Frequently asked questions
On hardware, the way we work, your data, quotes and the AI Act. Short answers, with the law or source behind them and the date we reviewed them.
Working with us: hardware, process, data and quotes
Which machine you need, how the work runs from the call to the handover, what happens to your data and how a quote is made.
What hardware do I need to run AI locally?
It depends on the model, not the brand: what matters is GPU memory (or unified memory) against the size of the loaded model. On our NVIDIA DGX Spark, llama3.1:8b took 9.2 GB loaded and gemma4:26b 17 GB, measured on 4 October 2026.
The loaded size includes the quantised weights and the context memory, so it grows with long conversations. Before recommending a machine we measure the model on your tasks. The VRAM explorer and the hardware guide give you a first idea.
Do you sell us the hardware?
No. We help you choose it and you buy it, from whichever supplier you like. The machine is yours from day one, and so is what we install on it.
Some product pages carry affiliate links, marked as such; they do not change what we recommend. If you already have a server or a GPU machine, we start by measuring what you have.
What is the process, from start to finish?
Four steps: a 15-minute call, a written scope with a fixed quote, the deployment on your hardware measured on your tasks, and the handover with documentation and training.
Nothing starts without the signed scope: what is delivered, with which data, who on your team takes part and on which dates. If something changes halfway, it changes in writing before we continue.
What happens on the 15-minute call?
You tell us what you want to solve and we tell you whether we can help, or whether you do not need to hire us. It costs nothing and it is not a sales demo.
If it fits, after the call we send you the scope in writing. If your case involves personal data, you do not need to share any on the call: describing the kind of data is enough.
How much does it cost? How is it quoted?
By scope: a fixed quote, in writing and before we start. We do not publish rates because the price depends on what is delivered, not on a table.
What weighs most: how many use cases, how many integrations with your systems, whether the hardware already exists and how much training is needed. Later support is optional and quoted separately. For the AI Act there is an entry offer with fixed deliverables, also quoted after the call.
Does my data leave my network?
No, in a local installation: the model runs on your machine and the prompts, documents and logs stay on it. There is no outside AI provider receiving them.
Your company remains the controller. As no data goes to a third-party service, there is no international transfer to justify (GDPR Chapter V). The impact assessment (Art. 35), if your processing requires one, is still yours; we give you the technical description it needs.
Do you need access to my systems or my data?
Only during installation and, if you contract it, support, through the channel you authorise. If that access lets us see personal data, we sign a processor agreement first (GDPR Art. 28).
To measure the model we prefer test or anonymised data. Remote access is opened for a specific task and closed afterwards.
Does it work without an internet connection?
Yes. Once installed, the model answers with no connection. The internet is only needed to bring in a new model or an update, and you decide when.
The model weights are copied once and checked against their hash before loading. Where full isolation is required, as in the public sector, updates come in on controlled media.
Which models do you use?
Open-weight models such as Llama, Qwen, Gemma or Mistral, chosen for each use case and measured on your tasks. We do not send your data to any model provider.
Each model has its own licence, and they do not all allow the same: Llama's, for example, has its own conditions. We review it with you before using it in production.
Is a local model as good as a cloud one?
Not always. An open model on your machine handles many bounded tasks well, such as summarising, classifying or searching your documents, but not everything. That is why we measure on your tasks before recommending anything.
If the case needs the largest model on the market, or a cloud service already solves the problem with the guarantees you need, we tell you on the call.
What happens after the handover?
You keep everything: the machine, the installed software, the documentation and your team's training. Later support is optional, by the month, and you can run it yourself or with another supplier.
The software we use is open and documented, so you do not depend on us to carry on. The training covers what Art. 4 of the AI Act asks for the people who will use it.
EU AI Act: obligations and dates
What Regulation (EU) 2024/1689 asks of a Spanish SME, with the dates and the articles.
Does the AI Act apply to my SME if I only use ChatGPT?
Yes, as a "deployer" (Article 3(4)): since 2 February 2025 Article 4 applies to you, which asks you to take AI-literacy measures for your staff. High-risk obligations reach you only if you use AI for an Annex III use case, such as recruitment or creditworthiness assessment.
Using a third-party model does not make you a provider. Since Regulation (EU) 2026/1744, Article 4 asks for measures that support AI literacy, taking into account your staff's knowledge and the context of use, without requiring you to guarantee any individual's level. Article 50 adds transparency duties for deployers in specific cases: deep fakes, and AI-generated text published to inform the public without human review or editorial responsibility.
Which AI Act dates affect me?
Three have passed: prohibited practices and AI literacy since 2 February 2025, general-purpose AI models since 2 August 2025, and general application since 2 August 2026. Annex III high-risk obligations, originally due on that same date, apply from 2 December 2027: Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), adopted and in force since 27 July 2026, set that date.
The same Omnibus moves Annex I high-risk AI (AI inside Section A regulated products such as medical devices, lifts or toys; machinery moved to Section B and gets its AI requirements through delegated acts under Regulation (EU) 2023/1230 that must apply by 2 August 2028) from 2 August 2027 to 2 August 2028, and applies two new prohibited practices it adds to Article 5 from 2 December 2026. It was published in the Official Journal on 24 July 2026 and amends Article 113 of the Regulation.
Is my customer-service chatbot high-risk?
Usually not: answering enquiries is not listed in Annex III. What Article 50(1) does require is that the person knows they are talking to an AI, unless it is obvious; that duty falls on the system's provider, and if you put the chatbot into service under your own name or trademark, the provider may be you (Article 3(3)).
It becomes high-risk if the same system is used for one of the Annex III purposes, for example assessing people's creditworthiness or credit score, selecting candidates or deciding admission to an educational institution (points 3, 4 and 5). Article 50(5) requires the notice to be clear and distinguishable, at the latest at the first interaction.
What are the fines, and who enforces in Spain?
Article 99 sets three bands: up to EUR 35 million or 7% of worldwide turnover for prohibited practices; up to EUR 15 million or 3% for breaching the obligations listed in its paragraph 4, including those of deployers (Article 26) and the transparency duties (Article 50); and up to EUR 7.5 million or 1% for supplying incorrect, incomplete or misleading information to the authorities. For SMEs the lower figure of each pair applies. In Spain, the state agency for AI supervision is AESIA.
AESIA (the Spanish Agency for the Supervision of Artificial Intelligence) was created by Royal Decree 729/2023, which approves its statute, and is based in A Coruña. The 7% and 3% figures are calculated on the preceding financial year and, for larger companies, whichever is higher applies.
What is a "deployer"?
The natural or legal person, public authority or body that uses an AI system under its authority, except in a personal non-professional activity (Article 3(4)). If you buy an AI service and use it in your business, with your customers or staff, that is you.
The provider is whoever develops the system, or has it developed, and places it on the market or puts it into service under its own name or trademark (Article 3(3)). A deployer's duties include AI literacy (Article 4), transparency in the cases of Article 50 and, for high-risk systems, assigning human oversight to people with the necessary competence, training and authority (Article 26(2)).
AI literacy and internal AI policy
What the AI Act asks about training, transparency notices and internal AI use, and what the GDPR adds, with the articles.
Do I have to train my employees in AI?
You have to take measures, but not guarantee a level: since 2 February 2025 Article 4 of the AI Act has required providers and deployers to act on their staff's AI literacy. Since 27 July 2026, in the wording given by Regulation (EU) 2026/1744, the duty is to "take measures to support" that literacy, without guaranteeing any specific level of any individual.
The original wording asked for measures to ensure, "to their best extent", a sufficient level of AI literacy. The Digital Omnibus on AI (Article 1, point 5, of Regulation 2026/1744) replaced Article 4: the measures take into account people's technical knowledge, experience, education and training, the context the systems are used in and the persons they are used on, and the Commission and Member States must support SMEs in particular, with practical examples published by the Commission. The Omnibus entered into force on 27 July 2026, the third day after its publication on 24 July, with no separate date for this article. According to the Commission no certificate is needed: an internal record of trainings and other initiatives is enough. If you use high-risk AI, Article 26(2) still requires the people overseeing it to have the necessary competence, training and authority.
Do I need an AI use policy?
Not literally: if you use systems that are not high-risk, the AI Act does not require a document called an "AI use policy". It does require AI-literacy measures (Article 4), and the GDPR requires you to be able to demonstrate that you process personal data properly (Articles 5(2) and 24); a short policy is the practical way to evidence both.
GDPR Article 24(2) provides that, where proportionate, the controller's measures include "appropriate data protection policies", and Article 32(4) requires it to ensure that anyone acting under its authority processes personal data only on its instructions. For Article 4, the Commission states that no certificate or specific governance structure is required (no AI officer, no board), and that an internal record of trainings and initiatives is enough. A short policy usually covers which tools are approved, which data is never entered, who reviews AI output before it is used externally, and how staff are trained and recorded. If you use Annex III high-risk AI, Article 26 adds its own obligations, applicable from 2 December 2027.
- Reglamento (UE) 2024/1689, arts. 4 y 26 (EUR-Lex) (opens in a new tab)
- Reglamento (UE) 2016/679 (RGPD), arts. 5.2, 24 y 32.4 (EUR-Lex) (opens in a new tab)
- Reglamento (UE) 2026/1744, art. 1, punto 40, que modifica el art. 113 (EUR-Lex) (opens in a new tab)
- Comisión Europea, «AI Literacy - Questions & Answers» (opens in a new tab)
Do I have to tell my customers they are talking to an AI?
If it is a chatbot, usually yes: since 2 August 2026 Article 50(1) requires that people interacting with an AI system are informed of it, unless this is obvious. Formally it is the provider's duty, but if you build your own assistant on a third-party model and put it into service under your name, the provider may be you (Article 3(3)).
As a deployer, Article 50(4) requires you to disclose that content is artificial in two cases: deep fakes (image, audio or video that appears authentic) and AI-generated or manipulated text you publish to inform the public on matters of public interest, unless it has undergone human review or editorial control and someone holds editorial responsibility. The notice must be clear and distinguishable, at the latest at the first interaction or exposure (Article 50(5)). Article 25, which turns into a provider anyone who puts their name on a system or modifies it, only concerns high-risk systems. Article 50 applies from 2 August 2026; Regulation (EU) 2026/1744 only gives until 2 December 2026 for the machine-readable marking of Article 50(2) in generative systems placed on the market before 2 August 2026, and does not change paragraphs 1 and 4.
What if an employee uses ChatGPT on their own ("shadow AI")?
The most immediate risk is data protection: if they paste customers' or employees' personal data into a personal account, that processing escapes your instructions, and as controller you are expected to have taken steps to prevent it (GDPR Articles 29 and 32(4)). In addition, the AI Act defines a deployer by use "under its authority" and only excludes personal non-professional activity, so use for work tasks is unlikely to fall outside your Article 4 duty.
GDPR Article 29 prevents anyone acting under the controller's authority from processing personal data except on its instructions, and Article 32(4) requires the controller to take steps to ensure this. If a provider processes data on your company's behalf, Article 28 requires a processing contract, which an account the employee opened personally does not create between your company and that provider. The AI Act does not expressly address unauthorised AI, but the Commission confirms that a company whose employees use ChatGPT to, for example, write advertising copy or translate text is subject to Article 4 and should inform them of risks such as hallucination. In practice: inventory what is being used, offer an approved alternative (local, or under a processing contract), set which data is never entered, and train your staff.
Who should receive the training?
The people in your organisation who operate or use AI systems, and those who do so on your behalf without being employees, such as contractors or service providers (Article 4). It does not have to be the same for everyone: the measures are tailored to each person's knowledge, experience and training and to the context the AI is used in.
The Commission reads "other persons dealing with the operation and use of AI systems on their behalf" as people within your organisational remit who are not employees: a contractor, a service provider or even a client, and accepts different training levels per group. It also warns that, in many cases, asking staff to read the instructions for use may be ineffective. People with a degree or experience in AI development normally count as AI-literate, though it is worth checking that they know your organisation's specific systems and their legal and ethical aspects. For high-risk systems, Article 26(2) additionally requires the people exercising human oversight to have the necessary competence, training and authority.
What should AI literacy training cover?
At a minimum, that your staff understand what AI is and how it works, which AI systems your organisation uses, and what their opportunities and risks are. According to the Commission, from there it is tailored to your organisation's role (provider or deployer), to the risk of the systems and to what each person already knows.
Article 4, as worded by Regulation (EU) 2026/1744, asks you to take into account people's technical knowledge, experience, education and training and the context the systems are used in. The Commission adds that simply asking staff to read the instructions for use may be ineffective, and that people using generative tools to, for example, draft or translate text should know specific risks such as hallucination. In practice a common module for everyone plus one per role is usually enough: people who use AI daily, people who review its output before it goes out, and people who decide which tools are approved.
How do I show I comply with Article 4, and can I be fined?
With an internal record of trainings and other initiatives: the Commission states that no certificate and no specific governance structure are required. National authorities supervise Article 4 from 2 August 2026 and may impose penalties or other measures, taking into account proportionality and the nature, gravity and intentionality of the infringement.
A useful record notes who received which training and when, which AI systems each group uses, and what material or policy they were given; the linked training-plan template does that. You do not need to appoint an AI officer or set up a board to comply with Article 4, although one can help organise it. If you also process personal data with AI, the same record helps demonstrate accountability under GDPR Article 5(2).
GDPR and AI: personal data in AI tools
What the GDPR asks when you use personal data with AI tools, in the cloud or locally, with the articles and what is still unsettled.
Can I put customer data into ChatGPT or another cloud AI?
Only with three things in place: a legal basis (GDPR Article 6), in practice a processor contract that meets Article 28 so the provider processes the data only on your behalf and, if the data leaves the European Economic Area, a transfer mechanism under Chapter V. If any is missing, do not enter personal data; and health data and the other special categories in Article 9 are prohibited unless one of its exceptions applies.
If the provider processes the data on your behalf, you are the controller and it is your processor (Article 4, points 7 and 8). Article 28(1) requires you to use only providers with sufficient guarantees, and Article 28(3) requires a contract that, among other things, binds it to process the data only on your documented instructions and to delete or return it at the end. Check which terms you are accepting: the consumer version and the business or API version of the same provider can have different terms. If the data goes to the United States, Implementing Decision (EU) 2023/1795 of 10 July 2023 finds an adequate level of protection only for organisations on the EU-US Data Privacy Framework List. The General Court upheld it on 3 September 2025 (Case T-553/23), but that judgment is under appeal before the Court of Justice (Case C-703/25 P), so it is worth following. For destinations without an adequacy decision you need Article 46 safeguards, such as standard contractual clauses. And even with all of that in place, the data minimisation principle (Article 5(1)(c)) asks you to send only what is needed: remove or pseudonymise names when the task does not require them.
- Reglamento (UE) 2016/679 (RGPD), arts. 4, 5.1.c, 6, 9, 28, 45 y 46 (EUR-Lex) (opens in a new tab)
- Decisión de Ejecución (UE) 2023/1795 (Marco de Privacidad de Datos UE-EE. UU.), art. 1 (EUR-Lex) (opens in a new tab)
- TJUE, comunicado de prensa 106/25 sobre la sentencia T-553/23, Latombe/Comisión (opens in a new tab)
- Recurso de casación C-703/25 P, DO C/2025/6610 (EUR-Lex) (opens in a new tab)
Do I need a DPIA to use AI?
Not always: GDPR Article 35 requires an impact assessment when processing, in particular using new technologies, is likely to result in a high risk to people. Using AI does not trigger it on its own, but the Spanish AEPD's list says that processing meeting two or more of its criteria requires one in most cases, and the use of new technologies is one of those criteria.
Article 35(3) always requires one in three cases: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; large-scale processing of special categories or criminal-offence data; and large-scale systematic monitoring of a publicly accessible area. The AEPD's Article 35(4) list, based on the Article 29 Working Party's WP248 guidelines, adds eleven criteria, including profiling, automated decisions, special categories, large-scale processing, data on vulnerable people and the use of new technologies or an innovative use of established technologies. The AEPD itself says the list is not exhaustive: if your own analysis finds a high risk, the DPIA is mandatory even if you do not match the list. Drafting generic text with an assistant, with no personal data, does not require one; scoring candidates or customers with a model meets several criteria (profiling, automated decisions, new technologies) and normally does. The assessment is done before processing starts, with the minimum content in Article 35(7), and if it indicates a high risk you do not mitigate with your measures, Article 36 requires you to consult the AEPD before processing.
- Reglamento (UE) 2016/679 (RGPD), arts. 35 y 36 (EUR-Lex) (opens in a new tab)
- AEPD, «Listas de tipos de tratamientos de datos que requieren evaluación de impacto relativa a protección de datos (art 35.4)» (opens in a new tab)
- AEPD, «Adecuación al RGPD de tratamientos que incorporan Inteligencia Artificial. Una introducción» (febrero de 2020, marcada «en revisión»), apartado IV.B (opens in a new tab)
Does local AI comply with the GDPR automatically?
No. Running the model on your own hardware removes the processor contract and the international transfers with the model provider, but the rest of the GDPR stays the same: you need a legal basis, to inform people, to secure the data, to limit how long you keep it and to handle their rights.
What goes away is specific: if no third party processes the data on your behalf during inference, there is no model processor for Article 28 to apply to and no Chapter V transfer. What remains: the Article 6 legal basis (and an Article 9 exception if special categories are involved), the information duties in Articles 13 and 14, the Article 5 principles (purpose limitation, minimisation, accuracy, storage limitation), Article 32 security, which now depends entirely on you, the rights in Articles 15 to 22 and, where the risk is high, the Article 35 DPIA. Two caveats: if a company maintains the equipment for you and processes the data on your behalf, it is your processor and you need a contract with it; and if the model produces inaccurate statements about specific people and you use them, the accuracy principle in Article 5(1)(d) applies all the same. Local reduces the risk surface; it does not replace compliance.
Do I have to tell people that I use AI with their data?
The GDPR does not ask for a line saying "we use AI", but it does require you to say why you process the data, on what legal basis, who receives it (the AI provider included) and whether it is transferred outside the European Economic Area (Articles 13 and 14). And if you take decisions based solely on automated processing with legal or similarly significant effects (Article 22), you must say so and give meaningful information about the logic involved.
If you collect the data from the person, the information is given when you obtain it (Article 13); if you obtain it from another source, within a reasonable period and at the latest within one month, or at the first communication with them (Article 14(3)). A provider that processes the data counts as a recipient even when it is your processor (Article 4(9)). If you are going to use data you already hold for a new purpose, such as analysing it with a model for something other than what you told people, Articles 13(3) and 14(4) require you to inform them before you do. For Article 22 decisions, Articles 13(2)(f) and 14(2)(g) require you to disclose their existence, the logic involved and the envisaged consequences, and where the decision is based on a contract or explicit consent, Article 22(3) requires at least that the person can obtain human intervention, express their point of view and contest the decision. Beyond the GDPR, the AI Act adds its own notices from 2 August 2026, such as telling someone they are talking to a chatbot (Article 50).
Can I use personal data to train or fine-tune a model?
It can be lawful, but it is not automatic: training or fine-tuning is processing with its own purpose, which needs a legal basis and, if you reuse data collected for something else, must pass the compatibility test in GDPR Article 6(4). Legitimate interest can work in some cases, according to the European Data Protection Board's Opinion 28/2024, provided you pass its three-step test.
The purpose limitation principle (Article 5(1)(b)) prevents processing data in a way that is incompatible with the purposes you collected it for. If you rely neither on consent nor on a law, Article 6(4) requires you to weigh, among other factors, the link between the two purposes, the context of collection and your relationship with the people, the nature of the data, the possible consequences and the safeguards, such as encryption or pseudonymisation. EDPB Opinion 28/2024, adopted on 17 December 2024, recalls that there is no hierarchy between legal bases and sets out the Article 6(1)(f) legitimate-interest test: a lawful, clearly articulated and real interest; processing that is necessary, with no less intrusive way; and people's rights not overriding it, where their reasonable expectations weigh in. It also warns that a model trained on personal data cannot in all cases be considered anonymous, and it leaves special categories outside its analysis; processing them remains prohibited unless an Article 9(2) exception applies. Under legitimate interest, people keep the Article 21 right to object. One open point: the proposed "Digital Omnibus" Regulation (COM(2025) 837) would change the GDPR on legitimate interest for AI and on the definition of personal data, but according to the European Parliament it is still going through the legislative process and changes nothing above today.
- Reglamento (UE) 2016/679 (RGPD), arts. 5.1.b, 6.1.f, 6.4, 9 y 21 (EUR-Lex) (opens in a new tab)
- CEPD, Dictamen 28/2024 sobre determinados aspectos de protección de datos relacionados con el tratamiento de datos personales en el contexto de los modelos de IA (17 de diciembre de 2024) (opens in a new tab)
- Parlamento Europeo, Legislative Train, «The Digital Omnibus Regulation Proposal» (2025/0360(COD)) (opens in a new tab)
What do I do if someone asks for their data to be erased from a model?
Reply within one month (GDPR Article 12(3)) and, if one of the grounds in Article 17(1) applies, erase the data wherever you hold it: conversation logs, knowledge bases and documents the assistant consults, and fine-tuning datasets. Removing data from the weights of a model that is already trained is technically hard, and there is not yet a settled view on how far that obligation reaches.
Erasure is not absolute: Article 17(1) grants it, among other cases, when the data is no longer needed, when consent is withdrawn, when the person successfully objects (Article 21) or when the processing was unlawful, and Article 17(3) sets out exceptions, such as the defence of legal claims. The one month can be extended by two further months for complex requests, if you say so within the first month. If you use a third-party model you have not trained on your data, the request concerns what you process, and if the provider is your processor, Article 28(3)(e) requires it to help you respond. If you have fine-tuned a model on personal data, EDPB Opinion 28/2024 recalls that such a model is not anonymous in all cases, so the rights can reach it; it cites output filters and post-training techniques that attempt to remove or suppress personal data as measures, and notes that authorities can order the erasure of the dataset or of the model itself if it was trained unlawfully. The AEPD's AI guidance asks for training data to be erased once no longer needed, or for a justification of why it cannot be, and recalls that in Spain erasure goes together with the blocking of data under Article 32 of the LOPDGDD (the Spanish data protection act). If you will not act on the request, Article 12(4) requires you to explain why within the month and to mention the right to complain to the AEPD.
- Reglamento (UE) 2016/679 (RGPD), arts. 12.3, 12.4, 15, 17, 21 y 28.3.e (EUR-Lex) (opens in a new tab)
- CEPD, Dictamen 28/2024, resumen y apartados 102, 107, 114 y 115 (opens in a new tab)
- AEPD, «Adecuación al RGPD de tratamientos que incorporan Inteligencia Artificial. Una introducción» (febrero de 2020, marcada «en revisión»), apartados III.E y III.F (opens in a new tab)
Who is controller and who is processor when I use an AI provider?
Normally you are the controller, because you decide why and how the data is processed (GDPR Article 4(7)), and the provider is your processor when it processes the data on your behalf (Article 4(8)). If the provider uses that data for its own purposes, such as training its models, it becomes a controller for that use.
As controller, you are responsible for the processing and must be able to demonstrate compliance (Article 5(2)). With a processor, Article 28 requires one with sufficient guarantees, a written contract with the minimum content in Article 28(3) (documented instructions, confidentiality, Article 32 security, help with rights and with the DPIA, deletion or return at the end, audits) and your prior authorisation before it engages other processors (Article 28(2)). Article 28(10) provides that a processor that determines the purposes and means of processing is considered a controller for that processing, and the AEPD's AI guidance applies this to providers: any additional processing they carry out for their own purposes makes them controllers for it. If you and the provider jointly decide purposes and means, you are joint controllers (Article 26): you need an arrangement that allocates the obligations, and the person can exercise their rights against either of you. What counts is who decides the purposes and means, so read the contract together with the provider's data-use policy before entering personal data.