Where AI is used in GRCxAI, how we disclose it, and how generated content is marked. Published so that a customer, a reseller or a regulator can read our position without asking for it.
AiBizzApps Limited is established in the United Kingdom, which is not an EU member state. That is not an exemption. The AI Act reaches providers established outside the EU where an AI system is placed on the EU market, or where the output of the system is used in the EU. GRCxAI is sold to customers in the European Economic Area, directly and through resellers, so we treat ourselves as in scope by design rather than by accident.
We would rather be in scope and say so. A product sold on the strength of EU AI Act readiness cannot sensibly argue its way out of the same regulation.
The AI Act allocates duties by role, and the roles are not interchangeable:
Every AI feature in the platform is listed here. Where a feature is not listed, it does not use a large language model.
| Feature | What the AI does | Output reviewed by a person |
|---|---|---|
| Compliance chatbot | Answers clause-level questions across the supported standards, in a conversational interface. | Interactive — disclosed at the start of the conversation |
| Document generation | Drafts policies, procedures and framework documents from your own records and context. | Yes — always presented as a draft for approval |
| Report generation | Drafts assessment reports, board reports and the Provision 29 annual report narrative. | Yes — always presented as a draft for approval |
| Risk analysis and briefings | Summarises and analyses risks, and drafts risk narratives. | Yes — decision support, not a decision |
| Risk extraction from assessments | Proposes candidate risks from an assessment report. | Yes — a mandatory review grid before anything is created |
| Third-party evidence review | Reads uploaded supplier evidence and proposes a verdict against the answer given. | Yes — findings are triaged by a person |
Inference is provided by Anthropic, PBC, as recorded in Schedule 4 of the Master Subscription Agreement. Customer Data is not used to train models.
Where GRCxAI interacts directly with a person, it says that it is an AI system. This applies to the compliance chatbot and to any future feature that converses with a user. The disclosure is shown at the start of the interaction, in the interface, without the user having to look for it.
This obligation carried no grace period. It has applied since 2 August 2026.
Article 50(2) requires synthetic content to be marked in a machine-readable form, so that software can detect it was AI-generated. A visible notice on a document is useful to a reader, but it does not by itself discharge this obligation.
Current status: this work is in progress. Systems already on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty, and we are working to that date. We will state here, with a date, when it is live.
What we intend to mark, and what we do not:
We are also assessing whether the business-to-business exemption in the Commission's guidance applies to how GRCxAI is actually used. We will record the conclusion here either way, because a determination nobody can see is worth very little.
One honest limitation: for plain text, no current marking technique satisfies every criterion the Act sets out. Where that is so, our position is to apply the best available method and to document what we did and why, against the state of the art at the time.
Our assessment is that GRCxAI is not a high-risk AI system under the AI Act. Governance document drafting, risk analysis, audit findings and a standards chatbot do not map to an Annex III category. On that basis the Article 16 provider obligations for high-risk systems — conformity assessment, CE marking, EU database registration, a technical file, an authorised representative — do not apply.
This is our determination, taken with advice, and it is kept under review. It would be revisited if the platform gained a capability that changed the analysis. We state it plainly because it is the first question a buyer's counsel asks.
The Commission's Code of Practice on transparency of AI-generated content offers signatories a predictable route to demonstrating compliance. Our position on signature is under consideration and will be recorded here once settled.
Questions about this statement, or a request for the underlying documentation as part of a procurement or audit: [email protected].
This statement is published as a factual description of our position. It is not legal advice, and it does not form part of the Master Subscription Agreement except where that agreement refers to it.
The platform carries an EU AI Act module — classification wizard, 84 obligations, Article 27 fundamental-rights assessments and a model registry.