Previous Article Back to Blog
6 October 2026 Nicolas Pinault & Majda Skrijelj Fetiveau 9 min read COMPARISON · AI ACT & GDPR

Why not just use ChatGPT, Notion, a law firm or a GRC tool? How Themio approaches AI Act and GDPR compliance for SMEs

By Nicolas Pinault, co-founder, product development, and Majda Skrijelj Fetiveau, regulatory analyst with more than 20 years in compliance and governance at international financial institutions. Last reviewed: 6 October 2026.

Executive Summary

Short answer. Each of these tools covers part of the job: ChatGPT explains rules, Notion organises work, a law firm interprets the law and defends you, and a GRC platform tracks controls. Themio, an EU-hosted compliance platform for European SMEs, does the systematic part in between.

  • Direct document checking : Themio checks your own documents against a defined set of AI Act and GDPR requirements, quotes the passage behind each finding, and separates “non-compliant” from “no evidence”.
  • Dated action plan and evidence : turns the identified gaps into a dated, structured action plan exportable for your team, management, or auditors.
  • Pre-filled document drafting : on selected plans, drafts the missing documents (record of processing activities, privacy notice, data breach register, AI system classification record), pre-filled from your onboarding answers and fully editable.
  • Human collaboration : Themio works alongside your lawyer or DPO by preparing the verifiable factual file, while they make the final judgment calls.
2 Dec 2027
AI Act High-Risk

new compliance deadline for Annex III high-risk AI systems set by Regulation (EU) 2026/1744.

5 Statuses
Rule-by-Rule Analysis

compliant, partial, non-compliant, no evidence or not applicable. Missing evidence is never assumed compliant.

Four tool categories connected to a central stack of compliance documents, illustrating Themio’s structured compliance layer.

Most SMEs we speak to already pay for an AI assistant and a workspace tool, and some have a lawyer on call. A compliance platform earns its place only if it does a job those three cannot.

What is Themio built for?

Themio gives SMEs a compliance tool that is efficient, reliable and accessible. Efficient, because your team should not spend weeks reading regulations to work out which ones apply. Reliable, because every finding must trace back to the law and to your own documents. Accessible, because an SME carries the same AI Act and GDPR obligations as a large group, usually without a legal department or a compliance budget to match.

Four problems come up again and again for SMEs: not knowing which rules apply, documents that are scattered or out of date, audits that cost a lot and age quickly, and AI tools adopted with no clear view of what the AI Act expects. We designed Themio around those four.

ChatGPT, Notion, a law firm, a GRC tool or Themio: which does what?

Option What it does well Where it stops for an SME compliance file Cost model
ChatGPT or a similar AI assistant Explains a rule in plain language, drafts text quickly Answers what you ask, so obligations you do not know about stay invisible; keeps no dated record of your file Per-user subscription
Notion or a shared drive Organises documents, tasks and owners Holds no regulatory logic: you decide what the law requires and whether your documents meet it Per-user subscription
Law firm or external DPO Interpretation, complex cases, representation before an authority, professional liability Billed on time; a review reflects your documents on the day it was done Fees per day or engagement
GRC platform Manages controls and audits for frameworks such as ISO 27001 Usually run by an in-house compliance or security team that already knows which obligations apply Annual licence
Themio Structured check of your own documents against AI Act and GDPR requirements, with quotes, gaps, an action plan and a dated history Leaves interpretation and representation to your lawyer or DPO, with a file ready for them Monthly subscription sized for SME budgets, free trial

These options combine well. A realistic setup for a 20-person company: Themio for the systematic work, a lawyer or DPO for the judgment calls, and your existing workspace for everything else.

Can ChatGPT handle AI Act and GDPR compliance?

Article 5(2) GDPR requires you to demonstrate compliance (explore our GDPR compliance guide ). A good chat answer helps you understand a rule, but it gives you nothing you can show an authority.

You can paste your privacy policy into an assistant and get a useful review. Three things are missing by default:

  • Coverage. You get answers to the questions you ask. An obligation you have never heard of, such as the record of processing activities under Article 30 GDPR, only appears if you think to ask.
  • Evidence. An assistant can explain what Article 13 GDPR requires. Themio tells you which sentence of your 2021 privacy policy falls short, and keeps that finding attached to the document.
  • Continuity. Next month, after you update the policy, you want to see what changed. A conversation does not keep a dated, structured history of your file.

How does Themio work?

  1. Classify your AI use. For each AI system you use or build, you answer a short questionnaire. Themio returns the risk tier and the article it rests on. Example: a marketing content tool used as a deployer, which interacts with people, lands in limited risk with transparency duties under Article 50 of the AI Act .
  2. Upload your documents. Privacy policy, terms and conditions, contracts, internal registers, AI questionnaires, or any other document you need analysed. PDF, Word, Excel, CSV and text files are accepted.
  3. Get a rule-by-rule result. Themio checks your file against a rule set built article by article from the GDPR and the AI Act. Each rule receives one status: compliant, partial, non-compliant, no evidence or not applicable.
  4. Read findings you can verify. Each finding shows the requirement and its article, what the analysis concluded, the passage quoted from your document, its section and the file it came from. In one test file, an internal AI questionnaire declared deployer input-data controls “not applicable”. Themio flagged the statement against Article 26(4) of the AI Act, quoted the line with its section, and named the source file.
  5. Close the gaps. Themio turns each gap into a task, with sub-actions, due dates and comments for your team or DPO. You can export the plan and the compliance report as PDF. On selected plans, Themio also drafts the documents your analysis found missing, such as a record of processing activities, a privacy notice, a data breach register or an AI system classification record. Themio pre-fills each draft with the information you gave at onboarding, and you adapt it as you see fit before adopting it.
  6. Keep a dated record. The engagement record exports, as PDF or CSV, a timeline of checks, scores, plans, completed tasks and filed documents.
Themio six-step AI compliance workflow, from classifying AI use and reviewing evidence to remediation and a dated record, with lawyer or DPO review.
How Themio works: Themio prepares the file, your lawyer or DPO decides.

You can also ask Themis, the built-in assistant, questions about your own file. Its answers are grounded in your documents and findings, with sources listed. When a three-person company asked whether all of the GDPR applied to it, Themis listed what applies regardless of size and what it likely did not need, such as a DPO, which Article 37 requires only in specific cases.

What does “no evidence” mean in a compliance check?

Most first-pass reviews sort requirements into compliant and non-compliant. Themio adds a third answer: your documents do not show it either way. If nothing in your file describes how you would notify a data breach within 72 hours under Article 33 GDPR, Themio reports no evidence and does not guess. That is the gap an auditor or a supervisory authority will ask about first.

Engagement Record Discipline

The engagement record follows the same discipline. It states on its face that it traces dated actions and attests to no compliance, that a task marked done was marked by you and not verified by Themio, and that a filed document is recorded, not validated.

Who designs Themio’s rules?

Regulatory specialists build and maintain Themio’s rules, article by article, and Themio checks every file against them in the same way. When the texts change, we update the rules, so your next analysis reflects the law as it stands.

When your situation turns on interpretation, such as whether a specific AI system falls under Annex III of the AI Act, Themio hands you a structured file and the open questions, and your lawyer or DPO makes the call.

How is Themio priced?

A consulting engagement is priced on time: someone reads your documents and writes up the gaps, and the next review starts again from reading. Themio’s rules are built once and applied to every file, which keeps the cost of each additional analysis low. We listened to what the SMEs in our survey said they could spend on compliance tools and set our plans accordingly. Every plan starts with a free trial. Current plans are on our pricing page .

Why act on the AI Act now?

The AI Act is already partly in force. Regulation (EU) 2024/1689 was amended by the Digital Omnibus, Regulation (EU) 2026/1744 , in force since 27 July 2026. The dates that matter for an SME:

  • Since 2 February 2025: the bans on prohibited practices (Article 5) and the AI literacy duty (Article 4). Since July 2026, Article 4 requires you to take measures that support your staff’s AI literacy, without guaranteeing a level for each person.
  • Since 2 August 2026: transparency duties under Article 50. People must know when they are interacting with an AI system, and some AI-generated content must be disclosed. Generative systems placed on the market before that date have until 2 December 2026 for machine-readable marking.
  • 2 December 2027: obligations for high-risk systems listed in Annex III, such as recruitment, credit scoring and education. 2 August 2028 for AI embedded in products covered by Annex I.

The delay changes the high-risk deadline only. You still decide now, under Article 6, whether your system is high-risk, and the evidence takes months to build.

The GDPR applies in parallel whenever your AI tools process personal data. Fines reach €15 million or 3% of worldwide turnover for most AI Act breaches, including Article 50, with SMEs capped at the lower of the two (Article 99(4) and (6)). Under Article 83(5) GDPR, they reach €20 million or 4%.

More SMEs use AI every year. According to Eurostat , 20.0% of EU enterprises with 10 or more employees used AI in 2025, up from 13.5% in 2024. Among small enterprises, the figure was 17%.

Why Themio works alongside your lawyer and DPO

Themio prepares and maintains your compliance file. Your lawyer or DPO interprets, advises and represents you. Themio gives no legal advice and issues no certificate, so its findings stay factual and traceable, and your adviser can check them without rebuilding the file.

Themio records a task you mark as done as your own declaration and does not verify it. It never counts a missing document as compliance. Coverage is explicit: the AI Act and the GDPR at launch, with NIS2, DORA, CSRD, AML and anti-bribery and corruption (ABC) in preparation.

What is on Themio’s roadmap?

Themio launches with the AI Act and the GDPR. Five further frameworks are in preparation:

  • NIS2 (Directive (EU) 2022/2555): scope qualification and the cybersecurity risk-management measures of Article 21. Our free NIS 2 Diagnostic already checks scope and readiness.
  • DORA (Regulation (EU) 2022/2554): ICT risk management and third-party oversight for financial entities and the ICT providers that serve them.
  • CSRD (Directive (EU) 2022/2464): sustainability reporting, including the value-chain data requests SMEs receive from larger customers.
  • AML : the EU single rulebook on anti-money laundering, Regulation (EU) 2024/1624, which applies from 10 July 2027, for obliged entities such as accountants, estate agents and dealers in high-value goods.
  • Anti-bribery and corruption (ABC) : Directive (EU) 2026/1021 on combating corruption, together with national laws such as France’s Sapin II law.

Anti-corruption is the newest of these obligations. Directive (EU) 2026/1021 , published in the Official Journal on 11 May 2026, harmonises corruption offences across the EU and makes companies liable, including for failures of supervision. For the most serious offences, fines reach 5% of worldwide turnover or €40 million. Member States must transpose most provisions by 1 June 2028. The directive recognises effective compliance programmes as a mitigating factor, so building one before that date pays off. In France, Sapin II already requires an anti-corruption programme from companies with at least 500 employees and more than €100 million in turnover, and those companies assess their suppliers, SMEs included.

Which framework do you need first? Tell us : your answers shape the order in which we build.

Frequently asked questions

Can I use ChatGPT for GDPR compliance?
You can use it to understand rules and draft text. For a compliance file you need coverage of all applicable obligations, findings tied to your own documents, and a dated record. Article 5(2) GDPR requires you to demonstrate compliance.
Does Themio replace a lawyer or a DPO?
No. Themio does the systematic checking and tracking. Interpretation, complex cases and representation before an authority stay with a lawyer or DPO.
Which regulations does Themio cover?
The EU AI Act and the GDPR at launch. NIS2, DORA, CSRD, AML and anti-bribery and corruption (ABC), covering Directive (EU) 2026/1021 and national laws such as Sapin II, are in preparation.
What happens when my documents say nothing about a requirement?
Themio marks it no evidence . A missing document is never counted as compliance.
Where is my data processed?
Themio is hosted in the European Union, and your documents are not used to train AI models.
Has the AI Act high-risk deadline been delayed?
Yes. Regulation (EU) 2026/1744 moved the obligations for high-risk systems listed in Annex III from 2 August 2026 to 2 December 2027, and to 2 August 2028 for AI in products covered by Annex I. The transparency duties of Article 50 have applied since 2 August 2026.
Does the EU anti-corruption directive apply to SMEs?
Directive (EU) 2026/1021 sets corporate liability rules for legal persons, which include SMEs. Member States must transpose most provisions by 1 June 2028. The directive recognises compliance programmes as a mitigating factor, so an SME that documents its anti-corruption measures early is better protected.
Which GDPR documents does a small business need?
Usually a record of processing activities (Article 30), privacy notices (Articles 13 and 14), contracts with processors (Article 28) and a data breach register (Article 33(5)), plus a DPIA when processing is likely to be high-risk (Article 35). Which ones apply depends on your processing; a Themio analysis shows the gaps in your own file.
Nicolas Pinault

Co-founder & Product Development

Software architect with over 20 years of experience designing SaaS solutions and deterministic rules engines.

Majda Skrijelj Fetiveau

Consultant & Chief Regulation Untangler

Senior Compliance Officer at an international financial institution, with more than 20 years of experience in governance, anti-corruption and European regulatory risk (GDPR, AI Act, DORA).

Get priority access to Themio

Themio opens to the public in the coming weeks. Check your own documents against the AI Act and GDPR, get an immediate action plan, and prepare a verifiable file for your lawyer or DPO.

Join the waitlist (10 free audit credits) →