• Artificial intelligence lawyers for companies

    Use artificial intelligence with legal certainty: the AI Act, the GDPR and employment obligations in a single service.

We help companies integrate artificial intelligence within the legal framework. First, we review which AI tools your organisation already uses, tell you which rules apply today and which in 2027, and prepare what a client, an audit or the Spanish Data Protection Agency (AEPD) may ask for: impact assessment, information to staff, contract with the provider and training. As artificial intelligence lawyers and data protection officers, we also work on AI where it usually fails: personal data and the people it affects.

Does your company need to review how it uses AI?

If you recognise any of these situations, the answer is yes:

  • Staff use ChatGPT, Copilot or Gemini and there are no written rules on what data can be entered.
  • A program decides or proposes shifts, commissions, promotions or dismissals, and nobody has explained it to the workers.
  • Your recruitment tool scores or even rejects CVs automatically.
  • You have contracted AI software without reviewing the processor agreement or where the data is stored.
  • You serve customers with a chatbot or automated calls.
  • You develop an AI product and do not know whether your system is regulated.

What applies today and what arrives in 2027?

First, the European Artificial Intelligence Act (Regulation (EU) 2024/1689) applies in phases. In addition, the Omnibus Regulation (EU) 2026/1744 postponed the high-risk obligations. However, the postponement does not affect everything:

Obligation Rule From
Prohibited AI practices, including emotion recognition in the workplace AI Act, art. 5 2 February 2025
Measures to support the AI literacy of staff who use AI systems AI Act, art. 4 (as amended by Regulation (EU) 2026/1744) Already applicable
Transparency towards people who interact with an AI system or receive generated content AI Act, art. 50 2 August 2026
Inform each worker in writing of the algorithms that decide on their working conditions Royal Decree 723/2026, art. 3.2.k) 5 October 2026
Inform the works council of the parameters of algorithms and AI systems Workers’ Statute, art. 64.4.d) Already applicable
Information, automated decisions and impact assessment GDPR, arts. 13, 14, 22 and 35 Already applicable
Annex III high-risk systems: employment, education, access to essential services AI Act, arts. 26 et seq. 2 December 2027

Therefore, if your company uses AI to make decisions about people, it already has enforceable obligations. What is postponed to 2027 is the most technical part of high risk, not the rest.

What we do as artificial intelligence lawyers

Inventory and classification

We review which AI systems the company actually uses, including those built into other software (ATS, scheduling, CRM, Copilot), and classify them under the AI Act.

Generative AI use policy

Internal rules for ChatGPT, Copilot or Gemini, for example which data must not be entered, which accounts to use and how to check the results. We also explain it in ChatGPT in business.

Impact assessment

We also assess whether the use of AI requires an impact assessment under Article 35 GDPR and, if so, we carry it out. In fact, it is usually needed in human resources.

Transparency with staff

Written information under Royal Decree 723/2026, a response within 30 working days and communication to the works council. We also explain it in what to tell employees about algorithms.

Providers and contracts

We review the processor agreement as well as the use of your data to train models, international transfers and the provider’s technical documentation.

Training and AI literacy

Sessions tailored to each role (management, HR, customer service, teachers) with attendance certificates and records to document the measures under Article 4 of the AI Act.

Customer service and marketing

Chatbots, voice assistants, automated calls and generated content: transparency notices, consent and, where Law 10/2025 applies, human assistance.

Companies that develop AI

On the other hand, if your product integrates AI, we help you determine whether you are the provider of a regulated system, what documentation you need and how to apply data protection by design.

What your company gets

AI tool inventory, with its risk classification and the company’s role in each one.

Internal AI use policy, ready to hand over to staff.

Impact assessment for the systems that need it.

Clauses and communications for workers, candidates, the works council and customers.

Provider report listing what is missing from each contract.

Training record to document your AI literacy measures.

How we work

We apply our work protocol in four phases to artificial intelligence.

1. Analysis

First, we inventory the AI tools, classify them by risk and determine which rules apply to you and where to start.

2. Planning

Then we draft the documentation your case requires: use policy, impact assessments, clauses and provider report.

3. Adaptation

Next, we meet your team to implement each document, review contracts and train the staff who use AI.

4. Success

Finally, your company is compliant and we keep it that way with quarterly checks and a review of every new tool.

Who we work for

  • SMEs that use generative AI on a daily basis and have no internal rules or reviewed contract.
  • Human resources departments with recruitment, scheduling, performance evaluation or time-tracking software.
  • Schools that use AI platforms, plagiarism detectors or assessment tools with underage pupils.
  • Start-ups and software companies that integrate AI into their product and need to know whether they are providers of a regulated system.

Why Auratech

  • We work from the inside. We are data protection officers for companies and schools, so we know how AI is used day to day, not just what the law says.
  • We combine the four rules. AI Act, GDPR, Workers’ Statute and Royal Decree 723/2026 in a single analysis.
  • Security and privacy. In addition, we work with the ISO 27001 and ISO 27701 frameworks, which fit the risk management required by the AI Act.
  • Documents that get used. Policies and clauses adapted to your real tools, not generic templates.

Frequently asked questions

Partly, yes. As a deployer, you must take measures to support the AI literacy of the staff who use it (art. 4) and respect the prohibited practices. In addition, everything entered into the tool has been subject to the GDPR since 2018.

Only partly. Regulation (EU) 2026/1744 postponed the Annex III high-risk systems to 2 December 2027. However, the prohibited practices, AI literacy, transparency, the GDPR and Royal Decree 723/2026 already apply.

Yes, if the system decides on working hours, tasks, pay, promotion, place of work or dismissal. Moreover, since 5 October 2026 this must be done in writing, explaining its criteria. Even an automated system is enough: it does not have to be AI.

It depends on the use. For example, according to the AEPD, one is needed in most cases when the processing meets two or more criteria on its high-risk list, and AI applied to people usually meets them. In fact, its September 2026 warning on AI in recruitment mentioned it expressly.

Yes, if the data transfer is covered. Usually the provider is certified under the EU-US Data Privacy Framework or the contract includes standard contractual clauses. You should also check whether it uses your data to train its models and how to disable it.

For prohibited practices, the AI Act provides for fines of up to €35 million or 7% of worldwide turnover; for most other infringements, up to €15 million or 3%. In addition, there are GDPR fines and, in employment matters, those under the Spanish Law on Social Order Infringements and Sanctions.

Free initial assessment

Want to know what applies to your company?

Tell us which tools you use and we will tell you where to start.