GPU Solutions

Solutions · Legal

AI for law firms and legal departments, with professional secrecy kept inside Spain

GPU Solutions runs open AI models on its own NVIDIA B200 GPUs in a Tier III datacenter in Madrid, so law firms and in-house legal teams can review case files, search their own precedents and transcribe meetings without client information leaving Spain. We never use your data to train models, and we sign a standard DPA with optional zero retention.

In short
  • Data processed and stored in Spain, with no subprocessors outside the EU.
  • Platform certified to ISO/IEC 27001:2023 and ENS Medium category by EQA.
  • Open models (Qwen, GLM, ALIA 40B, Whisper) on a private endpoint or dedicated environment.
  • From €1.50/h for a GPU fraction; standard dedicated environment 72 h after signature.

Why a law firm's AI cannot depend on a foreign API

Generative AI is already useful in everyday legal work: summarising a case file of several hundred pages, comparing two versions of a contract, finding how your own team argued a similar matter, or transcribing a meeting. These are reading and search tasks that eat up hours of senior lawyers' time, and a well configured model speeds them up, always with a professional reviewing the output.

The problem is where the data goes. In Spain, the General Statute of the Legal Profession and the Code of Ethics require lawyers to keep secret everything a client entrusts to them. Circular 3/2026 of the Spanish General Council of Lawyers (CGAE), approved on 10 April 2026, accepts generative AI as an auxiliary tool under human supervision, reminds lawyers that responsibility remains theirs, and treats entering client data into a third-party AI as processing subject to the GDPR, with secrecy extending to the technical provider. Pasting a contract into a public chatbot hosted outside the EU hardly fits that framework.

Our answer is simple: the models run on our GPUs in Madrid, operated by our own team in Spain. You know where every document sits, who can access it and which contract covers it. You can start with a GPU fraction or a private endpoint and grow into a dedicated environment; prices are public on pricing and the technical detail is on infrastructure. We track the regulatory changes affecting the sector in the regulatory radar.

Use cases for law firms and legal departments

Four uses that already work with open models on our infrastructure. Each one can be tested first on GPU Flow with non-sensitive documents and then moved to a private environment.

Review and comparison of long case files and contracts

The model reads a full case file or two versions of a contract and returns a structured summary, the clauses that changed and the points worth checking: deadlines, penalties, assignments, jurisdiction. The lawyer decides; the machine does the first read. Each NVIDIA B200 GPU has 180 GB of memory, which lets us serve large models with room for long documents, and the whole process happens inside your environment in Madrid.

Qwen3.8 or GLM 5.3 · private endpoint · OCR with Qwen3-VL 32B for scanned files

Search over the firm's own precedents, with cited sources

We index your briefs, legal opinions, template contracts and relevant rulings in storage that belongs to you. The assistant answers questions in plain language and cites the document and passage behind every statement, so the lawyer can check it in seconds. That is exactly what Circular 3/2026 asks for: human verification of what the AI produces. The index and the documents stay in Madrid, in a storage space with quotas.

Semantic search with sources (RAG) · Qwen3 14B or Gemma 4 26B · dedicated Exascaler storage

Transcription of meetings, hearings and depositions

Recordings of client meetings, hearings or depositions are turned into text with Whisper large-v3, and a language model then produces minutes, per-speaker summaries and action lists. Recordings hold particularly sensitive information, so the audio is processed on our GPUs in Spain and, if you ask for it, is not kept after transcription thanks to the zero-retention option in the DPA.

Whisper large-v3 · Nemotron 3.5 Lightning 30B for summaries · optional zero retention

Private coding and automation for legal-tech teams

Teams building internal tools (document automation, integrations with the document management system, data extraction from contracts) need a coding assistant that can read the repository without sending it anywhere. We offer sandboxes with SSH, Python, Jupyter and coding agents from €0.15 per active hour, connected to models running on our GPUs through an API compatible with the OpenAI and Anthropic SDKs.

Sandboxes from €0.15/active hour · GLM 5.3 · OpenAI- and Anthropic-compatible API

How a case file's data travels

The full path of a document, from your firm to the model's answer. At no step does it leave Spain.

  1. 01

    Encrypted transfer

    The document leaves your document management system over an encrypted connection (TLS) or, if you prefer, over a dedicated encrypted point-to-point link, with post-quantum cryptography available.

  2. 02

    Processing in Madrid

    The model runs on NVIDIA B200 GPUs in our Tier III datacenter in Madrid, in an isolated MIG fraction, a dedicated pod or a full node reserved for you.

  3. 03

    Storage under your control

    Indexed documents and outputs are kept in your own storage space, with quotas and restricted access. With zero retention, requests are not kept once answered.

  4. 04

    Answer with sources

    The lawyer receives the summary or answer with references to the original document, reviews it and decides. No data is used to train models, ours or anyone else's.

Regulatory framework and how we help

What each relevant rule requires for AI in legal practice, and which part the infrastructure solves. Professional responsibility stays with the lawyer; we give you an environment that makes it easier to meet.

Regulatory framework and how we help
RuleWhat it requiresHow we help
GDPRA data processing agreement with every provider handling personal data, and safeguards for any transfer outside the European Economic Area.Standard DPA, data processed and stored in Spain, no subprocessors outside the EU and optional zero retention.
General Statute of the Spanish Legal Profession and Code of EthicsProfessional secrecy over all facts, documents and communications the lawyer learns through their professional work.Isolated environments in Madrid, access limited to your team and data that is never used to train models.
CGAE Circular 3/2026 on generative AIAI used as an auxiliary tool under human supervision, full responsibility of the lawyer and secrecy extended to the technical provider.Answers that cite the source document for verification, a provider bound by contract and a known location for all processing.
AI ActHigh-risk obligations from 2 December 2027 for systems that assist judicial authorities in researching and interpreting facts and law, or in alternative dispute resolution.Open models with identified versions and documented infrastructure, useful for technical documentation if your use case falls into that category.
LOPDGDD (Spanish Organic Law 3/2018)A duty of confidentiality for every person and entity involved at any stage of personal data processing.Our own team in Spain bound by confidentiality, platform certified to ISO/IEC 27001:2023 and ENS Medium by EQA.

Regulatory radar: legal

Updates affecting AI in law firms and legal departments, with dates and official sources. Full view in the regulatory radar.

  1. AI Act high-risk obligations for Annex III systems start to apply

    Covers credit scoring, life and health insurance pricing, justice, essential public services and employment. Requires risk management, data quality, logging, human oversight and technical documentation.

    Official source: EUR-Lex · Reglamento (UE) 2026/1744 ↗

    DeadlineEU
  2. EuroHPC AI Gigafactories call closes (up to 7 consortia)

    Awards are expected in early 2027. Spain is bidding with a public-private candidacy. It signals where European compute capacity for training and running models will be located.

    Official source: EuroHPC ↗

    DeadlineEU
  3. AI Omnibus Regulation (EU) 2026/1744 published: new timetable for high-risk AI

    In force since 27 July 2026. Annex III obligations move to 2 December 2027 and Annex I obligations (AI in regulated products such as medical devices) to 2 August 2028.

    Official source: EUR-Lex · Reglamento (UE) 2026/1744 ↗

    In forceEU
  4. CGAE Circular 3/2026: briefs drafted with generative AI are lawful if the signer verifies them

    The signing lawyer must check the output and preserve professional secrecy and data protection. In practice, it matters where client documents are processed and who can access them.

    Official source: Consejo General de la Abogacía ↗

    In forceSpain
  5. CGPJ Instruction 2/2026: judges may only use AI tools provided by the Administration

    It requires human control of every output and bans entering case data into non-official AI systems. It sets the confidentiality standard expected around the judiciary.

    Official source: BOE-A-2026-2205 ↗

    In forceSpain
  6. CGAE White Paper on artificial intelligence and the legal profession

    It covers confidentiality, supervision of outputs and choice of providers. It recommends knowing where client data is processed, and under which contract terms, before adopting a tool.

    Official source: Consejo General de la Abogacía ↗

    PublishedSpain

Recent laws, guidance and decisions →

Frequently asked questions

Can a law firm use generative AI without breaching professional secrecy?

Yes, as long as it controls where data is processed and who can access it. CGAE Circular 3/2026 accepts AI as an auxiliary tool under human supervision and extends secrecy to the technical provider. On our platform, case files are processed in Madrid, with no subprocessors outside the EU, without being used to train models and under a signed DPA.

Is my clients' data used to train models?

No. Customer data is never used to train models, ours or third parties'. On top of that, the standard DPA offers optional zero retention: requests are processed and not kept after the answer is returned. The models we use are open (Qwen, GLM, ALIA 40B, Gemma) and run on our own GPUs, so there is no third-party API behind them.

How much does it cost to get started?

A 1/8 fraction of an NVIDIA B200 GPU (about 23 GB) costs €1.50/h and a full GPU €8.00/h, excluding VAT. For pay-per-use inference, GPU Flow starts at €0.06 per million input tokens. On demand there is no commitment, subject to availability; reserved capacity is guaranteed, with a six-month minimum. Details on pricing.

Is AI used by a law firm high-risk under the AI Act?

Generally, no. The AI Act classifies as high-risk the systems that assist judicial authorities in researching and interpreting facts and law, and those used in a similar way in alternative dispute resolution, with obligations from 2 December 2027. Summarising or drafting for a client does not fall there, although each case is worth reviewing.

How long does it take to get a private environment?

A standard dedicated environment is ready 72 hours after signature. Before that you can test the models on GPU Flow with non-sensitive documents and size your GPU needs with us by measuring your real workload on our cluster. Support comes from our own team in Spain, in Spanish and English, with a response in under 4 hours on business days.

Can we connect it to the tools we already use?

Yes. The API is compatible with the OpenAI and Anthropic SDKs, so many tools and internal developments only need a new service address and key. Teams that build their own software get sandboxes with SSH, Python and Jupyter. If you would rather not write code, we help you define the use case and the right environment in a first conversation.

Let's talk

Tell us which documents you want to work on with AI and we will propose the environment

Talk to the team →