← Back to home

AI Transparency Statement

Last updated: 24 April 2026

This statement describes how FileGPT.dev uses artificial intelligence, what customers and users should expect, and how we approach transparency under the EU Artificial Intelligence Act (EU AI Act). It supplements our Privacy Policy and Data Processing Agreement.

1. Purpose of the AI

FileGPT.dev builds private RAG (Retrieval-Augmented Generation) systems for technical document workflows. AI is used for:

  • Embedding generation: Semantic vector representations of document segments for retrieval.
  • Source-grounded answer generation: Natural-language answers based exclusively on approved document excerpts — with source references for human verification.
  • Structured extraction: Requirements, clauses, or key figures from technical documents such as specifications, RFQs, or quality standards.

AI does not replace professional, legal, medical, or safety-critical judgment. Outputs are to be treated as working aids, not final determinations.

2. Capabilities and limitations

Answers are produced by generative models and may be incomplete, outdated, or incorrect. The system is designed to ground responses in approved sources — however, it is possible that:

  • retrieval selects the wrong passage,
  • tables lose structural information during parsing,
  • the model draws an incorrect conclusion from correct context (confabulation).

The system is configured to rely only on supplied excerpts and not to make claims about information that is absent from the context. During the pilot, acceptance criteria and an evaluation set of real expert questions are defined to make actual quality measurable.

3. Data flow and minimisation

To answer a request, the system retrieves a limited set of relevant document passages and transmits these together with the user query to the configured language model. Complete document archives are not sent to the model.

Technical and organisational measures depend on the specific deployment — on-premise, private cloud, or isolated environment. The exact infrastructure is jointly defined during the assessment and documented in the DPA.

4. Human oversight and responsibility

Customers and users remain responsible for how AI outputs are used — particularly for legal, safety-critical, financial, or operationally significant decisions. The system supports human review through source references and auditable logging; it does not replace it.

Where a pilot is moved into production processes, approval mechanisms and human control points are established in the operating concept.

5. EU AI Act: roles and high-risk context

Whether a specific use case qualifies as a "high-risk AI system" under the EU AI Act (e.g. per Annex III) depends on the deployment context. Customers who integrate the system into their own products or decision-making processes must assess their own obligations as deployers or operators — including applicable conformity and governance requirements.

FileGPT.dev assesses its own position as provider of the implemented system and can supply contractually or informationally required documentation. Enquiries should be directed to info@filegpt.dev.

6. General-purpose AI (GPAI) models

The language and embedding models used may qualify as general-purpose AI models under the EU AI Act. The specific model is selected jointly with the customer during the assessment and documented — from locally operated open-source models to contractually controlled enterprise API services. Customers deploying the system may require provider documentation or contractual assurances for their own compliance programmes, which we will supply to the extent possible.

7. Updates

This statement may be updated as the service offering or legal requirements evolve. Material changes will be reflected in the "Last updated" date above and, where appropriate, communicated directly to customers.