PSL Avocat supports AI deployers, SaaS publishers and platforms in mapping their obligations, drafting contract documentation, negotiating LLM provider contracts and managing risks. Operational practice built on fifteen years of in-house advisory at international organisations. In French, English and Spanish.
Non-EU and EU-based AI vendors and providers selling to European customers: read our guide on what the Digital Omnibus on AI actually changes for your compliance calendar.
AI Act: phased application timeline
Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026, sets the final calendar of the AI Act. The dates below are definitive.
The Article 5 prohibitions and the AI literacy obligation (Article 4) apply since this date, unchanged.
The obligations on general-purpose AI models (Chapter V) apply since this date, unchanged. Models placed on the market before this date benefit from a transition until 2 August 2027 (Article 111(3)).
The AI Act enters into general application. The Article 50 transparency obligations apply. The Article 101 fines for providers of general-purpose AI models become applicable.
The new Article 5 prohibition of AI systems generating non-consensual intimate imagery or child sexual abuse material applies. The transitional period of the Article 50(2) machine-readable marking obligation ends for generative AI systems already on the EU market before 2 August 2026.
The high-risk obligations apply to AI systems listed in Annex III.
The high-risk obligations apply to AI systems embedded in products covered by Annex I.
HR AI and ed-tech: the two sectors on the front line
HR AI tool providers and ed-tech publishers fall within two domains explicitly listed in Annex III of the AI Act (education and vocational training, employment and HR management). High-risk classification is likely for the majority of use cases. The deployer carries obligations distinct from those of the provider, in addition to the GDPR baseline.
Adaptive learning platforms, automated scoring tools, AI tutors, exam monitoring systems, algorithmic guidance of learning pathways.
High-risk classification likely under Annex III for the majority of academic and university use cases.
Enhanced information to students and families, particularly where end users are minors (interaction between GDPR provisions on minors' data and AI Act transparency obligations).
Effective human oversight over any decision affecting assessment, guidance or selection.
LLM provider contracts reviewed to cascade deployer obligations downstream.
Sourcing tools, application scoring, video interview analysis, algorithmic performance management, turnover prediction, schedule optimisation.
High-risk classification likely under Annex III (recruitment, HR management).
Fundamental rights impact assessment prior to deployment (Article 27 AI Act FRIA obligation).
Information to candidates and employees on the existence and logic of processing (GDPR Article 14 and AI Act Article 50 from 2 August 2026).
Bias audit and test register, in the wake of the Foundever ruling of the Audiencia Nacional (SAN 2867/2025, 4 July 2025), subject to appeal before the Tribunal Supremo.
Information and consultation of employee representatives (France-specific: information and consultation of the works council under Article L.2312-38 of the Labour Code; Spain: Article 64.4.d of the Estatuto de los Trabajadores as amended by Law 12/2021).
Key decisions
Three decisions structuring current practice for AI deployers in France, Spain and at European level.
Article 22 GDPR applies to algorithmic scores produced by a third party and used to underpin an automated individual decision, even where the user of the score is not the one who calculated it. Direct read-across for HR AI and ed-tech deployers relying on third-party scoring tools.
Read the decisionFirst Spanish ruling recognising the right of employee representatives to access the parameters of algorithms used in employment relations. Alignment between French and Spanish law on transparency of automated assessment and algorithmic career management tools.
Read the decisionFirst major GDPR sanction against a generative AI provider in Europe. The decision establishes that training a large language model constitutes processing of personal data in its own right, subject to identification of a legal basis, information of data subjects and incident management. Central reference for any third-party LLM deployer.
Read the decisionNIS2: cybersecurity for essential and important entities
Directive (EU) 2022/2555 (NIS2) extends cybersecurity obligations to a significant number of tech companies, particularly managed service providers, cloud services, marketplaces and SaaS publishers exceeding SME thresholds. Essential and important entity categories are defined in Annexes I and II of the Directive. The transposition deadline was 17 October 2024. As of 12 May 2026, France and Spain have not completed transposition. In France, the bill on critical infrastructure resilience and cybersecurity reinforcement is before Parliament, with enactment expected during 2026. In Spain, the preliminary bill on Cybersecurity Coordination and Governance is under parliamentary review. The European Commission issued a reasoned opinion against both Member States on 7 May 2025 for failure to notify. Affected companies are nonetheless exposed to the Directive's regime and its direct vertical effect for unconditional provisions, as well as to requirements from European counterparties already applying NIS2 standards in their procurement specifications.
Are you in scope for NIS2?
Three binary questions. Three positive answers indicate likely applicability and justify a full analysis.
Does your activity fall within a sector listed in Annexes I or II of Directive 2022/2555 (energy, transport, banking, health, digital infrastructure, ICT managed services, cloud providers, marketplaces, search engines, social networks, manufacturing, research, etc.)?
Does your company reach the threshold of a medium or large enterprise (at least 50 employees or EUR 10 million annual turnover)? Certain entities are in scope regardless of size.
Are your services provided to at least one recipient established in the European Union?
Related regulations
Frequently asked questions
My company is established outside the EU but sells to European clients. Does the GDPR apply?
Yes. The GDPR applies as soon as you offer goods or services to individuals located in the Union, or monitor their behaviour, whether or not your company is established in Europe. In most cases you must also appoint a representative in the Union.
How do I know whether my AI system falls under the AI Act?
The AI Act classifies AI systems by risk level (unacceptable, high, limited, minimal). This classification determines the applicable obligations. A preliminary analysis quickly identifies what applies to your concrete situation.
What is the maximum penalty under the AI Act?
The AI Act provides for three tiers of administrative fines, depending on the nature of the infringement. Placing on the market or using an AI system presenting an unacceptable risk (for example generalised social scoring, or real-time facial recognition in public spaces for law enforcement purposes outside the exhaustively listed exceptions) exposes the operator to a fine of up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. Non-compliance with the other obligations, including those of providers and deployers and the transparency obligations for systems interacting with humans, is punishable by fines of up to 15 million euros or 3 percent of turnover. Supplying incorrect, incomplete or misleading information to authorities or notified bodies exposes the operator to a fine of up to 7.5 million euros or 1 percent of turnover. For SMEs and start-ups, each fine is capped at the lower of the fixed amount and the turnover percentage.
Our company deploys a third-party LLM (OpenAI, Anthropic, Mistral). What are our obligations?
Your obligations depend on how your use case is classified, not on the fact that the model comes from a third party. Outside the high-risk category, the deployer must take measures to support the development of AI literacy among its staff, and comply with the transparency obligations of Article 50 where they apply, in particular informing individuals exposed to content generated or manipulated by the system. For a use case classified as high-risk (recruitment, education, creditworthiness assessment), the regime is considerably heavier: use in accordance with the provider's instructions, human oversight assigned to competent staff, relevance of the input data you control, retention of the logs the system generates, and informing affected workers before any use in the workplace. These obligations apply from 2 December 2027 for the cases listed in Annex III and from 2 August 2028 for AI embedded in regulated products, following the postponement introduced by Regulation (EU) 2026/1744. The fundamental rights impact assessment and registration concern only certain deployers, mainly public bodies, private entities providing public services, and credit and insurance operators. Mapping your use cases determines which of these two regimes applies to you.
We already have a data protection policy. Are we compliant?
Not necessarily. GDPR compliance does not come down to a document published on your website. It involves internal organisation, contracts with your processors, management of data subject rights and the capacity to respond to incidents. A quick audit identifies the real gaps.
How long does GDPR compliance take?
As an indication, for an SME or a start-up, a first level of operational compliance can be reached in 4 to 8 weeks depending on the complexity of the processing activities.
DSA and DMA: is my company a covered platform?
The DSA applies to any digital platform offering services to users in the EU: marketplaces, social networks, content platforms, search engines, hosting providers. Obligations vary with size. The DMA targets a narrower scope: the gatekeepers designated by the European Commission. If you are not a designated gatekeeper, the DMA does not apply to you directly, but it can affect your conditions of access to the platforms that are.
What is the Data Act and who is covered?
The Data Act (Regulation (EU) 2023/2854, applicable since September 2025) governs access to data generated by connected products and related services. It mainly concerns manufacturers of connected products (IoT), providers of digital services linked to those products, and providers of data processing services (cloud, edge). Its objective is to allow users, both individuals and companies, to access the data their equipment generates and to share it with third parties of their choice.
Related articles on the blog
Last updated: 28 July 2026.
Request a first call
Describe your need in a few lines. Response within 24 business hours.
