Aixy·
GDPR EU AI Act Security Subprocessors Privacy

Responsible AI

EU AI Act transparency

How Aixy assesses its role in the AI value chain, screens design-lead use cases, and documents applicable EU AI Act controls.

Last reviewed
26 August 2026
Status
Publication draft
Not a public compliance claim yet.

This material is prepared for review, but Aixy has not enabled the EU AI Act compliance claim. The remaining role, transparency, evidence, and approval gates are listed on this page.

EU AI Act Readiness programme In progress

A documented path to EU AI Act readiness

The badge links to Aixy's current scope, role assessment, controls, and unresolved evidence. It is not a certification, CE marking, conformity assessment, or regulator endorsement.

Current role assessment

Gateway and control plane

Aixy authenticates, applies configured access, budget, routing, telemetry and guardrail controls, then sends eligible requests to a customer-selected model provider. Deterministic gateway functions are not automatically AI systems; each component still requires an Article 3(1) assessment.

Models and the value chain

Aixy does not currently claim to develop or train a general-purpose AI model. Its role may vary by feature and transaction—supplier, distributor, importer, provider or deployer—depending on branding, provider establishment, modification and intended purpose.

A general gateway is not high-risk merely because it can route to an AI model. Every production design lead must be screened against prohibited practices, Article 50 transparency, Annex I and Annex III use cases, and any fundamental-rights impact requirements.

Application timeline

DateApplicable scope
2 February 2025AI literacy measures and most prohibited practices
2 August 2025Governance and general-purpose AI model obligations
2 August 2026General application, enforcement, and Article 50 transparency obligations
2 December 2026Additional prohibited practices and the limited marking transition for pre-existing synthetic-content systems
2 December 2027High-risk systems classified under Annex III
2 August 2028High-risk systems embedded in Annex I regulated products

The 2027 and 2028 dates reflect Regulation (EU) 2026/1744. They do not postpone already-applicable prohibitions, AI literacy measures, transparency duties, GPAI rules, or other EU law.

Accountability controls

  • System and model inventory. Components, upstream providers, model versions, intended purposes, operator roles, risk conclusions and evidence must be registered and reviewed.
  • Design-lead admission gate. Every production pilot is screened for prohibited practices, high-risk categories, affected people, transparency, human oversight and fundamental-rights impact.
  • Access and stop controls. Organization and project permissions, API keys, model restrictions, routing policy and budgets can constrain or stop use without changing client applications.
  • Human oversight support. Customers retain control of purpose, provider and final decisions; pilot terms must identify the competent reviewer, override route and stop conditions.
  • Change and monitoring evidence. Model/provider changes, audit events, incidents, complaints and corrective actions require owned records and reassessment triggers.
  • Privacy-preserving operations. Prompt and response capture remains disabled by default. AI Act evidence should use bounded metadata and configuration where possible rather than copying customer content into logs.

Article 50 transparency

Where an AI system directly interacts with a natural person, the responsible provider must ensure an appropriate first-interaction notice unless the interaction is objectively obvious. Providers of systems generating synthetic content may also have machine-readable marking duties. Deployers have separate disclosure duties for deepfakes, certain public-interest text, emotion recognition and biometric categorisation.

For Aixy, the responsible party depends on the integrated system and use case. The customer normally controls the end-user interface, while upstream providers control model-output capabilities. Aixy must document that allocation, preserve required provenance where available, and avoid claiming marking support until it has been verified model by model.

Information available to design leads

Technical and organizational measuresAccess, encryption, monitoring, availability and incident controls. Provider and subprocessor transparencyService roles, processing purpose, locations and public terms. GDPR transparencyPrivacy roles, content boundaries, retention and customer responsibilities. Use-case assessmentRequest the design-lead screening and evidence discussion.

Publication gate

The stronger “EU AI Act compliance programme” wording remains disabled until every applicable item below has an owner, approval and retained evidence.

  • Approved operator identity, accountable AI owner, and legal/technical reviewers
  • Component-by-component AI-system classification and operator-role assessment
  • Production AI system and upstream model inventory with versions and intended purposes
  • Completed prohibited-practice, transparency, high-risk, and fundamental-rights screen for the first design lead
  • Verified Article 50 disclosures and synthetic-content marking or metadata pass-through
  • AI literacy completion, incident exercise, upstream documentation, and production control evidence

What the badge does not mean

The badge does not mean that Aixy, every upstream model, or every customer deployment is automatically compliant. It does not state that Aixy is a GPAI model provider, that a high-risk conformity assessment has been completed, or that an authority has approved the service.

Customers remain responsible for their own intended purposes, deployer duties, notices, human oversight, impact assessments and sector-specific law. Aixy's role and obligations must be reassessed when a feature, provider, model, use case or contractual presentation changes.

Official references

Consolidated EU AI Act · European Commission implementation timeline · Article 50 transparency guidance · Official compliance checker

Aixy·
Privacy Cookies Legal notice DPA EU AI Act Compliance contact