docs / compliance / eu-ai-act

EU AI Act

Soriku is designed inside the EU AI Act, not adapted to it afterwards. Local-first architecture turns most of the Act's requirements into the default state.

Risk tier

Soriku itself is a general-purpose AI tool, classified as limited risk under the Act. The risk tier of how you use it depends on what you build on top: a customer-service chatbot is limited risk, an automated hiring tool is high risk.

How Soriku maps to the Act

Act requirementHow Soriku addresses it
TransparencyEvery routed prompt has provenance: which model answered, which constraints applied, when it was routed.
TraceabilityRouting decisions logged to data/routing_log.jsonl. Append-only, timestamped, auditable.
Human oversightPilot mode tool calls require human confirmation by default. Plan mode shows the full task DAG before execution.
Data minimisationLocal-first by default. Prompts and completions never leave the device unless you opt in.
Vendor accountabilityAtypisch, Dutch entity, GDPR-bound. No reliance on US CLOUD Act jurisdiction.

Enterprise compliance support

Enterprise customers get formal compliance documentation: risk-tier assessment tailored to your use case, DPA on request, evidence pack mapping each Act article to engine guarantees.

DPA →