Automation & AI · Compliant AI

Compliant AI: the EU AI Act and GDPR under control

AI in a company is also a legal question, but not one to freeze in front of. Most use cases in mid-sized companies can be set up cleanly and with manageable effort. You just have to know which rules really apply, which ones only kick in later, and what all of that concretely means for your business.

01 — Stance

Compliance as a prerequisite, not a brake

There are two ways to deal with AI regulation, and both are wrong. Some ignore it and let the team work with private ChatGPT accounts until the first customer record ends up in someone else's model. Others ban everything out of fear and watch the competition pull away. The third way is unspectacular: classify your own use cases properly, put the right contracts and settings in place, and then get going with a clear conscience.

We walk this way with you as part of our work as an AI agency. We are not a law firm and we don't replace legal advice. We are the practitioners who have been building AI systems since the first GPT-3 APIs and have learned along the way how to set them up so that the lawyer and the data protection officer end up approving instead of blocking.

02 — Classification

The EU AI Act risk classes, translated into practice

The AI Act sorts AI systems into four tiers, and the good news comes first: most of what runs in mid-sized companies falls into the bottom two.

  • Prohibited practices: social scoring, manipulative systems. Banned since February 2025, practically never touches normal business use cases
  • High risk: AI that affects people, for example in candidate selection, credit decisions or critical infrastructure. Extensive duties around risk management and oversight will apply here
  • Limited risk: chatbots and generative systems. The core duty is transparency, i.e. making it recognizable that AI is involved
  • Minimal risk: the large remainder, from text summarization to email triage. No special duties beyond general AI literacy

The practical work consists of assigning each of your use cases to a tier and documenting the result. It gets delicate mainly where AI takes part in decisions about people, for example when screening applications. Exactly those cases are the ones we review with extra care before they go live.

03 — Current

What's changing right now: the 2026 deadlines

The timeline moved quite a bit in 2026. With the Digital Omnibus, the EU postponed the high-risk obligations in May 2026: they now essentially apply from December 2, 2027 instead of August 2026 as originally planned. What does take effect on August 2, 2026 are above all the transparency duties from Article 50, i.e. labeling chatbots and AI interactions. The duty to machine-readably label AI-generated content was moved to December 2, 2026 because the technical watermarking standards are still maturing. On top of that come notable documentation reliefs for small and mid-sized companies.

Our read: the postponement is a delay, not an all-clear. If you classify your use cases and get the base documentation done now, 2027 will be stress-free. If you wait, you do the same work later under time pressure.

04 — Data protection

GDPR in practice: DPAs, data flows, hosting

In day-to-day work, the GDPR is the harder hurdle than the AI Act, because it applies now and to every prompt containing personal data. Three things we put in order with every setup. First, the data processing agreement with every AI vendor, including the question of whether your inputs are used for training. Second, documenting the data flows: which data goes from which system into which model, and what happens to the outputs. Third, the hosting question: for many clients, a platform with EU hosting like Langdock is the simplest way to give the whole team AI access without data flowing uncontrolled into third countries.

05 — Governance

An AI policy against shadow AI

The biggest data protection gap in companies is not the approved tool, it is the one used in secret. Where there is no official AI access, employees work with private accounts, and nobody knows which customer data ends up there. The antidote is an internal AI policy plus an approval process: approved tools with safe default settings, clear rules for which data classes may go where, and a defined path for how new tools get reviewed and admitted. To make sure the policy is lived rather than gathering dust on the intranet, it is part of the standard program in our AI training.

Shadow AI doesn't disappear through bans. It disappears when the official way is the more convenient one.

06 — Collaboration

With your data protection officer, not against them

Data protection officers almost never block AI projects on principle. They block when nobody gives them solid answers. So we bring the DPO and, where present, the works council to the table early, and we bring what they need: vendor documentation, DPA drafts, data flow diagrams and a template for the threshold assessment for a data protection impact assessment. We know this way of working from years in tracking & analytics, where consent and data protection are part of every project. If this is exactly where you are stuck right now, get in touch: often a moderated conversation with finished documents resolves in two hours what has been stalled internally for months.

07 — Evidence

Documentation that stands up to audits

In the end, what counts is what you can show. With every project we leave behind a lean compliance package: the AI register with all deployed systems and their risk classification, the DPA archive, the data flow documentation, the AI policy with version history and the training records for the team. No binder theater, but a set of documents that an auditor, a customer in a supplier audit or a new DPO can follow in an hour. It is maintained as part of ongoing operations, because documentation that freezes after the project is worthless at the first tool change.

08 — Let's talk

Do you know which AI is already running in your company?

Tell us briefly which tools are in use or under discussion at your company. We will tell you honestly where you stand legally and what to do next. First call free of obligation, 30 minutes.

We reply within one business day.