In short
Every AI conversation sooner or later arrives at the same three questions. Where does our data end up? What does the law say? And who carries the responsibility if something goes wrong?
Below is the answer in plain language. This is not legal advice, and we are not a law firm. For your specific situation, consult your counsel, but with what follows you will hold that conversation far better prepared.
The AI Act in brief
The European AI Regulation classifies AI applications by risk. The greater the risk to people, the heavier the obligations. In practice most business applications, such as searching documents, reading invoices or processing orders, fall into the lighter categories.
It gets heavier for applications that affect people directly. Systems used in recruitment, selection, evaluation or decisions on promotion and dismissal fall into the high-risk category. More on our HR page.
WHERE DOES YOUR DATA RUN?
That is a choice, not a given. For every project we set out three things:
- Which data the language model gets to see. Often far less than people assume. For a knowledge base that is only the passages relevant to the question, not your whole archive.
- Where that happens. We work with the services of Anthropic and OpenAI, for which processing within Europe is available.
- What is retained. For business processing, your data is not used to train third-party models. That is set out contractually.
The application itself, the integrations and your database can run with us in Belgium, on our own servers, with monitoring and backups.
THE DATES TO KNOW
- Since February 2025 the prohibited practices and the AI literacy duty apply.
- Since August 2025 the rules for providers of general-purpose AI models apply.
- Since 2 August 2026 the transparency obligations apply, among others: people must know when they are dealing with an AI system and when content has been artificially generated.
- From 2 December 2027 the obligations for stand-alone high-risk applications apply. That date was moved by the Digital Omnibus, where August 2026 previously applied.
- From 2 August 2028 those obligations apply to AI embedded in regulated products.
In short: the postponement applies only to the heavy category. What already applies keeps applying.
GDPR: WHAT DOES NOT CHANGE
AI does not create a new privacy regime. The usual rules still apply, and they apply just as firmly:
- You need a lawful basis for the processing, as with any other system.
- You process no more data than is needed for the purpose.
- You put a processing agreement in place with every processor.
- Data subjects keep their rights of access, rectification and erasure.
- You inform the people whose data you process, including where AI is involved.
- For high-risk processing you carry out a data protection impact assessment.
GOOD TO KNOW
The practical point: most of the questions companies ask about AI and privacy are really questions about their existing data housekeeping.
Anyone who cannot say today who has access to which folder did not acquire that problem through AI. AI only makes it visible.
WHAT WE SET OUT IN EVERY PROJECT
- Which data is processed, where, and how long it is retained.
- Who has access, per role, carried across from your existing rights.
- Where a person must approve and where the agent works independently.
- A log of what was proposed and what was carried out.
- How the application identifies itself to customers, where applicable.
AI LITERACY: THE OBLIGATION OFTEN FORGOTTEN
The regulation requires organisations to ensure their people know enough about how AI works and where its limits lie. It is not a certificate you have to obtain, but it is something you must demonstrably arrange: an internal guideline on what staff may and may not put into an AI tool, and a moment where that was explained.
In practice that is often more urgent than the debate about risk classes, because in most companies staff are already using AI tools today, with or without permission.
YEARS OF .NET EXPERIENCE
PROJECTS DELIVERED
SUCCESSFUL ERP INTEGRATIONS
IN-HOUSE SPECIALISTS
Who is responsible?
As the user of an AI system you remain responsible for what happens to your customers' and employees' data, just as with any other software system. We are responsible for what we build and for the arrangements we make with you about it.
That is why we set those arrangements out in writing before the build starts, not afterwards. See how a project runs with us.
Why companies choose IDcreation
- The Belgian Defence has been our largest client for over ten years. What meets those security requirements will hold up with you.
- No standard package you have to bend to, but software that follows the way you work.
- Our own hosting in Belgium, with monitoring, backups and a single point of contact.
- Since 1996 we have built in Microsoft technology. One strong foundation makes us fast and thorough.















