What's changing in AI, GDPR and the law.
Court rulings, regulator guidance, and what they mean in practice for firms handling client data.
What Is Private AI? A Plain-Language Explainer
'Private AI' gets used loosely — sometimes it means real on-premise inference, sometimes it just means a familiar logo on an enterprise contract. Here is the actual distinction, and why it matters.
On-Premise AI vs. Cloud AI: What Actually Changes
Not a case that cloud AI is bad — a plain accounting of what genuinely changes when inference moves onto hardware you own: cost, control, maintenance, and where each one is actually the better fit.
US v. Heppner: What It Means for Law Firms Using ChatGPT or Claude
On February 10, 2026, a federal judge ruled that a defendant's exchanges with Claude were not protected by attorney-client privilege. Here is what the ruling actually says, and what it changes for law firms.
Is ChatGPT GDPR-Compliant for Firms in Spain? The AEPD's Operational Sovereignty Doctrine, Explained
The Spanish Data Protection Agency (AEPD) has formalized 'operational sovereignty' as a GDPR Article 32 obligation. Here is what it actually requires, in plain terms, with sources.
The EU AI Act's August 2026 Deadline: What Actually Applies After the Digital Omnibus
The EU AI Act's high-risk obligations, originally due August 2, 2026, were pushed back by the Digital Omnibus. But Article 50 transparency rules were not delayed and took effect on schedule. Here is what changed and what didn't.
Spain's AESIA and the New AI Governance Law: What Firms Need to Know
Spain now has two regulators for AI use — the AEPD for data protection, and AESIA for AI itself, backed by a new Organic Law moving through Congress with fines up to €35M. Here's what's confirmed and what's still pending.
EU & Spain AI Regulatory Calendar: Every Confirmed Deadline
A living reference of every confirmed EU AI Act and Spain-specific AI regulatory deadline, from the dates already in force through 2030 — updated as new dates are confirmed or amended.