This is a practical orientation for legal, compliance and security teams weighing a self-hosted AI deployment against the EU AI Act and GDPR. It is not legal advice, your EU-qualified counsel does the final review, but it maps the obligations that most often surprise teams onto concrete, on-premise controls.

Kaldryn ships the tooling and the documentation scaffolding for these obligations. It does not replace a lawyer. Treat this checklist as a starting map, not a guarantee.

First, self-hosting is not an exemption

A common misconception is that running AI on your own hardware puts you outside the EU AI Act. It does not. The Act regulates the deployment and use of AI systems based on risk, not on where the GPUs sit. What self-hosting changes is the difficulty of compliance: when data never leaves your perimeter, a whole class of obligations around transfer, processing and residency become architectural facts rather than contractual promises you have to extract from a vendor.

Know your risk tier

The Act is risk-tiered. Most enterprise assistant use, drafting, summarising, internal document Q&A, falls outside the high-risk categories, but you must confirm that for your specific use cases. Deploying AI in areas such as recruitment, credit, biometric identification or critical infrastructure can pull you into the high-risk regime with substantially more obligations. Step one is always a documented classification of each use case.

The transparency obligation (Article 50)

Users must know when they are interacting with an AI system, and AI-generated content must be marked as such where required. In practice this means a transparency notice in the assistant UI, locale-aware and customisable, plus clear labelling of AI output. This is straightforward to satisfy but easy to forget.

AI literacy (Article 4)

From 2025 the Act expects organisations to ensure staff who use AI systems have an adequate level of AI literacy. A short, trackable training module with a certificate is the pragmatic way to evidence this, and it doubles as good change-management when rolling an assistant out to a workforce.

Data governance and GDPR

This is where on-premise deployment pays for itself in compliance terms:

  • Data residency, when inference and documents stay on your hardware, residency is a fact of the architecture, not a clause to negotiate.
  • Right to erasure (GDPR Art. 17), erasure must propagate across conversations, documents, embeddings, any fine-tuned weights and backups; design for this from day one.
  • Lawful basis and minimisation, you still need a basis for processing and should apply DLP to keep sensitive categories out of prompts where appropriate.
  • Records of processing, your audit log is also your evidence base.

Logging and traceability

High-risk systems must keep automatic logs, and even outside that tier an immutable, exportable audit trail is the difference between asserting compliance and demonstrating it. Look for SIEM export (syslog or signed webhook) so the AI system's records flow into the same monitoring as the rest of your estate.

Human oversight

The Act expects meaningful human oversight of consequential AI use. Architecturally this means role-gated capabilities, the ability to review and override, and not wiring an assistant directly into irreversible actions without a human in the loop.

A condensed checklist

  1. Classify each use case by risk tier and document it.
  2. Add an Article 50 transparency notice and label AI output.
  3. Roll out and track Article 4 AI-literacy training.
  4. Pin data residency to your own hardware; confirm zero egress.
  5. Implement erasure that propagates to embeddings, fine-tunes and backups.
  6. Apply DLP to inbound and outbound messages.
  7. Enable an immutable audit log with SIEM export.
  8. Define human-oversight and role-gating policies.
  9. Prepare DPIA/FRIA documentation where required.
  10. Have EU-qualified counsel review the whole package.

Sector overlays

On top of the horizontal obligations, expect sector rules: MDR/IVDR and EHDS in healthcare; DORA, CRA and EBA expectations in finance; FRIA, an Article 49 registry and NIS2 in the public sector; and national regimes such as Sweden's Dataskyddslagen and Offentlighetsprincipen. A platform that ships these overlays as templates rather than leaving you to build them is doing a meaningful amount of the work for you.

Want the downloadable version of this checklist, pre-filled with a risk catalogue and DPIA/FRIA templates? Get in touch and we will share the compliance kit.