GPU Solutions

Solutions · Banking and insurance

AI for banking and insurance with customer data kept in Spain

GPU Solutions runs AI models for banks, insurers, fintechs and asset managers on its own NVIDIA B200 GPUs in a Tier III datacenter in Madrid. Customer data is processed in Spain, in an isolated environment, and is never used to train models. We also give you what DORA expects from an ICT provider: a clear data location, an auditable contract and an exit strategy.

In short
  • Customer data processed and stored in Spain, with no subprocessors outside the EU.
  • One isolated environment per institution: its own network, storage and access.
  • Platform certified ISO/IEC 27001:2023 and ENS Medium by EQA; datacenter certified ENS High.
  • Documentation for DORA, the AI Act and GDPR: contract, input for your register of information and exit plan.

Why financial AI needs a provider you can audit

In banking and insurance, AI pays off wherever there are lots of documents and lots of rules: customer onboarding files, policies, claims, supervisory circulars, internal manuals and thousands of lines of legacy code. Today's open models read, summarise, classify and write code well enough to take repetitive work off operations, compliance and technology teams, always with a person validating the output.

But those documents hold personal data, financial information and information covered by banking secrecy. Sending them to a foreign provider's API turns every query into a third-party ICT service your supervisor can ask you to justify: where the data is processed, who subcontracts to whom, what happens if the service goes down and how you would leave. With DORA applying since January 2025, those questions are no longer theoretical.

What comes next reinforces the trend. The AI Act classifies creditworthiness assessment of natural persons and life and health insurance pricing as high-risk, with obligations from 2 December 2027, and the EBA and EIOPA expect real governance and oversight of providers. We track every deadline in our regulatory radar. As a Spanish operator with its own infrastructure in Madrid, we offer an identifiable provider, a contract that fits your register of information and published prices.

Four AI use cases for banking and insurance

Cases built on open models available today, designed to pass a risk review. We size them by measuring your actual workload on our cluster.

Document analysis for onboarding and KYC files

An onboarding file brings together ID documents, deeds, powers of attorney, annual accounts, proof of income and beneficial ownership declarations. A vision model extracts the data from each document, cross-checks them and flags inconsistencies: an expired document, a director who does not match, an amount that does not add up. The analyst reviews a summary with links to each page instead of reading forty sheets. The decision stays with them.

Qwen3-VL 32B OCR · Nemotron Nano 12B VL · Qwen3.8

Internal assistant over policies and regulation

We index your internal policies, procedure manuals, supervisory circulars and applicable regulation in a private search space. A branch manager or compliance analyst asks in plain language and gets the answer with an exact citation of the document and its current version. For Spanish and Spain's co-official languages you can use ALIA 40B, from the Barcelona Supercomputing Center. Nothing anyone asks ever leaves your environment.

Search over your documents · GLM 5.3 · ALIA 40B

Insurance claims processing

A claim arrives with photos, repair invoices, loss adjuster reports, police reports and sometimes a recording of the policyholder's call. The AI transcribes the audio, reads the documents, extracts dates, amounts and the coverages involved, and drafts a claim file listing what is still missing. The handler starts with an organised case and makes the call. When a claim involves health data, everything still stays inside the isolated environment.

Whisper large-v3 · Qwen3-VL 32B OCR · Gemma 4 26B

Coding and analytics assistant for quant and dev teams

Your development and risk teams use coding agents and notebooks on GPUs in Madrid, against a private endpoint shared with no one. Use it to migrate legacy code, write tests, document internal models or explore portfolio data. Because the provider is identifiable, the contract is auditable and there is an exit plan, the service fits your ICT third-party risk framework under DORA without depending on a foreign API.

Sandboxes with coding agents · GLM 5.3 · dedicated private endpoint

How your customers' data travels

Four legs inside Spain, each documented for your register of information and your risk analysis.

  1. 01

    Your systems

    Your core banking, document management and claims platforms stay in-house. You only send the documents or data each use case needs.

  2. 02

    Encrypted link

    A VPN or a dedicated, encrypted point-to-point link, with post-quantum cryptography available. You can keep the whole path off the public internet.

  3. 03

    Isolated environment

    Your institution's own network, storage and access controls. We log access, and you apply your retention policy or zero retention.

  4. 04

    GPU in Madrid

    Inference and analytics on NVIDIA B200 GPUs in a Tier III datacenter in Madrid. Nothing is reused, not for training models and not for other customers.

Financial regulation and how we help

Compliance is your institution's responsibility. We provide infrastructure, a contract and documentation that fit your risk management framework and what your supervisor expects.

Financial regulation and how we help
RegulationWhat it requiresHow we help
DORA (Regulation (EU) 2022/2554)ICT third-party risk management: minimum contractual clauses, a register of information covering all arrangements, access and audit rights, and exit strategies for critical or important functions.A contract setting out data location, subcontracting and support levels in writing, input for your register of information, datacenter visits by appointment, and an exit plan with portability of data, models and images.
AI Act, Annex IIICreditworthiness assessment and credit scoring of natural persons, and risk assessment and pricing in life and health insurance, are high-risk. After the digital omnibus, obligations apply from 2 December 2027.Open models with pinned versions, your own images, access logs and data in Spain: the technical basis for the documentation, traceability and human oversight the regulation requires.
GDPRLegal basis, data minimisation, security of processing, a processor contract and control of international transfers, plus safeguards on automated decision-making (art. 22).A standard DPA, optional zero retention, no subprocessors outside the EU, no international transfers and no use of your data to train models.
EBA Guidelines on outsourcingPre-outsourcing assessment of the provider, risk and concentration analysis, audit rights, data location, an exit plan and documentation of each outsourcing arrangement.Information on the provider and its subcontracting chain, the platform's ISO/IEC 27001 and ENS Medium certifications, access for audits and support with your pre-outsourcing assessment.
EIOPA Opinion on AI governanceFor AI systems that are not high-risk, insurers must apply proportionate risk management, data quality, traceability, explainability and human oversight, including when they rely on external providers.Reproducible environments with a known model and version, access logs, data that never leaves your environment and technical documentation for your risk assessment.

Regulatory radar: banking and insurance

Rules and deadlines that affect AI in banking and insurance, each with its official source. The full list is in our regulatory radar.

  1. AI Act high-risk obligations for Annex III systems start to apply

    Covers credit scoring, life and health insurance pricing, justice, essential public services and employment. Requires risk management, data quality, logging, human oversight and technical documentation.

    Official source: EUR-Lex · Reglamento (UE) 2026/1744 ↗

    DeadlineEU
  2. Consumer Credit Directive (EU) 2023/2225 applies: explanation and human review in automated scoring

    When creditworthiness is assessed by automated processing, consumers can ask for a clear explanation, human intervention and a review of the decision. Models must be explainable case by case.

    Official source: EUR-Lex · Directiva (UE) 2023/2225 ↗

    DeadlineEU
  3. EuroHPC AI Gigafactories call closes (up to 7 consortia)

    Awards are expected in early 2027. Spain is bidding with a public-private candidacy. It signals where European compute capacity for training and running models will be located.

    Official source: EuroHPC ↗

    DeadlineEU
  4. AI Omnibus Regulation (EU) 2026/1744 published: new timetable for high-risk AI

    In force since 27 July 2026. Annex III obligations move to 2 December 2027 and Annex I obligations (AI in regulated products such as medical devices) to 2 August 2028.

    Official source: EUR-Lex · Reglamento (UE) 2026/1744 ↗

    In forceEU
  5. EBA finds no contradictions between the AI Act and banking rules

    The AI Act complements CRR/CRD, DORA and EBA guidelines on credit scoring. Banks can build on their existing model governance and ICT risk frameworks to comply.

    Official source: EBA ↗

    PublishedEU
  6. ESAs designate the first 19 critical ICT third-party providers under DORA

    Most are large cloud platforms, now under direct EU oversight. Financial entities remain responsible for managing concentration risk and exit strategies.

    Official source: EBA · ESAs ↗

    PublishedEU
  7. EIOPA opinion on AI governance and risk management for insurers

    It applies Solvency II, IDD, DORA and GDPR to AI use with an approach proportional to each use case's risk: data governance, documentation, explainability and human oversight.

    Official source: EIOPA ↗

    PublishedEU

Recent laws, guidance and decisions →

Frequently asked questions about AI in banking and insurance

Do you fit as an ICT provider under DORA?

Yes. We act as an ICT third-party service provider, and the contract sets out in writing what DORA requires: data location, subcontracting, support levels, access and audit rights, and an exit strategy. We also give you the information you need for your register of information. Classifying the function as critical or important is your institution's call, and we review it with you.

Where is our customers' data processed?

In Spain. Data is processed and stored on our own NVIDIA B200 GPUs in a Tier III datacenter in Madrid, with no subprocessors outside the European Union. Each institution has its own network, storage and access, and its data is never used to train models. With zero retention, nothing is stored after each request is processed.

Is an AI credit scoring model high-risk?

Yes, if it assesses the creditworthiness or sets the credit score of natural persons: Annex III of the AI Act treats it as high-risk, with obligations from 2 December 2027. Systems used to detect financial fraud are expressly excluded from that category. In insurance, risk assessment and pricing for life and health cover of natural persons are included.

Can we run our own models?

Yes. On a dedicated pod of 1 to 4 full NVIDIA B200 GPUs with passthrough, you load your own image, models and libraries. If you need more, there is a full eight-B200 bare-metal node, outside the shared cluster and with its own access. For inference you can deploy a dedicated private endpoint compatible with the OpenAI and Anthropic SDKs.

How do we exit if we change provider?

Through an exit plan agreed in the contract from day one. Your data, images and models are yours and are exported in standard formats; we work with open models and APIs compatible with OpenAI and Anthropic, so your code is not tied to us. It is the exit strategy DORA asks you to document for ICT providers supporting relevant functions.

How much does it cost?

A full NVIDIA B200 GPU costs €8.00/h excluding VAT and a 1/8 MIG fraction starts at €1.50/h; inference on GPU Flow starts at €0.06 per million input tokens. On-demand has no commitment; reserved capacity guarantees GPUs with a six-month minimum. Full details are on our pricing page.

Next step

Tell us which process you want to automate and what your supervisor asks of you

Talk to an engineer →