Trust Center

EU AI Act

Who is the provider, who is the deployer — and which obligations follow? How DeepMask fits into the AI Act.

The AI Act at a glance

Regulation (EU) 2024/1689 on artificial intelligence — the AI Act — entered into force on 1 August 2024 and applies in stages. It does not regulate AI systems as a blanket category but according to the risk of their concrete use, and it distributes obligations across different roles along the value chain.

For you as a customer, one distinction matters most: DeepMask is the provider of the platform, you are the deployer within your own organisation. The two roles carry different obligations — and both are achievable. This page sets out what they are and what DeepMask supplies for them.

Split of roles

Provider

DeepMask GmbH

  • Development and provision of the AI platform under its own name
  • Technical documentation of the models used and their origin
  • Transparent labelling of AI-generated content
  • Provision of the information you need as a deployer to meet your obligations
  • Selection of, and contractual arrangements with, the model providers

Deployer

Your organisation

  • Use of DeepMask in line with its intended purpose and the terms of use
  • Ensuring sufficient AI literacy among staff (Art. 4 AI Act)
  • Human oversight of results — in particular before decisions with external effect
  • Informing affected persons where the concrete use case requires it
  • Checking whether your own use case falls into a higher risk class

If you deploy DeepMask under your own name or brand, or substantially modify its intended purpose, you may become a provider yourself under Art. 25 AI Act. Talk to us in that case — we will help you draw the line.

Risk classification

The AI Act regulates AI systems according to four risk levels — the higher the risk of the concrete use, the stricter the obligations.

Unacceptable risk

Prohibited · Art. 5 AI Act

Practices that violate fundamental rights are banned entirely.

e.g. social scoring, emotion recognition in the workplace, manipulative techniques

High risk

Strict requirements · Art. 6, Annex III

Significant risk to health, safety or fundamental rights — permitted only with conformity assessment, risk management and human oversight.

e.g. candidate selection, employee performance evaluation, creditworthiness assessment

DeepMask's classification

Limited risk

Transparency obligations · Art. 50 AI Act

AI systems that people interact with or that generate content. Users must be able to tell that AI is in use.

e.g. AI assistants, AI-generated content

Minimal risk

No special obligations

All remaining AI systems — the regulation imposes no additional requirements.

e.g. spam filters, spell checkers

DeepMask as a platform: limited risk — not a high-risk AI system

  • DeepMask is a general-purpose AI system: a workspace for writing, research, document analysis and evaluation.
  • The platform makes no automated decisions about people. Results are presented as suggestions; the decision rests with a human.
  • The intended purpose expressly excludes the employment-related applications listed in Annex III No. 4 AI Act — in particular monitoring and evaluating the performance and behaviour of employees. The exclusion is a fixed part of the DPA as an annex.
  • There is no biometric identification, no social scoring and no emotion recognition in the workplace — the practices prohibited under Art. 5 are excluded.
  • What follows for DeepMask are the transparency obligations under Art. 50: users can always tell that they are working with an AI system and can see which model in which region is answering.

Important: the risk class depends on the use case, not on the tool alone. If you deploy DeepMask in an area listed in Annex III — for example to evaluate job applications, to assess creditworthiness or in education — your use case may qualify as a high-risk AI system. Additional obligations then apply to you as the deployer. We will support you with that assessment.

Intended purpose and excluded applications

Whether an AI system qualifies as high-risk depends under the AI Act on what it is “intended to be used for”. What matters is therefore the intended purpose defined by the provider (Art. 3 No. 12 AI Act). DeepMask defines it as follows — and expressly delimits it.

What DeepMask is intended for

Professional support

Support for professional activities: writing, research, and analysis and evaluation of documents and data — with the AI model best suited to each task.

Automation of work steps

Automation of recurring work steps within the business processes defined by the controller.

The human decides

Results are provided exclusively as suggestions — the decision always rests with a human.

Employee data for administration only

Processing of employee data exclusively for the provision and administration of the platform (user accounts, authentication, permission management, security logging) and to the extent that employees use the platform in the course of their work and enter content in doing so.

Expressly excluded applications

The following applications are not part of DeepMask's intended purpose. They are neither provided as features nor permitted contractually:

Monitoring and evaluating employee performance and behaviour

Annex III No. 4 lit. b AI Act

DeepMask is not intended to monitor or evaluate the performance or behaviour of employees. Usage and log data is evaluated exclusively for the purposes of information security, error analysis and evidencing system integrity — not to monitor the performance or conduct of individual employees.

Decisions on the terms of employment relationships

Annex III No. 4 lit. b AI Act

No use for decisions on the establishment, terms, remuneration, promotion or termination of employment relationships.

Task allocation based on individual behaviour or personal traits

Annex III No. 4 lit. b AI Act

No allocation or prioritisation of tasks based on the individual behaviour or personal traits or characteristics of employees.

Recruitment and selection of natural persons

Annex III No. 4 lit. a AI Act

No use for targeted job advertisements, for analysing and filtering applications, or for evaluating candidates.

Emotion recognition in the workplace

Art. 5(1) lit. f AI Act

DeepMask does not recognise or infer employees' emotions. This practice is prohibited under the AI Act and is not technically part of the platform.

Biometric identification, biometric categorisation and social scoring

Art. 5(1) lit. c and g, Annex III No. 1 AI Act

No biometric identification or categorisation of natural persons and no evaluation or classification of persons based on their social behaviour.

Further high-risk areas of Annex III

Annex III No. 2, 3, 5–8 AI Act

No intended use as a safety component of critical infrastructure, in education, for creditworthiness or risk assessment of natural persons, in law enforcement, in migration and asylum matters, or in the administration of justice.

Contractually agreed, not merely described

The intended purpose is defined by DeepMask as the provider (Art. 3 No. 12 AI Act) — it is not an option but part of the product definition. That is why the annex “Intended purpose under the AI Act and exclusion of high-risk applications” is a fixed part of every DPA export and is referenced in section I of the agreement. The exclusion works contractually in both directions: DeepMask does not provide the corresponding functions, and the controller is not entitled to use the platform in that way.

If the controller modifies the intended purpose in such a way that a high-risk AI system arises, the controller is itself deemed a provider under Art. 25(1) lit. c AI Act and bears the associated obligations. Extending the intended purpose requires a separate written agreement — please talk to us beforehand.

Note on co-determination: since DeepMask is not intended to monitor employee performance and behaviour, the platform is not a technical device aimed at such monitoring. Whether co-determination rights of the works council nevertheless exist in a specific case — for example under Section 87(1) No. 6 of the German Works Constitution Act (BetrVG) or based on a company agreement on AI use — depends on the concrete deployment within the organisation and is the controller's responsibility.

Obligations in detail

For every central obligation of the AI Act, this sets out what DeepMask delivers and what remains your responsibility as the deployer.

When it applies

The AI Act applies in stages. These dates are relevant to deploying DeepMask.

1 August 2024

Already applies

Entry into force

The AI Act enters into force; the transition periods begin.

2 February 2025

Already applies

Prohibited practices and AI literacy

The prohibitions under Art. 5 apply. At the same time the AI literacy obligation under Art. 4 takes effect for providers and deployers.

2 August 2025

Already applies

Obligations for GPAI models

The obligations for providers of general-purpose AI models and the member states' governance structure apply.

2 August 2026

Current

General applicability

The bulk of the regulation becomes applicable — including the transparency obligations under Art. 50 and the obligations for high-risk systems under Annex III.

2 August 2027

Upcoming

High-risk systems in products

The obligations for high-risk AI systems embedded as a safety component in regulated products (Annex I) become applicable.

How DeepMask supports you

Your obligations as a deployer cannot be outsourced — the evidence for them can. These are the building blocks we provide:

  • Intended purpose with exclusion of the high-risk applications under Annex III — a fixed part of every DPA as an annex
  • Complete list of all models in use, with provider, hosting region and knowledge cut-off
  • Public list of subprocessors, kept current at all times
  • Configurable DPA under Art. 28 GDPR including the TOMs as an annex
  • Restriction of model selection to endpoints hosted in Germany or the EU
  • Usage analytics per organisation as a basis for your internal governance
  • A contact for questions on classifying your concrete use case
Questions about classifying your use case?contact@deepmask.io

Note

This overview summarises the state of the AI Act and describes how DeepMask handles it. It does not constitute legal advice. For the classification of your concrete use case — in particular for potential high-risk applications under Annex III — we recommend an individual legal assessment.