Acceptable Use Policy
RESPONSIBLE AI — ACCEPTABLE USE POLICY
The AI Business · Last updated: [04/07/2026] · Version 2.0
Our Commitment to Responsible AI
We build AI that businesses can trust — and that means building it right. This Policy sets the standards that keep your systems, your users and your reputation protected. It isn't just fine print: it's how we make sure the technology we deliver stays lawful, safe and aligned with the EU AI Act and the wider European and Spanish framework from day one. When you work with us, compliance isn't your problem to solve alone — it's part of what we deliver.
Legal notice — not legal advice. This Policy reflects the EU and Spanish AI regulatory framework current as of 2026 and should be reviewed by a qualified AI/data-protection lawyer before publication. Regulatory dates are phasing in and may change. For clients under Spanish jurisdiction, the Spanish-language version shall be treated as authoritative.
1. Purpose and Scope
This Acceptable Use Policy ("Policy") governs access to and use of the services, platforms, models, APIs and AI-powered technologies provided by The AI Business ("we", "us", the "Service"). By using the Service you ("User") agree to this Policy, which forms an integral part of our Terms of Service. If you use the Service for an organisation, you accept it on its behalf and confirm you are authorised to do so. Our shared goal is simple: technology used lawfully, responsibly and ethically, under the framework in Section 2.
2. A Framework You Can Rely On
We design our work to align with, and help you meet:
Regulation (EU) 2024/1689 (the "EU AI Act"), including the Digital Omnibus simplification package
The Spanish AI governance framework — currently the Proyecto de Ley Orgánica para el buen uso y la gobernanza de la Inteligencia Artificial, approved by the Council of Ministers on 26 May 2026 and, at the date of this Policy, in parliamentary process and not yet in force
The GDPR (Regulation (EU) 2016/679) and Spanish LOPDGDD (Ley Orgánica 3/2018)
The Spanish Carta de Derechos Digitales
Where this Policy and mandatory law differ, the law prevails.
3. Clear Roles, Clear Responsibilities
The EU AI Act shares obligations across the value chain. Depending on your use, you may act as a provider, deployer, importer or distributor — and we'll help you understand which. Note that if you substantially modify a system we provide, or launch it under your own brand, you may become its provider under the AI Act and take on the related obligations. You are responsible for correctly classifying the risk level of your use case; we're here to advise.
4. Practices We Never Support (Article 5 EU AI Act)
To protect people and your business, the Service may never be used for any practice prohibited under the EU AI Act, including:
Subliminal, manipulative or deceptive techniques causing significant harm
Exploitation of vulnerabilities of age, disability or social/economic situation
Social scoring
Predictive policing based solely on profiling
Untargeted scraping of facial images to build facial-recognition databases
Emotion inference in the workplace or education (save medical/safety reasons)
Biometric categorisation to infer sensitive attributes
Real-time remote biometric identification in public spaces for law enforcement outside the narrow legal exceptions
We hold a zero-tolerance line on AI-generated child sexual abuse material (CSAM) and non-consensual sexual deepfakes — expressly prohibited following the additional EU prohibitions agreed in May 2026 — and report such activity to the authorities.
5. High-Stakes Uses, Done Properly
Some uses are classed as high-risk under Article 6 and Annex III (employment, access to essential services, creditworthiness and credit scoring, insurance, biometrics, critical infrastructure, education, healthcare, migration, justice, law enforcement). These aren't off-limits — they just have to be done properly.
If your use is high-risk, you're responsible for the applicable safeguards, which may include a risk-management system, data governance, technical documentation, logging, transparency and instructions for use, effective human oversight, accuracy, robustness and cybersecurity, a quality-management system, conformity assessment and, where applicable, CE marking and EU database registration.
Don't deploy in a high-risk context without these safeguards, and don't present our standard outputs as conformity-assessed high-risk systems unless we've agreed it in writing. Talk to us early — this is exactly the kind of thing we help clients get right.
6. Transparency That Builds Trust (Article 50 EU AI Act)
Honest AI earns trust. When your outputs reach end users or the public, you must:
Tell people when they're talking to an AI — chatbots and conversational agents (web, WhatsApp or elsewhere) must make clear the user is interacting with a machine, not a human
Label AI-generated or AI-manipulated audio, image, video or text in a clear, machine-readable way, in line with Article 50 (these obligations phase in during 2026)
Disclose deepfakes and AI-generated public-interest text as such
Please don't remove or bypass any watermarking or content-marking we provide — it's there to protect everyone.
7. AI Literacy (Article 4 EU AI Act)
You're responsible for a reasonable level of AI literacy among the people operating the Service on your behalf, matched to their role, the context of use and the people affected. We're glad to support training where it helps.
8. Keeping Humans in the Loop
Unless we've agreed otherwise in writing, the Service isn't a substitute for qualified professionals — including medical, legal, financial/tax/investment or psychological advice; outputs used in regulated settings should be reviewed by a professional.
And the Service must not make fully automated decisions without meaningful human oversight where those decisions significantly affect people — such as hiring, credit approvals, housing eligibility, criminal-justice outcomes, or emergency and safety-critical operations. This respects individuals' rights under Article 22 GDPR.
9. Privacy, Respected by Design
You must comply with the GDPR, LOPDGDD and applicable data-protection law. The Service may not be used to:
Process personal data without a valid legal basis
Build detailed profiles of private individuals without a lawful basis
Re-identify people from anonymised data
Generate content that unlawfully infringes privacy
Where we process personal data on your behalf, a Data Processing Agreement under Article 28 GDPR governs it. As controller, you remain responsible for the lawfulness of the data you submit and the outputs you deploy.
10. Fair Use of the Service
Please don't use the Service to generate or facilitate:
Content inciting violence, terrorism, hatred, discrimination, harassment or self-harm, or graphic imagery
Instructions for illegal activity, fraud or scams, content breaching export controls, or material infringing IP rights
Impersonation of real people or organisations, or false information presented as fact
And please don't:
Reverse-engineer or replicate our models or training data
Circumvent safety systems (including prompt injection or adversarial attacks)
Disrupt or overload the Service
Access restricted features without authorisation
Use outputs to train competing AI, or resell/sub-licence the Service, without our written permission
11. Quality You Can Stand Behind
When content generated with the Service is presented as factual, make sure it's accurate, add disclaimers where appropriate, respect third-party rights and licences, and follow the disclosure rules of any platform where it's published.
12. Know the Timeline (Informational, Subject to Change)
2 Feb 2025 — prohibited practices and AI-literacy obligations apply
2 Aug 2025 — governance rules, GPAI-model obligations and the penalty regime apply
2026 — transparency obligations (Art. 50, including synthetic-content marking) and the bulk of the AI Act, including high-risk Annex III systems, become applicable
2 Aug 2028 — extended transition (Digital Omnibus) for high-risk AI embedded in regulated products
Spanish AI governance law — applies once enacted
Always confirm current dates with a legal adviser.
13. Who Oversees This
In Spain, supervision is led by the Agencia Española de Supervisión de Inteligencia Artificial (AESIA, based in A Coruña), alongside sectoral authorities including the AEPD (data protection), Banco de España (creditworthiness), CNMV (capital markets), DGSFP (insurance), CGPJ (justice) and the Junta Electoral Central (electoral processes).
14. Enforcement
We may monitor use of the Service to ensure compliance, protect platform integrity and safety, and meet our legal obligations. Violations may lead to warnings, suspension, termination, and cooperation with authorities where required.
Separately, breaches of the EU AI Act may expose the responsible operator to:
Up to €35M or 7% of worldwide annual turnover (prohibited practices)
Up to €15M or 3% (other obligations)
Up to €7.5M or 1% (incorrect or misleading information to authorities)
The Spanish framework adds its own regime once in force. Responsibility for penalties arising from your use of the Service rests with you.
15. If Something Goes Wrong
If you become aware of a serious incident or malfunction involving a system built or operated with the Service, tell us promptly and cooperate with any notification to the authorities.
Suspected misuse can be reported to info@theaibusiness.com with supporting evidence. We treat every report seriously.
16. Keeping This Policy Current
AI and its regulation move fast — so will this Policy. We'll notify material changes through the Service or by email. Continued use after an update means you accept the revised Policy.
Building AI you can trust — responsibly, and by design.
Contact: info@theaibusiness.com · The AI Business · Madrid — Miami
We comply with GDPR and the AI Act and we put it in the contract.
Compliance by design, not patched later
DPA + audit, included in every project
Your data, your IP, 100% yours on delivery
next
GDPR · BY CONTRACT
EU AI ACT · BY CONTRACT
