Wealth Management by Zahlenwerk is now in beta. Join the waitlist

AI and the EU AI Act

Your compliance team will ask where we sit under the AI Act before your investment team asks anything else. This is the answer, with the reasoning shown rather than summarised. It is our own reading, not an external legal opinion, and we say so below rather than in a footnote.

What we are under the Act

A provider of an AI system, and a deployer of someone else's model

We build and put into service the in-app assistant, the document extractor and generated reports, which makes us a provider. We run them on Google's Gemini through Vertex AI, which makes us a deployer. Building on someone else's model does not move the provider role onto them: the system you use is ours, and so is the answer for it.

We are not a general-purpose AI provider

We train no models and place none on the market. The obligations that apply to model providers, including the systemic-risk tier, are theirs rather than ours. We are downstream of them, the same as you are downstream of us.

Your own key moves that boundary

If your team connects its own provider key, that provider becomes your processor choice rather than ours, the call leaves our EU-pinned pipeline, and your team takes on the deployer role for it. We say this in the Terms, on this page, and in the product on the screen where you paste the key, because finding it only in the Terms would be a fair complaint.

Which risk tier, and why

Nothing here is a prohibited practice

No social scoring, no manipulation, no untargeted scraping of faces, no emotion inference in the workplace, no biometric categorisation. The product values assets. It makes no inference about any person at all.

Not high-risk, and the two exclusions worth naming

We went through Annex III point by point. Fund and portfolio reporting is not a listed area. The two a careful reader would still check: we do not assess the creditworthiness of natural persons, and we make no employment or worker-management decisions. We are also outside Annex I, which covers AI embedded in regulated products.

This does not depend on the Digital Omnibus

The Omnibus deferred high-risk obligations to December 2027 and August 2028. That deferral is not what we are relying on. We would be outside the high-risk tier on the original schedule too, and if that ever changes, because we added something that scores a person rather than an asset, the honest thing is a new assessment rather than a quiet reinterpretation of this one.

So Article 50 is the part that binds us

The transparency duties took effect on 2 August 2026. They apply whatever the risk tier, and they are the substance of the next section.

How we meet Article 50

The assistant tells you it is an AI

Article 50(1) allows an exemption where it is obvious to a reasonably well-informed person, and for an assistant you open deliberately, in a product whose pricing page discusses AI allowances, that argument would probably hold. We disclose under the composer anyway. A line of text is cheaper than an argument.

Generated reports are marked so a machine can read it

Article 50(2) asks for marking that is machine-readable, not merely a sentence a person can see. A generated report carries both: an XMP packet and document properties in the PDF, core and custom properties in the .docx, meta tags and JSON-LD in the hosted view, plus the sentence in the small print. The same flag drives all of them, so the footer and the file properties cannot say different things.

Extraction is not marked, and that is deliberate

When the model reads your uploaded PDF and returns its figures, it transforms your own input rather than generating new content, which we read as the assistive-function exemption in Article 50(2)(a). Marking an extracted NAV as artificially generated would misdescribe it: the number is an attribute of your document, and your auditor would be right to object. Your letters are not marked either, because people write them.

Where we cannot name the model, we do not guess one

Some documents are exported long after their text was written, by whichever model was current then, or by your provider on your key. Those are marked as AI-generated without a model name rather than with an assumed one. The declaration is the obligation; the model name is a detail, and a wrong detail is worse than a missing one.

Nothing here is published to the public

The obligation on AI-generated text about matters of public interest does not reach us: generated reports are visible to the team that owns the account, there is no public link, and a person holds editorial responsibility for what leaves. We mark them regardless.

Approval is recorded, not just performed

An extraction below the confidence bar is inert until someone clears it, and the record now stores who cleared it and when. The gate always worked. What changed is that it now leaves evidence, which is the difference between describing a workflow and being able to show one.

AI literacy

Article 4, in force since February 2025

Providers and deployers must ensure a sufficient level of AI literacy among the people operating the system, measured against their role. Zahlenwerk is two people, both of whom build this directly. The confidence gating and the pseudonymisation boundary exist because of what we know about how these models fail, which is the same knowledge the article is asking for. We review it annually and record the date.

How it is actually built

Identifiers replaced before anything reaches a model, EU-pinned processing that raises an error rather than quietly falling back, a confidence bar below which a report cannot touch your portfolio, and an assistant with no delete operation. All of that is described in one place rather than twice, on the security page.

What we do not claim

The same list we keep on the security page, for this subject. These are the things a compliance team reasonably asks about and we cannot honestly tick yet.

  • We have no external legal opinion on this classification. It is our own reading of the Act, and we would rather tell you that than imply a lawyer signed it off.
  • We are not registered in any EU database, and do not need to be. Registration is a high-risk obligation, and the section above explains why we are outside that tier.
  • Our marking is metadata, not cryptographic provenance. It states that a document was AI-generated; it does not prove the document is unaltered. C2PA content credentials would, and we have not implemented them.
  • Marking survives our own exports. It does not survive someone copying the text into their own template, and nothing we can do at our layer changes that.
  • We cannot yet make a contractual statement about model providers retaining or training on data. Ask us and we will show you the current agreements rather than guess.

Questions your compliance team would ask

We will share the full internal assessment behind this page, answer specifics, and tell you plainly where our reading is a judgement call rather than a settled point. These questions reach the two of us directly.

Get in touch
EN
EnglishDeutschEspañol