This Artificial Intelligence Policy (hereinafter, the "AI Policy") sets out the principles, commitments and limits governing the use of artificial intelligence (AI) systems at PASSAS, both in the internal management of the firm and in the services provided to clients.
It is a public document. Its publication reflects the commitment of PASSAS to transparency in the use of AI and to proactive compliance with Regulation (EU) 2024/1689, whose general date of application is 2 August 2026, without prejudice to the staggered timetable resulting from its amendment by the Digital Omnibus AI Regulation.
The use of artificial intelligence at PASSAS is governed by the following instruments:
(a) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act), in particular Articles 4 (AI literacy), 5 (prohibited practices) and 50 (transparency obligations), as well as the provisions applicable to deployers and to general-purpose AI models;
(b) the Regulation amending the AI Act within the framework of the Digital Omnibus package, published in the Official Journal of the European Union on 24 July 2026 and in force since 27 July 2026, which maintains 2 August 2026 as the general date of application and as the date from which the transparency obligations of Article 50 become enforceable, and postpones the timetable for the obligations applicable to high-risk systems;
(c) Regulation (EU) 2016/679 (GDPR) and Ley Orgánica 3/2018 (LOPDGDD), as regards the processing of personal data by means of AI systems;
(d) the Estatuto General de la Abogacía Española (Real Decreto 135/2021) and the Código Deontológico de la Abogacía Española, as regards the limits of professional practice assisted by technological tools;
(e) ISO/IEC 42001:2023 on artificial intelligence management systems, as the reference standard for governance, risk assessment and continuous improvement in the use of AI.
PASSAS acts as a deployer of general-purpose AI systems in the following forms:
(a) Large language models for assistance with drafting, legal analysis, research, regulatory compliance, marketing and administration;
(b) Tools for the generation and modification of images and visual content;
(c) Tools assisting with code and software development;
(d) Voice processing and meeting transcription tools, used with the express consent of the other party on the terms of clause 7.
Under the AI Act, all the systems used fall within the minimal or limited risk category for the uses described in this Policy. PASSAS does not use high-risk AI systems within the meaning of Annex III to the AI Act, nor systems whose practice is prohibited by Article 5 thereof.
For the purposes of the preceding paragraph, PASSAS expressly states that it does not deploy AI systems intended to be used by a judicial authority, or on its behalf, to research and interpret facts and the law and to apply the law to a specific set of facts, nor systems intended for alternative dispute resolution, these being the cases contemplated in point 8 of Annex III to the AI Act. AI assistance in the firm's legal work always takes place within the framework of advice to clients and under the judgement and responsibility of the lawyer involved, in accordance with clause 5.1.
AI systems are used at PASSAS exclusively for the following purposes:
(a) Strategic co-pilot and assistance with the firm's management decision-making;
(b) Assistance with legal drafting and documentation, under the supervision and judgement of the responsible lawyer;
(c) Assistance with compliance with regulatory and ISO standards in professional engagements and compliance products;
(d) Assistance with marketing, communications and administration;
(e) Development of APIs, software and technological solutions, in compliance with the AI Act and in accordance with ISO/IEC 42001:2023;
(f) Processing of meetings and Virtual Consultations, with the prior, express and informed consent of the other party, for the generation of session reports.
The use of AI systems at PASSAS for purposes other than those set out above is prohibited. In particular, the use of free models, or of any system that shares or transmits client or firm data to training processes, is prohibited.
5.1. Human oversight. No decision capable of affecting the rights or interests of any person is taken solely by an AI system. Legal judgement is the exclusive responsibility of the firm's lawyers. AI assists and supports, but in no case replaces the professional responsibility of the lawyer.
5.2. Verification. PASSAS reviews the integrity, accuracy and authenticity of all information generated by AI before using, publishing or transmitting it. This review obligation is particularly rigorous in respect of references to legislation and case law and of statements of fact. AI can produce errors or non-existent references; responsibility for detecting them lies with the professional using the system.
5.3. Risk management. PASSAS applies a risk management approach in accordance with ISO/IEC 42001:2023, comprising the assessment of AI systems before their incorporation into the workflow, the definition of their authorised uses and periodic review of their suitability.
5.4. Secure models. PASSAS uses exclusively paid AI systems which, under their contractual terms, do not use the data processed for model training. The use in professional practice of free tools, or of tools that do not offer these safeguards, is expressly prohibited.
5.5. AI literacy. In accordance with Article 4 of the AI Act, enforceable since 2 February 2025, PASSAS ensures that those using AI systems on behalf of the firm have a sufficient level of knowledge of how they work, their limitations and the risks associated with their use. Training is documented internally and updated as new systems are adopted and as regulatory changes affecting it occur.
6.1. AI-assisted documents. Internal documents of the firm prepared with AI assistance are subject to human review and validation before use. In documents intended for third parties in which AI has played a substantial part, PASSAS will state that fact where it is relevant or where it is required under Article 50 of the AI Act.
6.2. AI-generated content. Images, designs and other visual content generated or substantially modified by means of AI and intended for publication are produced with the informed consent of their author and of those holding image rights over the content concerned. PASSAS does not produce deepfakes or any kind of synthetic content intended to mislead as to its origin or authenticity, in accordance with Article 50.4 of the AI Act.
6.3. Interaction with AI. Where AI systems with which the client interacts directly are used in the provision of services to clients, PASSAS will give prior notice of that fact, on the terms required by Article 50.1 of the AI Act.
6.4. Published editorial content. Content published by PASSAS on its blog and elsewhere on the website is prepared under the supervision, review and editorial responsibility of a lawyer identified by name and bar registration number, who assumes responsibility for its content irrespective of whether AI assistance was used in its preparation. The exception provided for in the second paragraph of Article 50.4 of the AI Act for content subject to human review and identified editorial responsibility therefore applies.
6.5. Interactive tools on the website. PASSAS makes interactive tools available to users, including questionnaires, self-assessments, calculators and similar utilities. For the purposes of the AI Act, every tool published on the website falls within one of the following two categories:
(a) Tools based on deterministic logic. The result is obtained by applying rules predefined by the firm's lawyers to the data entered by the user, without inference or generation of content. They do not constitute AI systems within the meaning of Article 3.1 of the AI Act, in accordance with recital 12 thereof, which excludes systems based on rules defined solely by natural persons to automatically execute operations. Article 50 does not apply to them.
(b) Tools incorporating AI systems. Those in which the result is obtained, wholly or in part, through inference or generation of content by an AI system, including conversational assistants.
Each tool states in its own interface, and before it is used, the category to which it belongs. Where a tool falls within category (b), that statement identifies the system used and satisfies the information obligation under Article 50.1 of the AI Act. Classification is carried out before each tool is published and is reviewed whenever its operation is modified.
The scope and effects of the result obtained through these tools are governed by clause 3 of the Legal Notice.
The processing of a person's voice, image or any biometric data by means of AI systems requires their prior, express and informed consent. PASSAS does not use AI systems for the recognition, analysis or classification of emotional states in any context, in compliance with Article 50.3 of the AI Act and as an expression of the firm's own professional commitment. The processing of recordings of Virtual Consultations or other meetings is governed by the Terms and Conditions of Service and the Privacy Policy.
The AI systems used by PASSAS are selected on the basis of the safeguards they offer as to confidential data processing, the absence of any use of that data for model training, and compliance with the GDPR. No client data, professionally protected data or sensitive firm information is entered into systems that do not offer these safeguards on a contractually binding basis.
No AI practice at PASSAS has as its object or effect discrimination, the impairment of fundamental rights, social scoring or any form of surveillance or behavioural manipulation. All the practices listed in Article 5 of the AI Act are expressly prohibited within the firm. Persons who have interacted with PASSAS services in which AI has played a part may address their enquiries or complaints to privacidad@passas.io.
Irrespective of the foregoing, any person may lodge a complaint with the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), as the national market surveillance authority, on the terms of Article 85 of the AI Act.
This AI Policy will be reviewed periodically and updated whenever new AI systems or uses are adopted, whenever material regulatory changes occur, or whenever the risk assessment so determines. The version in force is the one published on the website at the time of access.
This Policy is originally drafted in Spanish and is also published in English. Both versions correspond in their substantive content and each states its date of update. In the event of any discrepancy between them, clause 6 of the Legal Notice shall apply.
PASSAS uses AI systems to support the translation and localisation of the website's content, including its legal texts. Every translation is subject to human review by a lawyer of the firm before publication, in accordance with clause 5.2.
Regulation (EU) 2024/1689 has been in force since August 2024 and its general date of application is 2 August 2026, with a staggered timetable running to 2028 for certain categories of system; it imposes obligations on any company deploying AI systems, whether or not it developed them itself.
The AI Act introduces graduated obligations with different dates. Since February 2025 the prohibited practices of Article 5 and the AI literacy requirement of Article 4 have been enforceable, the latter affecting any organisation whose staff use these tools. Since 2 August 2026 the transparency obligations of Article 50 apply: giving notice when someone is interacting with an AI and labelling synthetic content. The high-risk obligations, following the Digital Omnibus, are postponed to December 2027 and August 2028 depending on the category of system. Publishing a policy is not in itself a standalone obligation, but it is the instrument that allows compliance with those that are to be evidenced, starting with AI literacy, and avoids having to build it in a hurry when the first inspection arrives, or the first client who requires it as a contractual condition.
The figure of the deployer covers any company using an AI system in the course of its professional activity, even where that system was developed by a third party. Using text generation tools, code assistants or transcription systems in internal processes or in client-facing work already makes you a deployer for the purposes of the Regulation. The specific obligations depend on the risk level of the system used, but responsibility for identifying that level and documenting the controls applied rests with the company deploying it.
A policy drafted without knowing the organisation's technology stack offers no protection in any real dispute. One that works identifies each tool individually, defines authorised and prohibited uses, establishes who may enter what kind of data into each system, and sets out the human oversight process to be followed before any AI output has legal or financial consequences. The AI Act and the GDPR overlap in practically every use case involving personal data, and a well-drafted policy resolves that overlap rather than ignoring it.
The AI policy is the document in the pack whose content depends most on the organisation's actual profile: the systems it uses, the data it processes and the risk level of each use case shape every clause. We draft it alongside the legal notice, the terms and conditions, the privacy policy and the DPA, so that AI risk management is integrated with GDPR compliance where the two overlap. The starting point is a €90 video consultation, credited against the fees if an engagement is ultimately formalised.