AI Regulation
Do you use ChatGPT or other AI in your business? Your legal obligations explained
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Direct answer: yes, using ChatGPT or another AI in your business already has legal consequences, even if it is the free version and you only use it to write text. Two sets of rules apply to you at once: the RGPD (the EU data protection regulation, cited by this Spanish acronym), as soon as you put any personal data about a client or your team into the AI, and the new European Artificial Intelligence Regulation (Reglamento (UE) 2024/1689), which since 2 February 2025 already requires you to train whoever uses AI in their work. This guide, last reviewed on 16 July 2026, explains what is enforceable today, what changes on 2 August 2026 and how to get in order without complicating your life.
This article is general information. It does not replace the advice of a lawyer or a specific analysis of your business: use it as a map, not as a legal opinion.
Contents
- Does using ChatGPT already make you responsible for anything?
- What does the RGPD require if you put data into an AI?
- What does the new European AI Regulation add?
- What is obligatory already, today?
- What changes on 2 August 2026?
- Do you use AI to make decisions about people? That is different
- Who supervises this in Spain, and what happens if you do not comply?
- Checklist: get your use of AI in order in 15 minutes
- Frequently asked questions
- Official sources
Does using ChatGPT already make you responsible for anything?
Yes. You do not need to have "signed up" for anything or to be using a paid plan: the moment you or someone on your team types a question into ChatGPT, Copilot, Gemini or any other AI for work, that tool is already part of your business in legal terms.
Two questions determine what you have to do:
- Do you put personal data into the AI? Names, emails, client histories, CVs, your team's data. If the answer is yes, the RGPD comes into play (next section).
- How do you use the AI? Writing a draft email is not the same as using it to decide who you hire or who you grant a loan to. The new European AI Regulation grades obligations according to the risk of the use, not according to the tool.
Most small businesses —a restaurant that uses AI to write the menu, a hairdresser drafting social media posts— are on the lightest tier of both sets of rules. But "light" is not "zero": there is one obligation that is already enforceable for everyone, whatever the size of the business, and we explain it in section 4.
What does the RGPD require if you put data into an AI?
Reglamento (UE) 2016/679 (RGPD) does not mention artificial intelligence, but it applies just the same: for the law, an AI that processes personal data is a data processing operation like any other. The AEPD (Spain's data protection authority) explains this in its guide «Adecuación al RGPD de tratamientos que incorporan Inteligencia Artificial»: before putting personal data into an AI, you have to have a legal reason to use it, provide adequate information and apply reasonable security measures, just as you would with any other software.
In practice, for a small business this comes down to three simple rules:
- Do not put more data into the AI than is necessary. If you ask ChatGPT to help you draft a reply to a client, there is no need to paste the whole email with their name, phone number and address: you can summarise the situation without the data that identifies them.
- Check whether the tool stores what you write and, if you have the choice, turn off history or the use of your conversations to train the model. Many AI tools allow this in their privacy settings.
- If the tool processes personal data of your clients or your team on your behalf, it is a processor (art. 28 RGPD), just like your hosting provider or your gestoría (the Spanish firm that handles a business's accounting and paperwork). Check whether the AI provider offers a data processing agreement: if it has one and you accept it, you formalise the relationship; if there is none, or you cannot review it, that is a signal to be careful about what you share with it. You can see how this contract works in our guide on the data processor contract.
No answer generated by an AI should become part of a document, a contract or a communication to a client without a person reviewing it first. This is not just prudence: if something goes wrong, the one answerable to the AEPD is still your company, never the AI.
What does the new European AI Regulation add?
Reglamento (UE) 2024/1689, known as the Artificial Intelligence Regulation or "AI Act", is a different rule from the RGPD: it does not regulate only personal data, but the use of artificial intelligence in general, with obligations that depend on the risk of each use. It was published on 12 July 2024 in the Official Journal of the European Union and entered into force on 1 August 2024, but its obligations do not all arrive at once: they apply on staggered dates until 2027.
For a business that uses AI as support (writing text, summarising information, generating images) the obligations are light. They become more demanding only if you use AI to make decisions that directly affect a person, as we will see in section 6.
What is obligatory already, today?
Since 2 February 2025 two blocks of the AI Regulation have been enforceable:
- Absolute prohibitions (art. 5). Certain uses of AI are prohibited throughout the European Union: manipulating people in ways they cannot notice, scoring people socially, or using emotion recognition at work or in educational settings (save for closed-list medical or safety exceptions). These are practices that almost no small business uses, but it is worth knowing that they exist and that they have been prohibited since that date.
- AI literacy (art. 4). This is the one that does affect you, with no exception for size: if someone on your team uses an AI tool for work, they have to know the basics about it —what it is for, what can go wrong (an AI can make up facts, which is called a "hallucination") and what they must not do with it, such as putting a client's confidential information into it. You do not need a course: a clear 10-minute explanation and the rules in this article already cover the required minimum.
This second point is law already in force, not a future recommendation. It is also the first document Tranquilia generates in its AI module: the register of AI systems you use, with the usage policy and your team's training already drafted.
What changes on 2 August 2026?
2 August 2026 is the date on which the AI Regulation rolls out most of its obligations, including one that directly affects many businesses: the transparency obligation in Article 50. From that date, if you have a chatbot or a voice assistant that speaks or writes directly to your clients, you have to tell them they are talking to an artificial intelligence, clearly and from the start. A visible sentence such as "This chat uses artificial intelligence" is already enough. The same applies if you generate images, audio or video with AI and publish them in a way that could be confused with real content: they have to be marked as AI-generated.
Before that date, on 2 August 2025, the governance rules and the obligations for those who build the largest AI models (such as OpenAI, Google or Anthropic) already came into force. This does not require anything directly from you as a user of the tool, but it explains why these companies are asking you for more and more information about how they handle your data and are publishing more documentation about their models.
One last date, 2 August 2027, affects only manufacturers of regulated products (for example, medical devices or vehicles) that incorporate high-risk AI: it is not relevant to a services or retail business.
Do you use AI to make decisions about people? That is different
The AI Regulation reserves its highest level of demands for what are called high-risk uses, listed as a closed list in its Annex III. The ones that occur most in an SME are:
- Screening CVs or rejecting candidates automatically.
- Evaluating your team's performance with the help of an AI, if the result has real consequences (promotions, dismissals, shifts).
- Deciding automatically about a person with no human involvement: granting or refusing a service, a discount or credit.
If your business does any of this, the AI literacy in section 4 is not enough: you need specific support before carrying on with that system, because the Regulation requires reinforced measures (technical documentation, effective human oversight, risk management). In addition, if an AI takes a fully automated decision about a person without anyone reviewing it, that person has the right to ask for a human being to review it (art. 22 RGPD). Talk to your gestoría before automating this kind of decision: it is the only part of this article where "do it yourself" is not the right advice.
Who supervises this in Spain, and what happens if you do not comply?
In Spain two authorities coexist with different roles. The AEPD (Agencia Española de Protección de Datos) remains the one that supervises whether you handle personal data correctly, whether or not you use AI. The AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), based in A Coruña, is the authority designated in Spain to supervise compliance with the AI Regulation itself (art. 70 of the Regulation).
The AI Regulation itself sets the maximum penalties at European level, in three tiers according to the seriousness of the breach (art. 99): up to 35 million euros or 7% of annual worldwide turnover for the prohibited uses in art. 5; up to 15 million or 3% for the remaining obligations (including the transparency in art. 50 and high-risk uses); and up to 7.5 million or 1% for giving false or misleading information to the authority. In all three cases the higher of the two figures applies, with one exception in your favour: for SMEs and start-ups, the law uses the lower of the two figures, not the higher, as a proportionality criterion.
Spain is still finishing the job of fitting this regulation into its own legal framework: on 26 May 2026 the Government approved the draft Ley Orgánica para el buen uso y gobernanza de la IA, which is still going through parliament and may change through amendments before it is passed. The definitive Spanish penalty regime is therefore not yet settled.
In practice, those European figures are the legal ceiling, not the norm: as with the RGPD, the penalty is graded according to the seriousness, the size of the business and whether you have cooperated. The best-known specific case to date is not Spanish: Italy's data protection authority (Garante per la protezione dei dati personali) fined OpenAI 15 million euros on 20 December 2024, not under the AI Regulation —which was not yet applicable— but for breaches of the RGPD: failure to notify a security breach in March 2023, processing personal data to train ChatGPT without an adequate legal basis, lack of transparency towards users and the absence of age verification. It is a real, public case, not a threat: it helps you understand what the authorities really look at, not to frighten a business that only uses ChatGPT to write an email.
Checklist: get your use of AI in order in 15 minutes
- [ ] Write down every AI tool you use in the business: ChatGPT, Copilot, an image generator, a machine translator, a camera with recognition. It is the first step of your register of AI systems.
- [ ] Do not put more personal data into the AI than is necessary: summarise the situation without full names, NIF (the Spanish tax identification number) or histories if it is not needed.
- [ ] Explain to your team, in 10 minutes, what can go wrong with AI (hallucinations, data leaks) and what must never be put into it. It has been obligatory since February 2025 (art. 4 of the AI Regulation).
- [ ] If a client talks to a chatbot of yours, add a visible sentence such as "This chat uses artificial intelligence".
- [ ] Never copy an AI answer directly into a contract or a communication to a client without a person reviewing it first.
- [ ] Check whether the tool offers a data processing agreement and formalise it if you put personal data into it.
- [ ] If you use AI to make decisions about people (recruitment, performance evaluation, credit), stop and consult your gestoría before going any further.
- [ ] Note the date of this review and go over it every time you start using a new AI.
With these eight points you have the minimum defensible basis. It does not replace a tailored analysis if your business uses AI intensively or for automated decisions about people.
Frequently asked questions
Do I need to ask my clients for permission to use ChatGPT?
No, generally speaking. What you need is a legal reason to process their data if you put it into the tool, and to inform them about your data processing as you already do with any other software you use (art. 13 RGPD). You do not need specific permission just for using AI, unless that particular use requires it (for example, consent for processing a special category of data).
Can I paste a client's email into ChatGPT so it helps me draft the reply?
Better avoid pasting the whole email with data that identifies them. Summarise the situation without name, phone number or contact details: "a client is asking about the delivery time for their order" works just as well for the AI to help you, and you minimise the data you share with it.
Does the free version of ChatGPT carry the same obligations as the paid one?
Yes. The AI Regulation and the RGPD do not distinguish between free and paid plans: what matters is what data you put in and what you use the tool for, not how much you pay for it.
My business is very small, does this really affect me?
Yes, even if you are self-employed with no employees. The AI literacy obligation (art. 4) applies to anyone who uses AI for work, whether or not they have a team. What changes with the size of the business is the proportionality of any eventual penalty, not whether the obligation exists.
Can I already be fined for using AI without having done any of this?
The obligations in force today are those of art. 4 (training) and the prohibitions of art. 5. The rest of the Regulation, including transparency towards clients, arrives on 2 August 2026. In practice, a small business that gets organised and corrects things when it spots a gap is not the usual scenario for a penalty.
Does this replace what the RGPD already asks of me?
No, it adds to it. If you use AI with personal data, all the RGPD obligations you already had still apply to you (record of processing activities, information clauses, the 72-hour deadline in the event of a breach) plus those of the AI Regulation.
Official sources
- Reglamento (UE) 2024/1689, de 13 de junio de 2024 — texto consolidado, EUR-Lex
- EUR-Lex — Resumen: normas para una inteligencia artificial fiable en la Unión Europea
- Reglamento (UE) 2016/679 (RGPD) — texto consolidado, EUR-Lex
- AEPD — Guía «Adecuación al RGPD de tratamientos que incorporan Inteligencia Artificial»
- AEPD — Infografía «Tratamientos que incluyen Inteligencia Artificial (IA)»
- AEPD — Orientaciones sobre IA agéntica desde la perspectiva de la protección de datos
- AESIA — Agencia Española de Supervisión de la Inteligencia Artificial
- La Moncloa — El Gobierno aprueba el proyecto de Ley Orgánica para el buen uso y gobernanza de la IA (26 de mayo de 2026)
- Garante per la protezione dei dati personali (Italia) — Comunicado sobre la sanción a OpenAI por ChatGPT (20 de diciembre de 2024)
Do you want your register of AI systems ready, with the usage policy and your team's training already drafted? Tranquilia's free tier covers up to 2 companies, with all features, with no time limit and no card. Try it free or check the prices if you need more companies.
If you also process personal data with your AI tool, have a look at our guide on the data processor contract as well.
Content produced with the support of artificial intelligence and verified against official sources (EUR-Lex, AEPD, AESIA, La Moncloa, Garante privacy Italia) by Tranquilia by GRAC SA. It does not constitute an official certification or a legal opinion. Consult your gestoría or a legal professional for your specific case.
Review: Tranquilia by GRAC SA — AI-assisted drafting with primary-source verification. Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.