Risk and data diagnosis
We classify your case by the risk level of the AI Act (unacceptable, high, limited or minimal) and identify which personal data it processes for the GDPR. From there come the concrete obligations you must meet.
Private AI that complies with the GDPR and the European Union AI Act. We deploy RAG agents in your own environments (AWS Bedrock, Azure OpenAI or private AI servers) so you can leverage AI without giving up control of your data.
Adopting AI without breaching regulations is a priority today. The GDPR governs the processing of personal data, and the new EU AI Act (Regulation (EU) 2024/1689) adds obligations based on the system's risk level. The risk rarely sits in some exotic project; it sits in the everyday, with teams pasting client data into ChatGPT because nobody has defined what is allowed and what is not. We help you deploy private AI that complies with both frameworks from the design stage.
We work in environments where your data does not train third-party models: AWS Bedrock, Azure OpenAI or your own private AI servers. On top of them we build RAG agents with access control, traceability and data minimization, aligned with the GDPR and the AI Act. The result works like a private ChatGPT for your company, but with the contractual and technical safeguards the public tool does not offer.
Implementing AI in line with the regulation requires a clear process. Four phases: classify the risk and the data, design the private AI architecture, implement with safeguards and maintain governance over time.
We classify your case by the risk level of the AI Act (unacceptable, high, limited or minimal) and identify which personal data it processes for the GDPR. From there come the concrete obligations you must meet.
We pick the environment that keeps your data under control: AWS Bedrock, Azure OpenAI or a private AI server. We define the legal basis, data minimization, retention and the RAG agent architecture.
We build the RAG agents and integrations with access control, encryption, activity logging and decision traceability. We document the processing for the traceability the GDPR and the AI Act require.
The AI regulation applies in phases through 2026 and 2027. We track regulatory changes, audit the systems and keep documentation up to date so your AI stays compliant.
2024/1689
EU AI Act: the framework your system must comply with.
0
Personal data handed over to train third-party models.
100%
Documented and traceable processing, aligned with the GDPR.
Indicative information; it does not constitute legal advice. We work alongside your legal counsel when the case requires it.
We answer the frequent questions companies ask before launching an AI project that handles sensitive data.
They are complementary. The GDPR (Regulation (EU) 2016/679) governs the processing of personal data; the AI Act (Regulation (EU) 2024/1689) governs AI systems by their risk. An AI project that processes personal data must comply with both at once.
The tool is not illegal; the use can be. The free version of ChatGPT offers no data processing agreement and, by default, trains on your conversations, so feeding it personal data about your clients is in practice a GDPR breach, with fines that can reach 4% of annual turnover. With AWS Bedrock, Azure OpenAI or a private AI server, correctly configured, that same processing can be compliant.
It is AI deployed in environments where you control the data and it is not used to train third-party models: private AI servers, AWS Bedrock or Azure OpenAI with isolation. It drastically reduces the risk of GDPR noncompliance compared to using public tools.
Yes, when configured correctly. Both let you process data in EU regions, without your prompts or data training the base models, with encryption and access control. We define the configuration and the data processing agreement so it is compliant.
Regulation (EU) 2024/1689 entered into force in August 2024 and applies in phases: prohibited practices from February 2025, general-purpose AI model obligations from August 2025, and most high-risk obligations in 2026 and 2027. That is why it pays to prepare your systems now.
We implement the technical part (private AI, RAG agents, data control, traceability) aligned with the regulation. For legal interpretation we work with your legal counsel or specialized firms; we do not replace legal advice.
Tell us which AI project you want to launch and what data it handles. We validate the risk level, propose the right private AI architecture and how to deploy it in compliance with the GDPR and the AI Act.