AI Act · GDPR · NIS2
Regulatory compliance has changed. These three laws affect your business today, even if no one has explained them to you yet.
They're not rhetorical. These are the exact points the AEPD checks when sanctioning a company.
ChatGPT, HR automations, software plugins... every undocumented AI use can expose you to sanctions under the AI Act.
The AEPD already sanctions notices, contracts and forms that citizens cannot understand, even if they are legally correct.
An RPA from 2018 or 2020 doesn't cover AI or current digital channels. Without an update, the AEPD won't consider it valid evidence.
The law gives you exactly 72 hours. Without a defined protocol, meeting that deadline is practically impossible.
This is not an optional service. It is legal compliance.
The European Artificial Intelligence Regulation (EU Regulation 2024/1689) entered into force in August 2024 and began to apply progressively. From August 2025, governance obligations and requirements for general-purpose AI models are fully enforceable across the EU.
The regulation classifies AI systems by risk level: unacceptable (prohibited), high risk, limited risk and minimal risk. It doesn't only affect AI developers: any company using AI tools (ChatGPT, candidate selection systems, customer service automations, software plugins) is subject to the regulation.
Obligations include inventorying and classifying all AI systems in use, ensuring staff have sufficient training (AI literacy, mandatory) and issuing an official assessment. Without that assessment, any AI use can expose you to fines of up to €35 million or 7% of global annual turnover.
The NIS2 Directive (EU 2022/2555) entered into force in January 2023 and had to be transposed into national law before October 2024. It significantly expands the scope of its predecessor: it applies to entities in more than 18 sectors (energy, transport, health, water, digital infrastructure, public administration) and lowers the size threshold. Medium-sized companies with more than 50 employees or over €10 million in turnover may already be obliged.
Key obligations include implementing technical and organisational cybersecurity risk management measures, reporting significant incidents within a maximum of 72 hours, and establishing an accountability chain that reaches the management body. Directors can be held personally liable in the event of non-compliance.
The sanctions regime is one of the harshest in European law: up to €10 million or 2% of global turnover for important entities. ATI assesses your exposure level, implements the required measures, and supports you in your dealings with INCIBE and the competent authorities.
The General Data Protection Regulation has been in force since May 2018, but the reality of 2025 has overtaken it. The GDPR did not anticipate language models like ChatGPT, mass data scraping, automatic transfers between SaaS platforms, or the use of AI in HR processes.
The Record of Processing Activities (RPA, Art. 30 GDPR) is the core document the AEPD requests in any inspection. An RPA from 2018 or 2020 that doesn't reflect current AI use, cloud tools or new acquisition channels has no value as evidence. The AEPD doesn't assess the document's existence: it assesses whether it reflects the company's active reality.
The AEPD has imposed more than 300 sanctions in the last three years. SMEs and self-employed individuals represent the most frequent profile, with fines ranging from €900 to €100,000. The most serious infringements (unreported breaches, unlawful processing) can reach €20 million or 4% of global turnover.
Fines are not only for large companies. An SME can receive sanctions that put the continuity of the business at risk.
MINOR LEVEL
Up to €40,000
Formal infringements: incorrect legal notice, cookies without properly informed consent, illegible forms.
SERIOUS LEVEL
Up to €300,000
No active RPA, no DPO when mandatory, failure to comply with data subject rights, lack of security measures.
VERY SERIOUS LEVEL
Up to €20,000,000
or 3% global turnover
Unreported data breach, unlawful use of AI, unauthorised transfers. If you are self-employed, you are liable with your personal assets.
72 hours is the time the law gives you to notify the AEPD of a breach. Without a defined protocol, meeting that deadline is practically impossible.
These are not exceptional cases. They are the day-to-day reality of any business.
A law firm uses ChatGPT to draft briefs containing client data. This happens in thousands of offices every day and almost no one realises.
In the event of a breach, the sanction could force closure
A restaurant posts a job vacancy and receives 40 CVs by email. The manager saves them in their inbox and gets on with the day.
AEPD fine: from €900 to €20,000 for an SME
An estate agency adds its clients to a WhatsApp group to send them property updates. It seems like a normal commercial gesture.
Each member without consent = separate infringement
A business signed its data protection contract back in 2018. It believes it is protected. The AEPD sees things very differently.
That client could be sanctioned today
Three laws. One point of contact. We handle everything so you don't have to.
We analyse all artificial intelligence systems in your company, known or unknown, and issue the official assessment. Without this assessment, any AI use is already an infringement. It is the mandatory first step for any company, regardless of size.
We keep your Record of Processing Activities up to date. Not a document gathering dust: active evidence the AEPD can verify at any time.
We redesign forms, legal notices and contracts to make them clear and understandable. The AEPD already sanctions texts that citizens cannot understand.
A perfect protocol is useless if the team doesn't know how to apply it. We train employees in data protection, correct AI use and basic cybersecurity.
We assess your cybersecurity posture and implement the measures required by NIS 2: technical protection, 72-hour breach notification protocol and management accountability.
We don't just manage compliance. We are your all-in-one advisor: taxes, grants, Verifactu, payroll, audits. One single point of contact for everything.
The AEPD doesn't value a 2018 contract. It values real, active evidence. We generate and maintain it.
We believe laws should be understandable for everyone. We design your documents so that anyone can understand them.
We don't disappear after signing. Constant monitoring and updates with every regulatory change. Always accessible.
Know your real situation before the AEPD finds out.