This file is automatically generated from the application's real texts. It is optimized so that Artificial Intelligence agents and crawlers (such as NotebookLM, ChatGPT, Claude, etc.) can read the website's information without needing to render JavaScript (SPA).
Versión en Inglés (EN)
1. Propuesta de Valor (Hero)
- Badge: Verify your compliance with European Digital Regulations 2026
- Título: Protect your company from multi-law sanctions in 3 minutes.
- Descripción: On August 2nd, Article 50 of the AI Act comes into force. Analyze anonymously and easily the exposure level of your digital infrastructure against the AI Act, EAA (Accessibility), Data Act, and CRA. Download 1 year of free license for our Local Anonymization Firewall.
- Alfabetización en IA (AI literacy training for your team): In force
- Transparencia (Transparency for bots, assistants, content, and emotion or biometric recognition): Upcoming
- Nota: ⚡ No registration · No company data · Immediate results on screen.
2. Autoevaluación Anónima (SelfEval)
- Título: How exposed is your digital infrastructure?
- Descripción: No technical or legal knowledge required. Answer honestly about the tools your team uses day-to-day.
- Nota: ⚡ No registration · No company data · Immediate results on screen.
3. Tabla Comparativa: Why secure your infrastructure with Checkpoint IA?
- Columna A: Copying a Generic Checklist
- Columna B: Checkpoint IA Environment ✦
- Technical Analysis: Theoretical, does not read your front-end code. vs. Scan of your interfaces and detection of opaque bots.
- Data Governance: Tells you what the law prohibits but not how to prevent it. vs. Delivery of a Local Firewall to anonymize everything uploaded to AI through your network before it leaves the company.
- Implementation: You have to draft and interpret everything from scratch. vs. Structured Playbook with direct tasks ready for your technical team, including training.
- Technical Solution: Abstract legal concepts only. vs. Local security software (Docker) and code patches.
- Continuity: Ends at initial diagnosis. vs. Automated updates for regulatory changes and ongoing technical support.
- Action Plan: No validity before authorities. vs. Generation of your Compliance Dossier defensible before AESIA, AEPD, and other regulatory inspections.
4. Cobertura del Dossier de Cumplimiento (What your Compliance Dossier covers)
Every item is designed to be defensible before a real inspection by European regulatory authorities.
- AI Act (Art. 50): Legal notices and synthetic content labeling
- AI Act (Art. 4): Team literacy plan and training record logs
- European Accessibility Act (EAA): E-commerce accessibility verification (EN 301 549)
- Cyber Resilience Act (CRA): Fast vulnerability reporting protocol (<24h)
- Data Act: Cloud contract auditing and data portability
5. Catálogo de Servicios (Don't have time to implement the playbook? Delegate the problem to us.)
In addition to our free diagnosis, we offer turnkey technical services to shield your company without interrupting your day-to-day operations.
- EAA Accessibility Audit: We audit your e-commerce or digital checkout flow to comply with EN 301 549 standards before June 28, 2025.
- Training & AI Literacy (Art. 4): We train your employees with role-based practical sessions and produce the mandatory documentation record required since February 2025.
6. Metodología de Trabajo (Our methodology)
We work directly from the text of Regulation (EU) 2024/1689, not third-party interpretations. Every diagnosis follows the same process a real inspection from the Spanish AI Supervision Agency (AESIA) would apply.
- Technical inventory, article by article
- Documented evidence, not just recommendations
- Language aligned with the Spanish and European regulatory framework
7. Preguntas Frecuentes (FAQs)
- Does the AI Act only affect technology companies?
No. The European Artificial Intelligence Regulation can affect any organization that develops, uses, or integrates artificial intelligence systems within its processes.
- If I already comply with the GDPR, am I ready for the AI regulation?
Not necessarily. The GDPR and the European Artificial Intelligence Regulation have different objectives. The GDPR primarily regulates the processing of personal data, while the AI Act establishes obligations related to the use, development, and management of artificial intelligence systems.
- Do I have to stop using ChatGPT or other AI tools?
No. The goal is not to eliminate the use of artificial intelligence, but to help use it responsibly, securely, and aligned with the organization's needs.
- Which companies should carry out an assessment?
Especially those organizations that: use AI in internal processes; employ AI assistants; use AI with clients or users; integrate AI in recruitment, customer service, or business decisions; or want to adopt AI in a structured manner.
- How much time does the process require?
It depends on the size of the organization, the number of tools used, and the complexity of the processes. The initial assessment allows defining the scope and establishing a tailored plan.
- Can AI be a competitive advantage?
Yes. Companies that incorporate artificial intelligence with clear processes, security, and a responsible vision will be able to better leverage their opportunities and reduce uncertainty.
- Is Checkpoint Ley IA a legal audit?
No. Checkpoint Ley IA provides technical, organizational, and process consulting services that prepare you for a legal audit. When a specialized interpretation is required, we recommend working with specialized legal professionals.
- Does Checkpoint Ley IA officially certify compliance with the AI Act?
No. Checkpoint Ley IA can carry out assessments and issue its own documentation on the process, but these assessments do not replace official certifications or conformity procedures that may be required under applicable regulations.
- What is Article 4 of the EU AI Act?
It requires companies to ensure their staff have a level of AI literacy proportional to their role and the context in which they use these tools. It has been in force since 2 February 2025 — it's not an August milestone, it's already enforceable today.
- What is Article 50, and why is August 2026 such a milestone?
Article 50 covers four transparency obligations: chatbots must disclose they are AI, synthetic content (images, videos, audio) must be labelled, systems using emotion recognition or biometric categorisation must inform users, and certain AI-generated texts of public interest must be identified. This is the obligation with a firm deadline: 2 August 2026.
- Is there a specific fine for not training my team?
Not directly. The Regulation does not set a standalone penalty for non-compliance with Article 4 — that decision is left to each member state. The real risk is indirect: if an untrained employee makes an error that leads to a transparency violation (Art. 50), that's where the larger sanctions apply — up to €15 million or 3% of global turnover.
- What should an internal AI use policy include?
At a minimum: an inventory of authorised tools, clear rules on what is and isn't allowed, data privacy guidelines, access controls, and a framework for human oversight of AI-driven decisions.
- Does my company need to carry out a FRIA?
Probably not. The FRIA (Fundamental Rights Impact Assessment) is only mandatory for public bodies, companies providing essential services (healthcare, energy, transport), and entities using AI to assess creditworthiness or set insurance prices. Most SMEs fall outside this specific obligation.
- What changed with the 'AI Omnibus'?
Obligations for 'high-risk' AI systems (recruitment, scoring, etc.) were postponed until December 2027. This does not affect Article 4 (already in force) or Article 50 (transparency, August 2026) — those two keep their original dates.
- Does the European Accessibility Act (EAA) affect my e-commerce?
Yes. As of June 28, 2025, digital services in the EU, including e-commerce, banking, and transport, must be accessible to people with disabilities, complying with technical standards such as EN 301 549 and WCAG. Only microenterprises with fewer than 10 employees and annual turnover under €2 million are exempt. Non-compliance can lead to tiered fines of up to €1,000,000 (applying the sanctioning regime of the General Disability Act RDL 1/2013) and the withdrawal of your products or services from the market.
- What is the Data Act and how does it affect my company's data?
The Data Act is the regulation that ensures fair access to data generated by connected products (IoT) and digital services. It obliges manufacturers to design products so users can access their data by default, free of charge, and in real time. Additionally, for companies using cloud services, it prohibits unfair lock-in clauses and forces providers to remove barriers and costs to switch providers easily.
- What fines do I face for non-compliance with the Data Act?
Although local penalty scale has not yet been published, European law requires sanctions to be effective and deterrent. If the infringement involves limiting access to or portability of personal data, data protection authorities will apply GDPR fines directly, reaching up to €20 million or 4% of your company's global annual turnover.
- Does the Cyber Resilience Act (CRA) apply to software or hardware we develop?
Yes. The CRA establishes that every product with digital elements (hardware or software) must be secure by design and protected against cyber threats throughout its lifecycle. This implies providing continuous security updates, clear documentation, and promptly reporting critical vulnerabilities or incidents to authorities. CRA sanctions can reach up to €15 million or 2.5% of global company turnover.
- Are there grants or financial aid available to adapt to these regulations?
Yes. SMEs can leverage initiatives such as Spain's Kit Digital and Kit Consulting programs. These programs subsidize digital solutions, cybersecurity improvements, and specialized AI advisory services, helping fund a major part of your compliance adaptation process without impacting your profitability (with vouchers ranging from €3,000 to €29,000).
- How do I legally prove I complied with the training requirement?
With documentation: a record of who attended, what was covered, on which date, and an internal AI use policy signed by the team. That is what gets reviewed during an inspection.
- How is Checkpoint Ley IA different from doing it ourselves?
A generic course doesn't account for the specific tools your team uses, nor does it generate a defensible inspection dossier. Checkpoint Ley IA starts from a real diagnosis of your company, trains each person according to their role, and delivers full documentary evidence of the process.