it's an AI falls on whoever designs it, not on whoever uses it. What the deploying company owes is something else: checking it works and not breaking it. The difference matters more than it seems.

Facilita RGPD and Gestiona RGPD: what they solve well — and where the coverage ends

The AEPD's free tools are an excellent starting point for an SME's basic GDPR compliance. The Agency itself warns of their limit: obtaining the documents doesn't mean you comply. And AI, by design, falls outside their scope.

Harmonised standards under the AI Act: why the presumption of conformity still doesn't exist

The technical standards that will make high-risk obligations operable under the AI Act are not yet published, let alone cited in the Official Journal. What that means for anyone buying or deploying high-risk systems, and why certain marketing claims deserve scepticism.

The AEPD is already fining AI: enforcement that doesn't wait for the AI Act

While many companies watch the AI Act calendar, they forget that the GDPR already applies to AI today. The patterns that generate the most enforcement cases are avoidable, and they all point to the same thing: missing assessment and missing evidence.

The article that didn't move: why 2 August is still a real date

While everyone celebrates the postponement of high-risk obligations, the transparency duty under Article 50 still applies from 2 August 2026. It's the date many SMEs aren't watching.

Article 4 AI Literacy after the Omnibus: the obligation softens, the diligence doesn't

The Digital Omnibus rewrites Article 4 in a less demanding tone. That doesn't mean AI literacy stops mattering. It means exactly the opposite of what alarmist messaging sells.

FRIA and DPIA are not the same thing: why one does not replace the other

They look alike, they overlap, and they get confused more often than they should. But the AI Act's FRIA and the GDPR's DPIA are structurally different instruments. Treating one as the other is a mistake with consequences.

AI in the dental clinic: where the real risk sits and what to document now

AI-assisted image diagnosis is already routine in many clinics. Understanding why it's classified the way it is — and which obligation lands first — avoids both panic and carelessness.