AI Act and GDPR in practice: using AI without the risk
No blockade from legal, no data leaking out. We build the technical and organisational guardrails for running AI in production.
Why this is on the table now
The EU AI Act is in force and applies in stages: first the prohibited practices and the obligation to build AI literacy inside the company, then the requirements for general-purpose AI models. Further stages follow. In parallel the GDPR continues to apply unchanged, now to data flows that did not exist two years ago.
In practice this hits companies in two places. First through shadow usage: people have long been using AI, often through private accounts, and nobody knows which documents leave the building along the way. Second through the counter-reaction: data protection and legal block everything out of uncertainty, and the competitive disadvantage grows quietly alongside.
Both are symptoms of the same problem: there is no safe, official route. That is exactly what we build.
The three guardrails in operation
Legal certainty sits in how the systems are built. These three points are part of ours from the start.
EU hosting and anonymisation
Strategic context and company data are EU-hosted. Personal and sensitive content is masked before it reaches an AI model; compliance warnings take effect inside the workflow, not in hindsight. With the model providers it is ruled out that your data ends up in their training.
Auditability and documentation
Who produced what, with which tool and on what basis? Every run is logged and traceable: which model, which context, which approval. For critical use cases the human decision is a binding part of the process, including disclosure wherever it is required.
Guardrails against hallucinations
Agents work against defined system instructions and filters, not against an empty chat window. They draw on the company knowledge base instead of guessing, and they may only do what they are meant to do. Whatever remains uncertain goes to a person before it goes outside.
How we go about it
Take stock
Where is AI already being used, officially and unofficially? Which data leaves the company in the process, which use cases are sensitive, and where is a rule missing?
Build the guardrails
Secure access, anonymisation before anything reaches a model, roles and permissions, logging. Built into the systems, not filed as a policy on the intranet.
Operation and enablement
Training for the teams, approval paths for critical cases, documentation that keeps up. Governance that makes AI usable instead of slowing it down.
Token consumption, model choice and vendor lock-in are important questions, but they are not legal ones. How we keep costs transparent and models interchangeable is covered in the Admin Layer of the AI platform.
From blocker to enabler: make your AI projects legally sound.
In a 30-minute AI governance check we name your biggest data protection and compliance risks and show the route to a solution.