Transparency by construction.
The assistant tells people AI is answering, shows where every answer came from, and is contractually kept away from the uses the Act calls high-risk. Your deployer duties arrive already discharged.
The articles that matter, and where each lands.
The Act asks three things of a system like this: that people know they are talking to an AI, that the organisation deploying it keeps its people AI-literate, and that high-risk uses are kept out. Each one is a mechanism here, not a memo.
Because answers are grounded in the client's own record and carry their citations, the deployer can always show why the assistant said what it said, the property regulators keep circling back to.
Every conversational surface (web chat, sign-in, invitations, messaging channels, the CLI) discloses that answers are AI-generated and cited
The in-product help centre serves as the deployer's AI-literacy resource: how answers are produced, what citations mean, what the assistant refuses and why
Deployments are contractually excluded from high-risk uses; the product is a knowledge engine over business documents, and the terms keep it that
Answers cite their sources or decline; nothing executes actions, a human reads, verifies against the passage, and decides
What the assistant is, and refuses to become.
A knowledge engine over your own documents: it retrieves, grounds, cites and answers. It does not profile people, score candidates, evaluate employees, or trigger actions in other systems. Where a corpus contains people, GDPR mechanisms, export, erasure, records, run underneath every answer.
That boundary is contractual as well as technical: the terms exclude Annex III uses, so the system your counsel reviewed is the system your teams get.
For your counsel's file.
How a deployment is built: the single-tenant boundary, the permission model, the audit chain and the AI data flow: the document a security review starts with.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
Send your own questionnaire: CAIQ, SIG, or your in-house sheet, in the request note. Answers come from the architecture, not a boilerplate script.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
The position paper itself is readable in the trust library, beside the architecture overview it depends on.
The AI Act, answered for deployers
Does the EU AI Act apply to a company using AI on its own documents?
Yes, as a deployer you carry transparency and AI-literacy duties. Naxis Assistant is built so those duties are already discharged in the product: every surface discloses the AI interaction (Article 50), and the in-product help centre serves as the literacy resource Article 4 expects.
Is a company knowledge engine a high-risk AI system?
Answering questions over business documents is not an Annex III high-risk use, and deployments are contractually excluded from being turned into one. The product answers questions; it does not score people, filter candidates, or decide anything about persons.
How do people know they are talking to an AI?
Every conversational surface says so: web chat, sign-in, invitations, messaging channels, even the CLI. Disclosure is not a setting that can be switched off.
What keeps a human in charge of the outcome?
The assistant cites its sources or declines, it never executes actions. A human reads the answer, opens the cited passage, verifies, and decides. Oversight is the workflow, not an add-on.
Where is this position written down for our records?
The position paper is readable in the trust library, and the architecture overview it depends on can be requested as a signed document from your account.
Read the whole record.
The Act's articles, the GDPR mechanisms and the architecture live on one page, readable now.