Technical and organisational consultancy on Regulation (EU) 2024/1689: we inventory the AI systems your organisation uses, classify them by risk and set up the documentation, internal policies and training the law requires. It is not legal advice and does not replace a lawyer: it is the engineering and procedural work a law firm does not build.
What we cover
The work between the law and your systems
We have been building and running AI software in production from day one. We know what is inside each tool, which model drives it, what data it touches and what records it leaves. Compliance rests on that, not on filling in a template.
Every engagement starts with the inventory, because nothing can be classified without knowing which systems exist, and ends with material your team can maintain without us.
Inventory and risk classification
We locate every AI system in the organisation, including those that arrived without going through IT. For each one we record the model provider, its purpose, the data it handles, your company's role (provider or deployer) and a preliminary risk level.
Internal usage policies
A short, readable rulebook on what may and may not be done with AI: approved tools, data that never gets pasted into a chat, when human review is mandatory and who answers for each decision. Written to be read by everyone, not to be filed away.
Technical documentation
We put in writing what you have to be able to show: architecture, providers, purpose, input data, known limits, tests carried out and a version log. In a living format, updated whenever the system changes.
AI literacy training (Article 4)
Sessions for the people who use these tools every day: how they work, where they fail, what a hallucination is and when to stop and ask. With supporting material and an attendance record: Article 4 has applied since February 2025 and, without that record, there is no way to show it was met.
Transparency readiness (Article 50)
We review the interfaces, wording and outputs of each system so that people know they are talking to an AI or reading AI-generated content: on-screen notices, content marking and API response fields.
What we do NOT cover
Where our work ends
Saying it up front saves misunderstandings. There are two things this service does not do, and neither is an oversight: both require a professional qualification we do not hold.
Binding legal opinions
We do not issue legal opinions or sign formal advice. The risk classification we deliver is preliminary and technical: it is there to work from and for a lawyer to validate, never to replace that validation.
Representation before the AESIA
We do not act before the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) or any other authority, whether in a request for information or in enforcement proceedings. We prepare the material that will have to be submitted; defending it has to be your legal representation.
For those two we recommend engaging separate legal counsel, and we are glad to work alongside the firm you choose: we hand over the inventory, the technical documentation and the evidence, and they build their legal view from there. If you do not have a firm yet, look for one with a practice in data protection and digital law.
Contact
Tell us what you have running
Tell us in your message which AI tools you use and what for. With that we can tell you whether the engagement makes sense, what would be needed and how much work it is. A person from the team replies, with no obligation.
Service legal notice
This service is operational and technical consultancy on AI compliance. It does not constitute legal advice and does not replace the intervention of a qualified lawyer.
The regulatory references on this page are to Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence. Its text and its application timetable prevail over any summary published here.