Articles for companies that use AI rather than develop it — including companies outside the EU, which the regulation reaches whenever their AI output is used in the Union. Everything here reflects the position after the Digital Omnibus, with links into the primary texts so you can check it yourself.
Who the AI literacy obligation covers, what the Digital Omnibus changed, and why there is no separate fine for Article 4. With a one-day plan for smaller firms.
Which fields a defensible AI inventory needs, how to uncover shadow AI in your own organisation, and how often the register has to be maintained.
The transparency duties have applied since 2 August 2026. Who Article 50 really binds, what you must disclose — and what you expressly need not.
Deadlines after the Digital Omnibus, which duties actually bind users of AI, and a plan that works without a consulting project.
What belongs in an internal AI use policy, how to write one people actually follow, and the section that is missing almost everywhere.
Where AI gets sensitive in a hotel: skin analysis in the spa, treatment data in the hotel system, face recognition at check-in — and what is banned outright.
Skin-analysis apps, before-and-after images, booking bots: what applies in a salon, and what applies additionally to doctors.
Who should take responsibility for AI in a company, what the role covers, how to appoint someone in writing, and how much time it actually takes each month.
ChatGPT at work under the GDPR: processing under Art. 28, security under Art. 32, and the difference between a personal and a business account.
How companies decide which AI tools are allowed: three lanes, seven checks, clear responsibilities and a turnaround time people can rely on.
Staff use AI without approval. Why that happens, how to uncover it without making people defensive, and what to do with what you find.
When employee representatives must be involved before AI is introduced, what Directive 2002/14/EC guarantees everywhere, and what belongs in an agreement.
How to place a specific AI tool in the four risk tiers of the EU AI Act, what Annex III covers, and where the classification usually goes wrong.
When a business customer asks about AI compliance: which twelve questions come up, how to answer each one, and which six documents cover them.
Customer data have reached a public AI tool: immediate steps, whether it is a notifiable breach under Art. 33 GDPR, and what to document either way.
The three penalty ranges of Article 99, why SMEs always pay the lower figure, and the one obligation that carries no fine at all.
Why pricing models entered into AI tools can cost you trade secret protection, what reasonable steps under Directive (EU) 2016/943 means, and how to take them.
Drafting reports with ChatGPT, exercise apps, booking bots: what applies in a therapy practice — and why the riskiest tool is the most innocent-looking one.
Caries detection AI, smile simulations, dictation and booking bots: what applies in a dental practice — medical-device law, secrecy and advertising limits.
Summarising assessments, drafting letters, booking bots: what applies in a tax or accounting firm — and why a client file is more sensitive than it looks.
Click course, online course, per-employee subscription, per-company subscription — calculated for 10, 25 and 50 people, with the full method shown.
Consent for client photos, labelling AI preview images, booking bots, and the line where retouching becomes misleading advertising.
Labelling duties for AI content produced on commission, NDA traps when briefs go into AI tools, and liability for hallucinated claims — the guide for agencies.
When AI-furnished property photos must be labelled, where virtual staging becomes misleading, and how to draft listings without exposing applicant data.
Why AI-quoted service values are dangerous, what applies to number-plate photos and customer data, and how to draft quotes without exposing the pricing.
How trades businesses use AI in the office without exposing customer data and pricing — and why general contractors now demand AI evidence from subcontractors.
How law firms use AI without breaching client confidentiality: tool choice with a contract, the lesson of Mata v. Avianca, and the firm organisation to match.
The risk rule of Art. 37 GDPR, Germany's 20-person threshold in Section 38 BDSG, and the honest status of its announced repeal.
Why the 250-employee exemption of Art. 30 GDPR almost never applies, what belongs in the records, and the honest status of the proposed omnibus relief.
When a DPA under Art. 28 GDPR is mandatory, which providers it covers (cloud, newsletter, AI tools), who needs none — and how SMEs keep track.
CC instead of BCC, wrong recipient, lost laptop: when a personal data breach exists and how the 72-hour clock of Art. 33 GDPR really runs.
Why staff training belongs to accountability, what a usable training record contains — and why nobody can sell you a GDPR certification for employees.
Microsoft, Google, OpenAI, Mailchimp: when using US services is a third-country transfer, and what the Data Privacy Framework really delivers.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free