Back to the AI Act Shield iApp
LegalTech & Security — EU AI Act 2024/1689 & GDPR compliance

AI Act Shield by iaCiao

Local-first redaction and restore of sensitive data, for law firms, accountants and consultants.

iaCiao x AI Act Shield cover poster
PROMOTIONAL POSTER FOR THE PROFESSIONAL FIRMDownload the HD cover

Do your associates paste contracts and financial statements into ChatGPT or Claude? Are you really compliant with the EU AI Act and the GDPR?

87% of professional firms share confidential text containing tax IDs, IBANs, names and amounts with the cloud servers of generative AI every day. Sending data in the clear to servers outside the EU is a direct breach of Art. 32 GDPR and of Regulation (EU) 2024/1689.

Official penalties and financial exposure
REGULATION (EU) 2024/1689 & GDPR
EU AI Act penalty
UP TO €35 MILLION
(or up to 7% of global turnover)

No governance of input data and non-compliant use in the workplace.

GDPR Art. 83 penalty
UP TO €20 MILLION
(or up to 4% of global turnover)

Unlawful transfer outside the EU and failure to apply Art. 32 security measures.

Professional indemnity
€0 COVERED
(claim denied for gross negligence)

Insurers refuse to pay out when no anonymisation was in place beforehand.

Real-world case — what actually happens inside a firm
The everyday scenario

A partner or a trainee pastes a 15-page Word file into ChatGPT — a defence brief or a draft of an extraordinary financial statement — to get a quick summary. The document contains tax IDs, VAT numbers, bank statements with IBANs and details of tax disputes.

The consequences for the firm
  • Data leaked into cloud logs: indexed and retained for 30+ days on servers in the US.
  • Mandatory breach notification: every client must be told, with serious reputational damage.
  • Only anonymisation cures it: an Enterprise account does not cure a transfer in the clear that has already happened.

How AI Act Shield works (local anonymizer, zero cloud)

Demo: from the document in the clear to the masked text
Animation of the four AI Act Shield steps: confidential text, masking, AI processing, restore
Screen recording of the actual app, sped up. The interface in the recording is the Italian one.
1Mask locally

Upload the document or paste the text. The local engine finds and replaces tax IDs, VAT numbers, IBANs and names with anonymous placeholders ([CLIENT_1], [IBAN_1]).

2Process on the cloud AI

Safely send the masked text to ChatGPT, Claude or DeepSeek. The AI works on the placeholders, and the answer keeps its formal and legal accuracy intact.

3Restore in one click

Paste the answer back into AI Act Shield: the real data, held in your own computer's memory, goes back into place instantly.

Evaluation matrix for the Managing Partner and the DPO

Security and compliance criterionAI used directly (no Shield)With AI Act Shield (iaCiao)
Processing of client personal dataClear data on US/China serversMasked locally, 100%
Compliance with Regulation (EU) 2024/1689Penalties up to €35MCompliant
Adequacy of technical measures (Art. 32 GDPR)Penalties up to €20MAppropriate technical measures
Audit trail certificate for DPOs and inspectorsImpossible to producePrintable in one click
Standalone desktop mode (air-gapped)Cloud web onlyOffline .EXE / .DMG app
Patterns recognised across Italy and the EU

Automatic detection of tax IDs, VAT numbers, IBANs, professional titles, names, addresses, phone numbers, emails and any confidential term you add yourself.

Nothing is uploaded to a server

No document is ever sent to an external server — not even to ours. Masking and restoring happen only in your own computer's memory.

Protect your firm starting today
Open the iApp at iaCiao.com/iapps/ai-act-shield or ask for the desktop version for the firm's workstations.