Does your company use ChatGPT, Copilot, or AI? Legal Requirements Under the AI Act in 2026 and How to Comply

A company that uses artificial intelligence and is adapting to the requirements of the AI Act of 2026 with legal guidance.

It’s likely that your company is already using artificial intelligence, even if no formal decision has ever been made to implement it.

A sales rep asks ChatGPT to improve a proposal for a client. Someone in administration uses Copilot to summarize a document. Marketing generates text or images using AI. Human Resources is testing a tool to sort resumes. A programmer uses a code assistant. And perhaps an employee copies information from clients, contracts, or internal documents into an AI tool to save time.

All of this may be happening without company management knowing exactly which tools are being used, what they’re being used for, or what information is being entered into them.

And that’s one of the main problems.

By 2026, using artificial intelligence in a company will no longer be solely a matter of productivity or innovation. It will also be a matter of regulatory compliance.

The European Artificial Intelligence Regulation—known as the AI Act—establishes obligations that affect not only large tech companies that develop AI models. It may also impose obligations on companies that simply use AI systems in their operations.

Furthermore, some of these obligations have been in effect since 2025, and as of August 2026, new provisions and oversight mechanisms have taken effect. European Digital Strategy

That is why the question many companies should be asking themselves right now is not:

“Do we use artificial intelligence?”

Otherwise:

“Do we know exactly how we’re using artificial intelligence and whether we’re using it correctly?”

The AI Act may also affect your company even if you don’t develop artificial intelligence

There’s a fairly widespread misconception: that the AI Act mainly affects companies like OpenAI, Microsoft, Google, or firms that develop their own models.

That’s not the case.

The Regulation distinguishes between different operators and expressly includes the role of the“deployer”: in simple terms, anyone who uses an AI system under their authority.

Therefore, a company may be subject to certain obligations under the Regulation even if it has not developed any algorithms or markets artificial intelligence products.

An SME that incorporates an AI solution into certain processes, a startup that automates part of its customer service, or a company that uses AI-based tools for certain decisions may fall within the scope of the Regulation.

However, this does not mean that using ChatGPT to draft an email automatically makes a company an operator of a high-risk system.

The AI Act specifically adopts a risk-based approach: obligations depend on which system is used, what it is used for, and what role the company plays in relation to that system. EUR-Lex

And this distinction is crucial.

So, can my employees use ChatGPT or Copilot?

Generally speaking, yes.

The AI Act does not prohibit companies from using generative AI tools.

The issue isn’t using AI in and of itself, but rather how it is used.

It’s not the same to use a tool to suggest three possible subjects for an email as it is to use a system to evaluate job candidates.

Nor is it the same to ask it to summarize public information as it is to feed it a confidential client contract.

Nor is using AI to generate ideas for a marketing campaign the same as letting a system make or influence decisions that affect employees, consumers, or third parties.

That’s why, from our perspective, one of the first mistakes a company should avoid is adopting a rule as simple as:

“ChatGPT can be used at this company.”

The correct legal question is much more specific:

Who can use which tool, for what purpose, with what data, and under what controls?

That’s where compliance really begins.

The AI Act obligations a company must review in 2026

Not all organizations will have the same obligations. However, there are several issues that virtually any company using AI should review.

1. Train employees who use artificial intelligence

This is probably one of the least well-known obligations.

Article 4 of the AI Act establishes obligations regarding AI literacy.

This requirement took effect on February 2, 2025. Following the amendments introduced in 2026, there remains an obligation for providers and those responsible for deployment to take measures to promote AI literacy among the people who use these systems on their behalf. Monitoring and enforcement of this obligation began in August 2026. European Digital Strategy

In practice, this means that it doesn’t seem enough to simply purchase a license for a tool and let each employee learn how to use it on their own.

Training should be tailored to how AI is actually used.

For example, a marketing department will need to understand issues related to content, intellectual property, personal data, and the review of results.

Human Resources will need to be particularly aware of the risks associated with decisions regarding candidates and employees.

The sales department should know what customer information it can enter and what it cannot.

And anyone who uses AI to analyze documents or generate information relevant to a decision should be aware of one fundamental fact: a convincing answer from an AI is not necessarily the correct answer.

The European Commission itself maintains a repository of AI literacy practices used by organizations, which includes in-person training, learning platforms, and other models. The Commission cautions, however, that simply copying one of these initiatives does not automatically demonstrate compliance. European Digital Strategy

Is it necessary to provide all employees with an official AI Act training course?

Not necessarily.

The regulation does not mandate a single course, certificate, or number of hours for all companies. In fact, the Commission’s current guidance clarifies that individuals are not required to reach a specific, uniform level of knowledge. European Digital Strategy

What matters is that the measures be reasonable, taking into account—among other factors—the knowledge and experience of the individuals involved and the context in which AI is used.

For this reason, a generic 20-minute training session sent to the entire workforce may be far less useful than providing department- and risk-specific training.

2. Know Which AI Tools Are Actually Being Used

Before drafting policies, protocols, or documents, there is a much more basic question:

What AI does your company currently use?

In many organizations, the actual answer doesn’t match management’s response.

The company may have a subscription to Microsoft Copilot, but some employees may also be using personal versions of ChatGPT, Gemini, Claude, or other tools.

This informal use of technology applications is commonly known as shadow IT. With the expansion of artificial intelligence, a similar problem has emerged: AI tools being used by employees without any corporate decision having been made regarding them.

From a compliance perspective, it is very difficult to control something the company doesn’t even know exists.

Therefore, an initial audit should identify, at a minimum:

  • What AI tools are used;
  • who uses them;
  • for what purpose;
  • what information is entered;
  • what results the system generates;
  • whether those results influence decisions affecting individuals;
  • which provider offers the service;
  • and whether there is human oversight.

You don’t have to start with a massive technology project.

For many small and medium-sized businesses, a well-done inventory can be the most important first step.

3. Establish an internal policy on the use of artificial intelligence

A company that allows the use of AI without basic guidelines exposes itself to problems that go far beyond the AI Act itself.

Let’s consider an example.

An employee needs to review a client contract. To save time, they copy the entire document into a public AI tool and ask it to identify the most important clauses.

They’ve saved fifteen minutes.

But they may have just entered personal data, confidential information, prices, commercial terms, or trade secrets into an external platform.

That risk isn’t addressed by simply telling employees to “be careful.”

It’s important to have an internal AI usage policy that clearly explains what is and isn’t allowed.

A good policy should specify which tools are authorized, what information must not be entered, when a human must review the results, which uses require prior authorization, and what to do if an incident occurs.

And it must be written in a way that the people who will actually use it can understand it.

A thirty-page protocol full of legal definitions that no one reads offers the company less protection than clear, well-known, and properly implemented rules.

4. Be very careful with personal data

Compliance with the AI Act does not replace the GDPR.

Both regulations may apply simultaneously.

If, in order to use an artificial intelligence tool, the company processes data from customers, employees, job applicants, suppliers, or other individuals, it must also analyze data protection regulations.

This becomes particularly important when employees enter names, email addresses, personnel files, work histories, conversations with customers, employee evaluations, or any other information that could be used to identify an individual into AI tools.

In certain high-risk systems, the AI Act itself expressly links the obligations of the entity responsible for deployment to the data protection impact assessment provided for in Article 35 of the GDPR. EUR-Lex

Therefore, purchasing an enterprise version of a tool may enhance certain safeguards, but it does not, in and of itself, eliminate data protection obligations.

The specific processing must be analyzed.

5. Avoid entering confidential information and trade secrets without proper oversight

This issue warrants separate discussion because not all confidential information constitutes personal data.

A company handles information that can be of enormous value even if it does not identify any individual:

business plans, profit margins, source code, internal processes, pending offers, negotiation strategies, unannounced projects, information about an acquisition, databases, or technical documentation.

Copying this information into an external tool without first reviewing its terms and settings can create an unnecessary risk.

Therefore, an AI policy should clearly classify what types of information can be used with each tool.

It is not enough to simply ask:

“Does it contain personal data?”

You must also ask:

“Would we feel comfortable sharing this information with a third party?”

6. Pay special attention to the use of AI in Human Resources

This is a particularly sensitive area.

The AI Act considers certain systems intended for use in areas such as hiring or selecting employees, making decisions that affect working conditions, promoting or terminating employment relationships, assigning tasks based on specific characteristics, or monitoring and evaluating employee performance and behavior to be high-risk. EUR-Lex

This does not mean that any Excel spreadsheet containing candidate data or any one-off use of ChatGPT by HR is automatically a high-risk AI system.

The system and its specific purpose must be examined.

But it does mean that a company should pay special attention if it uses artificial intelligence to:

screening resumes, scoring candidates, recommending hires, evaluating productivity, assessing employees, deciding on promotions, assigning specific tasks, or playing a significant role in employment decisions.

In addition, when the high-risk workplace system applies, the Regulation sets forth specific obligations to provide information to the affected workers and their representatives. EUR-Lex

Important: The timeline for high-risk systems has changed

This point warrants special attention because many of the articles previously published online may now contain outdated dates.

Following the regulatory changes of 2026, official information from the Commission currently sets the effective date for the rules applicable to certain high-risk systems listed in Annex III as December 2, 2027, while for certain systems integrated into regulated products listed in Annex I, the timeline extends to August 2, 2028. European Digital Strategy

Therefore, when dealing with a system that could be considered high-risk, it is advisable to analyze both its classification and the specific timeline that applies to it, rather than automatically applying a generic date.

7. Human oversight: “The AI said so” should not be enough

One of the most dangerous mistakes in implementing artificial intelligence is turning a support tool into an authority.

We’ve all seen AI results that seem extraordinarily certain but are wrong.

In a business context, this can have significant consequences.

An AI system may incorrectly summarize a contract, attribute something to a document that it does not say, generate a nonexistent reference, or misinterpret certain information.

When it comes to high-risk systems, human oversight takes on specific legal importance. The AI Act requires that the individuals responsible for such oversight possess adequate competence, training, and authority. EUR-Lex

But even outside of these scenarios, establishing human oversight is a sensible practice.

A simple internal rule can prevent many problems:

The greater the impact of a decision, the less likely we should be to automatically accept an AI’s response.

8. Disclose when a person is interacting with an AI

Since August 2026, the transparency obligations set forth in Article 50 of the AI Act have taken on particular importance.

Among other things, the Regulation stipulates that certain systems designed to interact directly with individuals must inform them that they are interacting with an AI, unless this is already evident under the circumstances. EUR-Lex

This is particularly relevant for companies that incorporate chatbots or virtual assistants into their websites, apps, or customer service channels.

If a customer reasonably believes they are speaking with a person when they are actually interacting with an automated system, it will be necessary to verify whether the solution complies with the corresponding transparency obligations.

Article 50 also sets forth specific rules for certain types of artificially generated or manipulated content. EUR-Lex

What happens if my company only uses ChatGPT to draft texts?

There’s no need to panic here.

If a company uses a generative tool to help draft emails, prepare drafts, summarize non-sensitive information, or generate ideas, that does not automatically mean it is using a high-risk system.

But it also doesn’t mean it can ignore any obligations.

It may still be necessary to review issues such as:

staff AI literacy, data protection, confidentiality, intellectual property rights, the vendor’s contractual terms, and oversight of the results.

That is precisely why it is unhelpful to classify a company’s situation simply as “compliant” or “non-compliant” based on whether it uses ChatGPT.

What matters is understanding what the company is actually doing with the tool.

What AI practices are prohibited?

The AI Act does not merely distinguish between standard systems and high-risk systems. It also establishes certain prohibited practices deemed incompatible with the level of protection required in the European Union.

These prohibitions took effect on February 2, 2025. European Digital Strategy

Among the regulated practices are certain manipulative or deceptive techniques, certain uses aimed at exploiting people’s vulnerabilities, certain social scoring systems, and some particularly sensitive biometric uses, among others.

Not all of these situations will be common in a Spanish small or medium-sized business.

But precisely because the consequences can be significant, a company that intends to implement advanced systems for behavioral analysis, biometrics, emotion recognition, or automated decision-making should conduct a legal review of the project before putting it into operation—not after it has already been deployed.

What fines does the AI Act provide for?

This is probably the section that generates the most headlines, but it is also one of the most prone to misunderstanding.

The Regulation provides for different levels of penalties depending on the nature of the violation.

For certain violations related to prohibited practices, fines may reach 35 million euros or, in the case of companies, up to 7 percent of their annual worldwide revenue for the previous fiscal year, whichever is greater.

Other violations subject to the provisions of Article 99 may result in fines of up to 15 million euros or up to 3% of annual global turnover, whichever is higher. There is also a specific penalty for certain incorrect, incomplete, or misleading information provided to the authorities. EUR-Lex

This does not, of course, mean that an SME will automatically receive a fine in the millions simply because an employee misused ChatGPT.

The penalty regime itself provides for circumstances that must be taken into account, and the Regulation contains specific rules regarding fines applicable to companies, including SMEs. EUR-Lex

But the figures help illustrate one thing:

artificial intelligence is no longer an area where a company can improvise indefinitely without considering its compliance.

How to Adapt Your Company to the AI Act by 2026

If your company currently uses ChatGPT, Copilot, Gemini, Claude, or other AI solutions, there’s no need to start by creating a hundred documents.

It’s better to start by understanding the reality.

At Martínez Caballero Abogados, we would generally structure a compliance process around the following issues:

  1. Take inventory of the AI systems in use, including those that employees have started using on their own initiative.
  2. Identify actual uses. It’s not enough to know the name of the application; you need to know how the company uses it.
  3. Classify the legal risk of each use. A text-drafting assistant does not necessarily pose the same risks as a tool used to evaluate candidates.
  4. Review the data and information being entered. This is especially true for personal data, customer documentation, trade secrets, and confidential information.
  5. Analyze suppliers and contracts. It is important to know what service is being contracted, under what conditions, and what happens to the information provided.
  6. Create an internal AI policy. It should be clear, practical, and tailored to the company’s operations.
  7. Train employees. Not only on how to get better answers, but also on which uses pose risks.
  8. Establish human oversight. Especially for processes that could significantly affect people or the business.
  9. Document the measures taken. A policy that exists only in a forgotten file does not demonstrate actual implementation.
  10. Review the system periodically. Tools change, employee practices change, and the regulatory framework is also evolving.

A practical example: an SME with 40 employees that uses AI

Let’s imagine a company with 40 employees.

The marketing department uses ChatGPT to draft posts.

The sales department uses Copilot to prepare proposals.

Administration uses AI to summarize documents.

And Human Resources has started testing a tool that screens resumes.

The company might make the mistake of treating all four cases exactly the same because they all use “artificial intelligence.”

However, legally, they do not necessarily carry the same level of risk.

The company should identify each tool and its purpose, verify what information is entered, review the processing of personal data, establish internal rules, and train employees.

And the use of AI in recruitment would warrant a much more in-depth, specific analysis due to its potential classification as a high-risk scenario under the Regulation.

This approach is far more useful than enacting a blanket ban on the use of AI.

Artificial intelligence can lead to enormous productivity gains. The goal of compliance should not be to prevent its use, but to enable its use without taking on unnecessary risks.

Mistakes We’re Seeing in Companies That Use Artificial Intelligence

There are some approaches that are best avoided.

“We have the enterprise version of ChatGPT, so we’re already compliant.”

Not necessarily. The product’s features can help, but compliance also depends on how the organization uses it.

“Employees only use it for work.”

That’s precisely why there’s a business risk. If it’s used in a professional context, it matters what information is entered and what decisions are based on its results.

“The final decision is always made by a person.”

The presence of a person does not automatically make any process safe. If that person systematically accepts the algorithm’s recommendation without any real ability to question it, oversight may be merely a formality.

“We’re an SME; the AI Act is for big tech companies.”

The Regulation sets out obligations for various stakeholders and is not limited to large companies that develop models.

“When it becomes mandatory, we’ll adapt.”

Some obligations have been in effect since February 2025, and others become enforceable as of August 2026. European Digital Strategy

Checklist: Should my company review its use of artificial intelligence?

There’s an easy way to do an initial check.

If you answer “no” or “I don’t know” to several of these questions, it’s probably worth taking a closer look:

  • Do we know which AI tools our employees use?
  • Have we identified the purpose for which each one is used?
  • Do we know if employees enter personal data?
  • Do we know if they enter contracts or confidential information?
  • Do we have authorized and unauthorized tools?
  • Is there an internal policy on the use of AI?
  • Have employees received training tailored to their use of AI?
  • Do we use AI in hiring or employee management?
  • Do we use it to make or support decisions about customers or users?
  • Do we have chatbots that interact directly with customers?
  • Is there a person responsible for monitoring specific outcomes?
  • Would we be able to explain and document to an authority what measures we have taken?

Not every company needs to set up a massive compliance structure.

They should, however, be able to demonstrate that they understand how they use AI and have assessed its risks.

Frequently Asked Questions About the AI Act and Businesses

Is compliance with the AI Act mandatory in Spain by 2026?

Yes. The Artificial Intelligence Regulation is a directly applicable European Union regulation, and several of its provisions are already enforceable. The first obligations took effect in February 2025; others took effect in August 2025; and a substantial portion of the framework took effect in August 2026. Certain provisions regarding high-risk systems currently have later implementation dates. European Digital Strategy

Can a company use ChatGPT?

Generally speaking, yes. The AI Act does not establish a blanket ban on ChatGPT or generative AI in companies. What matters is analyzing the specific use, the information being processed, and any obligations that may apply.

Do I have to train my employees on artificial intelligence?

If the company falls under the obligations of Article 4 as a provider or deployer, it must take measures to promote AI literacy among the people who use these systems on its behalf. This obligation takes effect in February 2025. There is no single mandatory course for all companies. European Digital Strategy

Do I need an internal policy on the use of ChatGPT and AI?

There is no general rule that literally states that every company must have a document titled “ChatGPT Policy.” However, establishing and documenting internal rules can be a very useful measure for managing obligations related to AI literacy, data protection, confidentiality, and the oversight and control of tool usage.

Is using AI to select employees high-risk?

Certain AI systems used for hiring, recruitment, employment decisions, task assignment, or employee evaluation are included among the high-risk use cases listed in Annex III. It is necessary to analyze the specific purpose and operation of the system and to take into account the current timeline for the implementation of these obligations. EUR-Lex

Does the AI Act replace the GDPR?

No. The AI Act coexists with data protection regulations and other applicable rules. A company may comply with certain obligations under the AI Act and yet still process personal data in a manner that requires correction.

What happens if an employee uses AI without the company’s permission?

It depends on the case, but this is precisely one of the reasons why it is advisable to establish authorized tools, internal policies, and training. Banning a specific application also does not necessarily prevent other similar tools from appearing.

When is it advisable to conduct a legal audit of AI?

Especially when the company already uses multiple tools, processes confidential information or personal data through them, uses AI in Human Resources, automates decisions affecting individuals, incorporates chatbots, develops its own solutions, or plans to implement a new system with significant impact.

The Real Risk in 2026: Using AI Without Knowing How It’s Being Used

Artificial intelligence is already part of the day-to-day operations of many companies.

Trying to eliminate it entirely is probably neither realistic nor, in many cases, desirable.

But allowing every department or employee to use any tool, enter any information, and trust any result is not a sustainable strategy either.

The AI Act requires companies to begin addressing artificial intelligence as they have previously done with other areas of compliance: identifying risks, establishing responsibilities, training staff, and being able to demonstrate the measures taken.

And not all companies need exactly the same thing.

An SME that uses ChatGPT for support tasks does not necessarily require the same level of compliance as a company that uses algorithms to screen employees, evaluate customers, or automate decisions.

Therefore, before creating unnecessary documentation, it makes sense to determine exactly which AI the company is actually using and what obligations arise from those specific uses.

Does your company use ChatGPT, Copilot, or other AI tools?

At Martínez Caballero Abogados, we advise companies, SMEs, startups, and entrepreneurs on the legal review of their artificial intelligence systems and tools and on their compliance with the AI Act, GDPR, and other applicable regulations.

We can help you identify existing AI uses within your organization, assess their level of risk, and prepare the necessary measures: tool audits, internal AI policies, contract reviews, data protection, employee training, and compliance protocols.

If your company is already using artificial intelligence and you’re not sure if it’s being used correctly, it’s better to review how it’s being used now than to discover the problem when an incident occurs.

Contact Martínez Caballero Abogados to review your company’s use of artificial intelligence and determine which provisions of the AI Act actually apply to your organization.

Carolina Pedraza
Attorney Specializing in Commercial Law
Martínez Caballero Abogados

Primary legal sources: Regulation (EU) 2024/1689, as consolidated in EUR-Lex; official information from the European Commission on the implementation timeline for the AI Act under the European Digital Strategy; criteria from the AI Office on artificial intelligence literacy under the European Digital Strategy; and information from the Commission on the obligations and implementation of the Regulation starting in August 2026.

Share this article: