EU AI Act
Soriku is designed inside the EU AI Act, not adapted to it afterwards. Local-first architecture turns most of the Act's requirements into the default state.
Risk tier
Soriku itself is a general-purpose AI tool, classified as limited risk under the Act. The risk tier of how you use it depends on what you build on top: a customer-service chatbot is limited risk, an automated hiring tool is high risk.
How Soriku maps to the Act
| Act requirement | How Soriku addresses it |
|---|---|
| Transparency | Every routed prompt has provenance: which model answered, which constraints applied, when it was routed. |
| Traceability | Routing decisions logged to data/routing_log.jsonl. Append-only, timestamped, auditable. |
| Human oversight | Pilot mode tool calls require human confirmation by default. Plan mode shows the full task DAG before execution. |
| Data minimisation | Local-first by default. Prompts and completions never leave the device unless you opt in. |
| Vendor accountability | Atypisch, Dutch entity, GDPR-bound. No reliance on US CLOUD Act jurisdiction. |
Enterprise compliance support
Enterprise customers get formal compliance documentation: risk-tier assessment tailored to your use case, DPA on request, evidence pack mapping each Act article to engine guarantees.