← Home Guides
TRENKO
Guides · Free

AI compliance guides.

The six questions asked most often at the intersection of the EU AI Act and GDPR — each paired with the ready-to-fill document that answers it.

10 guides 14 documents No sign-up DOCX · XLSX · MD
§ 01 — Guides

Pick where to start.

Each guide explains one legal question and ends with the blank template that answers it. The order is a suggestion — the scope test determines which of the others you actually need.

01 · START HERE

Article 50 scope test and compliance kit

Who do the transparency obligations bind? A four-question scope test drawn from Article 2, followed by a six-document dossier: scoping assessment, disclosure texts in three languages, synthetic-content policy, supplier addendum, employee policy and a compliance register.

7 files · DOCX / XLSXOpen the scope test
02

Corporate AI use policy

Who is liable when an employee pastes company data into ChatGPT? Shadow AI, a classified tool list, prohibited input categories and a data-leakage incident protocol.

Policy · MDOpen
03

High-risk classification form

Is your software high-risk under Art. 6 and Annex III? Scope, role and classification, with the Art. 6(3) derogation and the Art. 99 fine thresholds.

Form · MDOpen
04

Autonomous AI agents and contract liability

Does what the agent agreed bind the company? An authority matrix, human approval thresholds, disclosure text for counterparties and a rollback protocol.

Protocol · MDOpen
05

AI output copyright and commercial use

Can you sell the images, text and code you generate? Ownership, provider terms, the record of human contribution, and infringement screening for each output type.

Checklist · MDOpen
06

AI in hiring and discrimination risk

Who does your screening system screen out? Profiling determination, indirect discrimination proxies, pass-rate measurement, human oversight and a candidate notice.

Form · MDOpen
07

Korea AI Basic Act readiness

Korea's Framework Act on AI applies from 22 January 2026, with extraterritorial reach. A high-impact classification test, generative-AI labelling, the domestic representative and an obligations register.

Self-assessment · MDOpen
08

Korea PIPA automated decisions

Since March 2024, a right to refuse fully automated decisions and to demand an explanation. A disclosure notice, an automated-decision register and a request-handling workflow.

Notice · MDOpen
09

Turkey KVKK cross-border data transfer

Article 9 changed on 1 June 2024. A tiered decision map — adequacy, standard contract, binding corporate rules and the narrow exceptional cases — with the 5-day notification.

Decision map · MDOpen
10

Turkey KVKK × AI data governance

AI runs on personal data and KVKK already applies. Lawful basis, special categories, profiling and transparency — aligned with the prospective Turkish AI Act.

Checklist · MDOpen
§ 02 — What these documents are for

What an audit asks for is a filled file, not a report.

In an audit, or on an EU corporate buyer's supplier form, the first question is not whether a breach occurred but whether the company holds a written record of the measures it took beforehand. The templates in these guides exist to produce exactly that record.

They are all blank frameworks: without the bracketed fields and the classification sections completed for your company, they do no work. The places where they are most often filled in wrongly are set out in each guide's § 04.

Note These documents are general in nature and do not constitute legal advice. The article numbers cited reflect the legislation as at the date the guides were prepared; confirm against the version in force before relying on them.
§ 03 — Frequently asked

Questions.

Are these templates really free?

Yes. All six guides and their templates download without registering or giving an email address. The documents also sit on the page as copyable text, and download in markdown, Word and Excel formats.

Which guide should I start with?

The scope test is the most efficient starting point. Until you establish whether the Regulation binds you, you cannot tell which of the other documents you need. If you are in scope, the next step is role determination: provider, deployer, or deemed provider under Art. 25.

Can I adopt the templates as they are?

As a framework yes, as a final document no. The bracketed fields and classification sections have to be completed for your company. They also need checking against your existing client and supplier agreements.

Do these apply to a company outside the EU?

Yes. The Regulation applies even where the provider or deployer is established in a third country, provided the system's output is used within the Union (Art. 2(1)(c)). The data protection and employment law obligations covered also apply independently of any EU connection.

Weren't the high-risk rules postponed?

The application date for high-risk obligations was postponed. But the Article 50 transparency obligations stayed outside that postponement, and data protection obligations already apply today and call for substantially the same records.

Let's adapt a template to your company.

In a twenty-minute preliminary call we work out together which document applies to you. If you're out of scope, we tell you that clearly too.

Reserve your spot for an online call The call is online · the documents are yours either way