Trust Center · Compliance

EU AI Act — position statement

AXOS as a deployment platform; risk tier by customer use case; hooks provided for high-risk deployers.

Back to Trust Center

Source: docs/compliance/eu-ai-act.md

EU AI Act — position statement for AXOS

Regulation Regulation (EU) 2024/1689 (the "AI Act")
Version of this statement 1.0
Review date 2026-08-21
Next review 2027-02-21, or earlier if the Commission publishes relevant guidance or harmonised standards
Owner Data Protection Lead, ScotiTech Solutions Limited

Summary

AXOS is a deployment platform: a self-hosted workspace with an AI agent that customers configure and operate inside their own infrastructure, connected to a model endpoint the customer chooses.

Under the AI Act the risk tier attaches to the AI system as used, not to the platform in the abstract. The same AXOS installation can host a minimal-risk internal knowledge search in one workspace and a use case that meets the Annex III high-risk definition in another. The customer, as deployer, classifies each use case. ScotiTech supports that classification; it does not make it.

We do not claim AXOS is "AI Act compliant". Compliance is a property of a specific system in a specific use, operated by a specific deployer. What we claim is that AXOS is designed to support deployers who must meet the Act's obligations, and that we are transparent about where those hooks are and where they are not.

Roles

AI Act role Who Notes
Provider of a general-purpose AI model The model vendor the customer connects (e.g. Azure OpenAI, Anthropic, Bedrock, a self-hosted open-weight model) ScotiTech does not train or place GPAI models on the market.
Provider of an AI system ScotiTech, for the AXOS software as shipped We provide the system; we do not decide its intended purpose in a given deployment beyond the documented product functions.
Deployer The customer Determines the use case, the data, the affected persons, and therefore the risk tier.
Distributor / importer Not applicable in the typical direct engagement

Risk tier by customer use case

Customer use case (examples) Likely tier Customer obligations (non-exhaustive) AXOS hooks
Internal knowledge search, drafting assistance, meeting summaries Minimal risk Voluntary codes of conduct; general transparency good practice Transparency to end users, logging
Chat assistant interacting with members of the public Limited risk (Art 50) Inform the person they are interacting with an AI system End-user AI disclosure label; configurable system prompt
Sorting or ranking job applications; credit or insurance eligibility; access to essential services; education admission or assessment High risk (Annex III) Risk-management system, data governance, technical documentation, record-keeping, transparency and instructions for use, human oversight, accuracy/robustness, fundamental-rights impact assessment where required (Art 27), registration where required Audit logging, human-in-the-loop review gates, per-workspace model and source scoping, technical documentation pack, export of logs to customer SIEM
Social scoring, real-time remote biometric identification in public, emotion inference in workplace/education, manipulative techniques Prohibited (Art 5) Must not be deployed Prohibited by the AXOS Acceptable Use Policy and Terms s.4

What AXOS provides to support high-risk deployers

These are product capabilities that exist today. "Evidence available" means we can show it working in a technical review.

Act requirement What AXOS provides Status
Record-keeping / logging (Art 12) Per-request audit events: identity, scope resolved, sources retrieved, model called, response hash. Exportable via syslog / webhook to the customer SIEM. Evidence available
Human oversight (Art 14) Configurable review gates on AI-generated actions; role-based approval before an action is committed; ability to disable AI features per workspace. Evidence available
Transparency to end users (Art 13, Art 50) AI-generated content is labelled in the UI; system-prompt disclosure is configurable; citations link back to source documents. Evidence available
Technical documentation (Art 11, Annex IV) Architecture and data-flow documentation, component inventory, model-connection design, logging schema, security controls. Supplied as the technical documentation pack. Evidence available
Data governance (Art 10) ACL-first retrieval so the model only sees content the user may access; per-workspace source scoping; retention controls. Evidence available
Accuracy, robustness, cybersecurity (Art 15) Security controls in the Trust Center; model accuracy depends on the customer-selected model and is the customer's to evaluate for their use case. Partial — platform controls evidence available; model-level accuracy not evaluated by ScotiTech
Quality-management system (Art 17) ScotiTech's engineering process: version control, CI, code review, coordinated disclosure. Not yet certified to ISO 42001. Gap — roadmap
Conformity assessment, CE marking, EU database registration Deployer / provider obligation for the specific high-risk system. Not applicable to the platform; customer responsibility
Fundamental-rights impact assessment (Art 27) Customer's obligation. ScotiTech supplies platform-level inputs via the DPIA support note. Customer responsibility

Limitations (stated plainly)

  • AXOS does not assess or certify your use case. Classification is yours.
  • AXOS has no control over the behaviour, accuracy, or training data of the model you connect.
  • ScotiTech does not hold ISO/IEC 42001 or any AI-specific certification today.
  • Harmonised standards under the Act are still being finalised; we will revise this statement when they are published.

Customer responsibilities

  1. Classify each use case before go-live and record the reasoning.
  2. For limited-risk uses, enable the end-user AI disclosure.
  3. For high-risk uses, stand up the deployer obligations above, using the AXOS hooks as inputs — not as a substitute.
  4. Do not deploy Art 5 prohibited practices.
  5. Keep your DPIA / FRIA current as the use case changes.

Related

  • Terms of Use s.4 (AI-specific acceptable use) and s.5 (risk classification)
  • Data Processing Agreement — DPIA support note
  • Framework mappings: NIST AI RMF, NCSC secure AI development, ICO AI guidance