What you really risk using AI without a shield on your data.
The AI Act deadlines, the penalties that are already in force and the three regimes stacking up. Then seven concrete things to do, in order.
2 August 2026 came and went, and in most firms nothing happened.
That is not good news. It means a deadline was read as a formality, when in fact it changes how you answer a very concrete question: where did my client's data go?
The facts are worth laying out, because there has been a lot of confusion lately — in both directions. Some say anyone who opens ChatGPT faces a €35 million fine. Others concluded that since the high-risk rules were postponed, everything can wait until 2027.
Neither reading holds.
What changed, and what didn't
The AI Act — Regulation (EU) 2024/1689 — entered into force as a whole on 1 August 2024, but it applies in stages.
Already applicable:
- Since 2 February 2025: the prohibitions on banned practices (Art. 5) and the AI literacy obligation (Art. 4). The latter applies to anyone using AI systems in their organisation, regardless of risk level. Yes: including the three-person firm using a generative assistant to draft.
- Since 2 August 2025: obligations for general-purpose AI models (GPAI), national governance and — this is the point — the penalty regime under Article 99.
New a few weeks ago: on 27 July 2026 Regulation (EU) 2026/1744, the AI Omnibus, entered into force, simplifying and in several places rewriting the AI Act. It pushed back the high-risk rules: Annex III systems now apply from 2 December 2027, high-risk systems embedded in regulated products from 2 August 2028.
That is where the misunderstanding comes from. The delay made headlines, and many read it as "the AI Act has been postponed".
It hasn't, for three reasons.
First: the delay concerns one specific category of systems. The transparency obligations still apply from 2 August 2026 — informing people when they interact with an AI system, flagging artificially generated or manipulated content. The only concession is technical: for generative systems already on the EU market before 2 August 2026, machine-readable marking of outputs shifts to 2 December 2026.
Second: the Omnibus did not only postpone, it also added. From 2 December 2026 Article 5 will contain two new prohibitions — the generation of non-consensual intimate images and of child sexual abuse material — which fall into the highest penalty tier.
Third: the Article 99 penalties had already been operative for a year.
The penalties, in numbers
Article 99 of the AI Act sets three tiers.
| Breach | Maximum |
|---|---|
| Prohibited AI practices (Art. 5) | €35 million or 7% of total worldwide annual turnover |
| Other obligations under the Regulation (providers, deployers, importers, distributors) | €15 million or 3% |
| Incorrect, incomplete or misleading information to authorities | €7.5 million or 1% |
The higher of the two applies. For SMEs and startups the opposite criterion applies: the lower of the fixed amount and the percentage. That is genuine proportionality, but it is not a free pass — 3% of a partnership's or an SME's turnover is still a number nobody wants on their books.
Providers of general-purpose AI models face a separate channel: the European Commission can fine up to €15 million or 3% (Art. 101). Unlike the rest, that power only became exercisable on 2 August 2026: Article 113 had expressly carved it out of the 2025 deadline.
The real risk isn't the AI Act on its own
Here is the point most articles miss, and the one that actually matters.
Uploading a client's contract to a chatbot is not, in itself, an AI Act breach. The AI Act regulates AI systems: how they are built, how they must be declared, who has to know what. It is not the law governing the processing of personal data.
That is the GDPR. And that is where the serious problems start.
When you paste a client's name, a medical report, unfiled accounts or a candidate's CV into a non-EU cloud service, you are processing personal data. You therefore need:
- a legal basis (Art. 6, and for health or criminal data also Arts. 9–10);
- a data processing agreement covering that provider (Art. 28);
- adequate security measures (Art. 32);
- a valid mechanism for transfers outside the EU (Arts. 44–49);
- an updated privacy notice and a consistent record of processing activities.
GDPR fines reach €20 million or 4% of worldwide turnover.
And this is not theory — though the most-cited case teaches something different from how it gets retold.
By decision no. 755 of 2 November 2024, made public on 20 December, the Italian Data Protection Authority fined OpenAI €15 million in relation to ChatGPT. In a judgment filed on 18 March 2026 the Court of Rome annulled the decision. Not on the merits: on jurisdiction. Since February 2024 OpenAI has had a single establishment in the Union, in Ireland, and cross-border breaches are decided by the Irish lead authority through the one-stop-shop mechanism. The allegations — no legal basis for training, insufficient transparency, no age verification — were never examined by any court: the investigation continues in Ireland. In May 2025, by contrast, a €5 million fine went to Luka Inc. for Replika, on similar grounds.
Two things follow, both useful.
First: the question is open, not settled in anyone's favour. Second, and more relevant to you: those decisions concern providers. Anyone using those services with their own clients' data answers for themselves, before their own national authority, with no one-stop-shop to shelter behind.
The third layer, for Italian professionals, is Law no. 132 of 23 September 2025, in force since 10 October 2025. Article 13 sets out two things:
- AI may only be a support tool. It does not replace the intellectual work, the critical judgment or the direct responsibility of the professional.
- Information about the AI systems used must be communicated to the client in clear, simple and exhaustive language, to protect the relationship of trust.
The law prescribes no particular form. Professional bodies, however, consistently recommend giving it in writing and before the engagement, as an addition to the engagement letter, specifying the type of tool and whether it operates in a closed system or online. Not because the law requires it, but because in a dispute it is the only version you can actually prove.
On top of all this, for members of a professional body, come client confidentiality and ethical rules. Those have no turnover threshold: they have disciplinary proceedings.
Three regimes stacking up. None of them accepts "I didn't know the data was leaving" as a defence.
What actually happens inside firms
It is almost never a deliberate decision. It is a habit that forms over three months.
An associate is in a hurry. They paste a draft into the chatbot to tidy up the wording. It works, it saves forty minutes, and next time they paste the whole contract — names, addresses, amounts. Nobody told them in writing not to. Nobody explained it.
Six months later the firm no longer knows which documents left, when, to which provider, under which account — often a personal one.
That is the fragile point: not the fine itself, but the inability to reconstruct what happened. When an access request, a complaint or an inspection arrives, the question is always the same: show us what you did and why it was lawful. A firm that cannot answer has already lost, before anyone discusses amounts.
What you can share — and what you can't
There is one practical rule: before hitting send, ask whether that text allows anyone to identify a person.
Must not leave unshielded:
- names, tax codes, addresses, contact details of individuals;
- health, criminal, biometric, trade-union data, or data on minors;
- client correspondence covered by privilege;
- contracts, deeds and expert reports with the parties identified;
- unfiled accounts, financial data traceable to a specific subject;
- CVs, appraisals and data on employees or candidates;
- third-party data the client entrusted to you — their employees, counterparties, suppliers.
Safe to share:
- legislation, published case law, official guidance;
- template clauses and standard forms, without the parties;
- method questions — how do you structure an indemnity clause, what line items make up a statement;
- genuinely anonymised documents, meaning stripped of anything enabling re-identification;
- aggregated data that cannot be traced back to an individual;
- already public information: filed accounts, company records, registered deeds.
Watch out for a common trap: removing the name is not enough. "The minority shareholder of the Serravalle transport cooperative who challenged the March resolution" identifies a person just as effectively as a tax code. Anonymisation is either systematic, or it is an illusion.
Seven things to do, in order
- Take stock of what is already in use. Don't ask "do we use AI?". Ask each person which tools they open, under which account, and for which documents. The answers are almost always surprising.
- Write a one-page policy. Permitted tools, forbidden data, who authorises exceptions. One page that gets read beats twenty that get filed.
- Support your people's AI literacy. This is not best practice: it is Article 4 of the AI Act, applicable since February 2025 and rewritten by the Omnibus. In the version now in force it requires providers and deployers to take measures to support the AI literacy of anyone operating the systems on their behalf, calibrated to skills, context of use and the people involved. It no longer requires guaranteeing a specific level — but it remains an obligation, and what you don't document, you can't demonstrate.
- Update the client notice. Article 13 of Law 132/2025: clear, simple, exhaustive. In writing and before the engagement, as professional bodies recommend.
- Fix the contracts upstream. Processor appointment, safeguards for non-EU transfers, confirmation that the provider does not use your inputs to train its models.
- Update your records and assessments. The record of processing activities must include AI use. Where processing is risky, you need a DPIA.
- Keep a trail. Who used what, on which data, with what outcome. Compliance is not a state: it is evidence you must be able to produce.
None of these seven requires a meaningful budget. It requires a decision.
The technical problem behind the legal one
So much for the law. But there is a technical reason these obligations are so hard to meet, and it should be said plainly.
The most capable AI tools are cloud services. To use them, the text has to leave your computer. From that moment, compliance depends on contracts, notices and clauses — that is, on paper describing a behaviour, rather than a mechanism preventing it.
The choice the market has offered so far was binary: powerful models with your data outside, or your data safe with less capable models. Most professionals chose power and stopped asking the question.
That is not a moral failing. It is that nobody put the shield in the right place — before the data leaves, not afterwards, in a contract.
Podz.AI: the cloud, without your client's data
That is exactly the problem we set out to solve with Podz.AI, the personal AI workstation built on our DigiSense® framework.
Podz is a single application you install on your computer — Windows, macOS, Linux. Conversations and documents stay there, in a folder you own, with an encrypted database. The cloud is not the default behaviour: it is a choice, every time.
You work with a local, private engine that runs even offline. When you need more capability, you switch on the Cloud engine with frontier models like Claude or GPT, using your own key: G&G does not resell the service and does not sit between you and the provider.
And this is where the Anonymizer comes in — the heart of the matter.
Before the text leaves your computer, personal data is masked:
On your computer: Mr Mario Rossi, born in Rimini on 3 April 1980, residing at 12 Garibaldi St., declares that…
What the cloud provider sees: Mr [NAME-1], born in [CITY-1] on [DATE-1], residing at [ADDRESS-1], declares that…
In the answer you read, the real data is restored automatically. The cloud provider never saw it.
Around this sit specialists you install with one click, like apps: Legal Assistant (reads contracts, flags risky clauses, anonymises), Web Researcher (answers while always citing its sources, also available fully local), CV Screening (masks identifying data before review, so applications are judged on merit — which also helps against bias).
You only ever talk to Podz. It brings in the right specialist and shows you, in the chat, who worked and what was protected.
One clarification we insist on, because it is the same one we put on the product site. Anonymisation is strong protection, not a legal guarantee. No software makes you automatically compliant with the AI Act, the GDPR or Law 132/2025: the compliance assessment remains yours, and it has to be done.
What changes is the substance. Personal data that never leaves your computer is not a transfer to justify, not a risk to mitigate by contract, not a line you will have to defend before an authority. It is a problem that never arose.
Documents are not used to train any model. They sit in a folder you own: copy it and you have a backup, move it and you take everything with you. Podz is built in Europe. The trial is 30 days, full features, from first launch.
A closing thought
The question I hear most often is: can we use AI with client data?
It is the wrong question. The right one is: where does the data end up when we do?
If the answer is "I don't know", the problem is not the AI Act. The AI Act merely put a price on something that was already risky.
The high-risk deadlines have moved to 2027 and 2028. There is time to get organised. But it is time to act, not to wait — because the AI literacy obligations, the transparency obligations, the rules on processing and the duty to inform the client are all already in force today.
People who work with confidential data don't need less artificial intelligence. They need artificial intelligence that doesn't expose them.
Sources
- Regulation (EU) 2024/1689 (AI Act) — Arts. 4, 5, 50, 99, 101, 113
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026 — EUR-Lex
- High-risk postponement (Annex III → 2 Dec 2027; regulated products → 2 Aug 2028) — Iusletter
- Obligations from 2 August 2026, the rewriting of Art. 4, new prohibitions and the start date of Art. 101 — Altalex
- Art. 26 AI Act, deployer obligations — AI Act Service Desk, European Commission
- Article 50 transparency and the marking deadline of 2 December 2026 — European Commission, Shaping Europe's digital future
- Law no. 132 of 23 September 2025, Art. 13 — text of the article; commentary in Altalex
- Garante fine against OpenAI (decision no. 755 of 2 November 2024, €15m) — Garante per la protezione dei dati personali; annulled by judgment of the Court of Rome filed on 18 March 2026 — Altalex, Il Sole 24 Ore
- Garante fine against Luka Inc. for Replika (€5m, 19 May 2025) — Garante per la protezione dei dati personali
- Podz.AI — features, Anonymizer, specialists, FAQ — product site
This article is for information purposes only and does not constitute legal advice. For your specific situation, consult a qualified professional or your professional body.
Where to go next
Want to know where your firm's data ends up?
Tell us how you work today and which tools you use. A person from the team answers, not a form.