EU AI Act Compliance

Risk Assessment, Transparency Statement, and Compliance Declaration

Last updated: July 2026

Executive Summary

faktry is committed to compliance with the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689). This document provides a comprehensive risk assessment of our AI systems, our compliance measures, and transparency obligations under the EU AI Act.

Overall Risk Classification: Limited Risk

All AI systems operated by faktry fall under the "limited risk" category under Article 50, primarily requiring transparency obligations. None of our systems fall under the high-risk categories defined in Annex III. We are implementing compliance measures in advance of the August 2026 full-application date.

EU AI Act Application Timeline

The EU AI Act applies in phases. Provisions currently in force:

  • 2 Feb 2025: Prohibited practices (Article 5) — in force
  • 2 Aug 2025: GPAI model obligations (Articles 51–56) — in force for model providers
  • 2 Aug 2026: Transparency obligations (Article 50) and most deployer obligations — upcoming
  • 2 Aug 2027: Remaining high-risk system provisions (Annex III legacy systems)

faktry is implementing the measures described in this document ahead of the 2 August 2026 deadline.

1. About the EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It establishes a risk-based approach to AI regulation, categorizing AI systems into four risk levels:

  • Unacceptable Risk: Banned AI practices (e.g., subliminal manipulation, social scoring, real-time biometric identification in public spaces)
  • High Risk: AI systems with significant potential harm, requiring strict compliance (e.g., medical devices, recruitment tools, critical infrastructure)
  • Limited Risk: AI systems requiring transparency obligations (e.g., deepfake-capable generators, chatbots, content generation)
  • Minimal Risk: AI systems with no specific obligations (e.g., spam filters, games)

2. Roles and Responsibilities

Under the EU AI Act, different obligations apply depending on whether an entity is a provider (developer of an AI system) or a deployer (entity that uses an AI system in a professional context).

faktry's Role: Deployer of Third-Party AI Systems, and Provider of the Integrated Platform

faktry acts as a deployer of the individual AI models provided by third parties (OpenAI, Black Forest Labs, Google, ElevenLabs, fal.ai, etc.). faktry does not develop, train, or fine-tune any foundation models or general-purpose AI (GPAI) models, so the GPAI-specific obligations under Articles 51–56 apply to our upstream model providers, not to faktry.

faktry also acts as a provider of the integrated AI application it offers under its own name — the software that combines, sequences, and presents access to third-party AI capabilities. We do not treat this as settling which entity bears the machine-readable marking duty under Article 50(2) for every output: our outputs carry the marking applied by the underlying model provider (see Section 5.3), so the transparency outcome required by Article 50(2) is met regardless of how that question is ultimately resolved.

3. AI Systems Inventory

faktry integrates the following AI systems in its platform. All AI calls are routed through our backend processing pipeline with input content moderation applied before any generation request is dispatched.

3.1 Image Generation & Editing

FeatureModels UsedProviderRisk Level
Text-to-Imagegpt-image-1, gpt-image-1.5, gpt-image-2OpenAILimited
Text-to-ImageFlux 2 Pro / Max / Flex (incl. EU-hosted variants)Black Forest LabsLimited
Image Editing / Inpaintinggpt-image-1/1.5/2, Flux 2 Pro/Max/Flex Edit (incl. EU variants)OpenAI, Black Forest LabsMinimal
Upscaling / EnhancementVarious models via fal.aifal.aiMinimal

3.2 Video Generation

FeatureModels UsedUnderlying ProviderRisk Level
Text-to-VideoKling v2.1/v2.5/o3 (Kuaishou), Sora 2 (OpenAI), Veo 3.1 (Google), LTX 2.3 (Lightricks), Wan v2.7 (Alibaba)via fal.aiLimited
Image-to-VideoKling v2.1/v2.5/o3, Veo 3.1, LTX 2.3, Sora 2, Wan v2.7via fal.aiLimited
Video Editing / ExtensionKling o3, Veo 3.1, LTX 2.3, Wan v2.7via fal.aiLimited
Video UpscalingSeedVRvia fal.aiMinimal

3.3 Audio Processing

FeatureModels UsedProviderRisk Level
Speech-to-TextWhisper-1 (OpenAI), ElevenLabs Scribe v2OpenAI direct; fal.aiMinimal
Text-to-Speechgpt-4o-mini-tts (OpenAI), ElevenLabs eleven-v3, Qwen-3 TTS, Gemini TTSOpenAI direct; via fal.aiLimited
Music GenerationMinimax Music v2, v2.6via fal.aiLimited

3.4 Text & Content Generation

FeatureModels UsedProviderRisk Level
Script Generationgpt-5.4, gpt-5.4-mini, gpt-5.4-nanoOpenAILimited
Prompt Enhancementgpt-5.4, gpt-5.4-miniOpenAIMinimal
PDF / Document Processinggpt-5.4, gpt-5.4-mini, gpt-5.4-nanoOpenAIMinimal

4. Detailed Risk Assessment

4.1 Limited Risk Systems

The following AI systems are classified as "limited risk" under Article 50 of the EU AI Act (applying from 2 August 2026):

Image, Audio & Video Generation Systems (Article 50(4))

Deployers of AI systems that generate or manipulate image, audio, or video content constituting a "deep fake" must disclose that the content has been artificially generated or manipulated. faktry's image, video, and audio generation features fall under this provision.

Our Compliance:Content published through our public Prompt Gallery — where faktry itself makes AI-generated content available to third parties — carries the European Commission's voluntary transparency label (see 5.4) at first exposure. The AI model used is displayed alongside every result. Our Terms of Service require users to clearly disclose AI-generated content whenever they publish or distribute it themselves (Section 4.2.1). We rely on provenance signals embedded by the underlying AI providers (see 5.3) and do not intentionally strip them during processing.

Text Generation Systems (Article 50(1))

AI systems intended to interact directly with natural persons as conversational interfaces must inform those persons that they are interacting with an AI system. faktry's script and prompt generation features are AI-assisted writing tools, not autonomous chatbots. Users knowingly invoke these features.

Our Compliance: All text generation and prompt enhancement features are explicitly labeled as AI-powered in the interface. Generated output is presented as AI-generated content, not as human-written text.

Emotion Recognition & Biometric Categorization

AI systems performing emotion recognition or biometric categorization must inform natural persons exposed to such systems.

Our Compliance: faktry does not deploy emotion recognition or biometric categorization systems. Our platform does not process biometric data for identification purposes.

4.2 High-Risk Assessment

We have evaluated our AI systems against the high-risk criteria in Annex III of the EU AI Act:

High-Risk Category (Annex III)Assessment
Biometric identification & categorization✓ Not applicable
Critical infrastructure management✓ Not applicable
Education & vocational training✓ Not applicable
Employment, worker management, access to self-employment✓ Not applicable
Access to essential services (credit, insurance, benefits)✓ Not applicable
Law enforcement✓ Not applicable
Migration, asylum, and border control✓ Not applicable
Administration of justice and democratic processes✓ Not applicable

Assessment Result: No High-Risk Systems

Based on our analysis, faktry does not operate AI systems that fall under the high-risk categories defined in Annex III of the EU AI Act. faktry is a creative content generation platform; it does not make consequential decisions affecting individuals' rights, safety, or livelihoods. Users deploying our tools in contexts that may qualify as high-risk are responsible for conducting their own conformity assessment.

4.3 Prohibited Practices

Under Article 5 of the EU AI Act, certain AI practices are prohibited (in force since 2 February 2025). We confirm that faktry does not engage in any of the following prohibited practices:

  • Subliminal or manipulative techniques operating below conscious awareness to distort behaviour
  • Exploitation of vulnerabilities of specific groups (age, disability, social/economic situation) to distort behaviour
  • Social scoring by public authorities or on their behalf
  • Real-time remote biometric identification in publicly accessible spaces
  • Biometric categorization based on sensitive attributes (race, political opinions, religion, sexual orientation)
  • Emotion recognition in workplace and educational institution contexts
  • Indiscriminate scraping of facial images or biometric data from the internet or CCTV footage
  • AI-based predictive policing using individual profiling

5. Transparency Obligations

5.1 AI-Generated Content Disclosure

In preparation for compliance with Article 50 (applying from 2 August 2026), we implement the following transparency measures:

  • Interface Labels: All AI-generated content is clearly labeled as AI-generated within our platform at the point of creation
  • Model Attribution: The specific AI model used to generate content is displayed alongside results
  • Public Gallery Attribution: Content in the Prompt Gallery displays the AI model and provider used for generation
  • API Transparency: API documentation and responses identify the AI system used for each operation

5.2 Deep Fake Disclosure (Article 50(4))

When our AI systems generate or manipulate content that may constitute a "deep fake" — image, audio, or video content that appreciably resembles an existing person, object, place, or event — we require:

  • Clear disclosure within the platform that content has been artificially generated or manipulated
  • Users must accept our Terms of Service, which explicitly require downstream disclosure of AI-generated content that resembles real individuals
  • Our content moderation system actively filters prompts requesting generation of content that could mislead audiences about real individuals

Note: faktry does not apply its own machine-readable watermarking or C2PA signing to exported files. Our underlying AI providers apply their own provenance mechanisms (e.g. SynthID, C2PA manifests) to their outputs where they offer them, and faktry does not intentionally strip that metadata during processing (see Section 5.3).

5.3 Upstream Provider Marking and Provenance (Article 50(2))

Article 50(2) requires that synthetic audio, image, video, or text outputs be marked in a machine-readable format detectable as artificially generated or manipulated. faktry does not apply its own machine-readable watermarking, C2PA signing, or embedded metadata to exported files. Instead, we rely on the marking mechanisms our underlying AI providers apply to their own outputs (for example C2PA content credentials or invisible watermarking, where a given provider offers them).

faktry does not intentionally strip, alter, or degrade this provenance data as part of our processing pipeline. We periodically verify that files retain their upstream provenance signals after passing through our storage and delivery pipeline, and we will disclose here if a specific provider or file format is found not to preserve them.

5.4 Labelling and the European Commission Transparency Labels

The European Commission provides a voluntary set of visual labels ("AI GENERATED" / "AI MODIFIED") to help implement Article 50 disclosure in a consistent, recognizable way. Use of these specific labels is optional; the underlying disclosure duty is not.

AI generatedAI modified

Where faktry itself publishes AI-generated content to third parties — currently, in our public Prompt Gallery — we display the applicable Commission label on the content at first exposure. Elsewhere in the product, results are attributed to the AI model used but are not additionally marked with the Commission label, since the person viewing them is the person who generated them and is already aware the content is AI-produced.

SurfaceDisclosure mechanism
Public Prompt GalleryCommission transparency label displayed on the content itself
In-product generation resultsAI model attribution displayed alongside the result
Exported / downloaded filesUpstream provenance metadata, where applied by the AI provider (Section 5.3)
Publication by usersContractual disclosure obligation, Terms of Service Section 4.2.1

5.5 Copyright and Training Data Transparency

Training data transparency obligations under Article 53(1)(d) apply to GPAI model providers, not to faktry as a deployer. We rely exclusively on third-party AI providers (OpenAI, Black Forest Labs, Google, ElevenLabs, Alibaba, Lightricks, Kuaishou, Minimax) who are responsible for their own compliance with Article 53 training data disclosure requirements. We select providers that commit to EU AI Act compliance and transparency about their model development practices.

6. AI Governance Framework

6.1 Human Oversight

Our platform is designed with human control as the default:

  • No AI outputs are automatically published, acted upon, or forwarded without user review and explicit action
  • Users can reject, modify, or regenerate all AI outputs before use
  • Content flagged by moderation is blocked before generation and logged for human review
  • An admin interface enables human review, override, and audit of AI-related decisions
  • Users can report inappropriate or harmful AI outputs via our support channels

6.2 Data Governance

We implement robust data governance practices:

  • faktry does not develop or train any AI models; all AI capabilities are provided by established third-party providers
  • User content submitted to the platform is processed solely to provide the requested service; it is not used for AI training by faktry
  • We do not share user content with third parties beyond what is necessary to fulfill individual API calls to AI providers
  • Data processing complies with our Privacy Policy and applicable data protection law (GDPR)

6.3 Technical Documentation

We maintain documentation for our integrated AI platform including:

  • System purpose and intended use cases
  • Inventory of AI models and providers in use (as listed in Section 3)
  • Content moderation architecture and policies
  • Risk mitigation measures and human oversight mechanisms
  • Incident logging and response procedures

6.4 Quality Management

Our quality management for AI systems includes:

  • Continuous monitoring of AI provider availability and output quality
  • User feedback integration and issue tracking
  • Version control for moderation policies and prompt filters
  • Regular review of content moderation effectiveness
  • Change management process for adding new AI models or providers

7. Risk Mitigation Measures

7.1 Input Content Moderation (Two-Layer System)

faktry operates a two-layer content moderation system applied to all user-submitted prompts before any generation request is dispatched to an AI provider:

Layer 1 — Local Pattern Matching (real-time, <1 ms)

A rule-based filter checks prompts against curated patterns for sexual content, violence, hate speech, and self-harm content across English, German, and Spanish. High-severity matches (hate speech, self-harm) result in immediate blocking with no further API call. Medium-severity matches are escalated to Layer 2.

Layer 2 — OpenAI Moderation API (borderline cases)

Prompts flagged as medium severity by Layer 1 are evaluated by the OpenAI omni-moderation-latest model. This provides classifier-based scoring across categories including sexual content, hate, harassment, self-harm, and violence. A prompt is blocked if either layer determines it violates policy.

Moderation Audit Logging

All blocked prompts are logged server-side for audit and review purposes. Logs include the endpoint, model, and moderation category triggered. An admin interface enables human review of moderation events and policy adjustments.

Output moderation: For AI-generated outputs, faktry relies on the content policies and output safety systems of upstream AI providers (OpenAI, Black Forest Labs, Google, ElevenLabs, fal.ai, etc.), each of which implements their own output-level safety controls. faktry does not additionally filter generated content files, but users may report outputs via our support channels for human review.

7.2 Prohibited Content Categories

The following content categories are blocked at input and/or output level:

  • Child sexual abuse material (CSAM) — immediate block, zero tolerance
  • Violent or graphic content glorifying harm
  • Hate speech targeting protected characteristics
  • Self-harm and suicide-related prompts
  • Non-consensual intimate imagery
  • Prompts designed to generate disinformation about real identifiable individuals

7.3 Security Measures

Our AI systems are protected against misuse:

  • Input validation and sanitization on all API endpoints
  • Prompt injection protection
  • Rate limiting and quota enforcement per user and API key
  • Secure API key management for all third-party AI providers
  • Authentication required for all AI generation endpoints

8. User Obligations

Users of faktry are responsible for how they use and publish AI-generated content. Under the EU AI Act and applicable law:

  • Transparency: When publishing or distributing AI-generated content, users must clearly disclose its artificial origin, as required by Article 50 of the EU AI Act and by Section 4.2.1 of our Terms of Service (applying from 2 August 2026)
  • Deep Fake Disclosure: Content generated to resemble real persons, places, or events must include clear disclosure that it is AI-generated or AI-manipulated
  • Provenance Preservation: Users must not remove, alter, or obscure AI provenance metadata or watermarks embedded in generated files (Terms of Service Section 4.2)
  • High-Risk Use Cases: Users deploying faktry outputs in contexts that may qualify as high-risk under Annex III must conduct their own conformity assessment independently of faktry
  • Legal Compliance: Users are responsible for ensuring their use of AI-generated content complies with all applicable laws, including copyright, defamation, data protection, and electoral regulation
  • Content Responsibility: Users are responsible for the content they create and its downstream use

9. Third-Party AI Providers

All AI capabilities in faktry are delivered by third-party providers. We select providers that commit to safety, transparency, and regulatory compliance. The following table lists our primary providers and the AI systems accessed:

ProviderAI Systems / Models UsedAccess Method
OpenAIgpt-image-1/1.5/2 (image gen), gpt-5.4 series (text), gpt-4o-mini-tts (TTS), Whisper-1 (STT)Direct API
Black Forest LabsFlux 2 Pro / Max / Flex (image gen + editing), incl. EU-hosted variantsDirect API
fal.ai (aggregator)Kling Video (Kuaishou), Sora 2 (OpenAI), Veo 3.1 (Google/DeepMind), LTX 2.3 (Lightricks), Wan v2.7 (Alibaba), ElevenLabs TTS/STT, Qwen-3 TTS (Alibaba), Gemini TTS (Google), Minimax Music, SeedVRvia fal.ai API

The GPAI-specific obligations under Articles 51–56 of the EU AI Act apply to each model provider listed above. faktry, as a deployer, relies on these providers maintaining their own GPAI compliance documentation and making it available per Article 53.

10. Incident Management

We maintain an incident management system for AI-related issues:

  • Incident Logging: All AI-related incidents are logged and tracked, including moderation overrides and reported outputs
  • Response Procedures: Defined processes for investigating, containing, and resolving AI incidents
  • User Reporting: Users can report harmful or inappropriate AI outputs via our support channels
  • Authority Notification: Serious incidents involving potential harm are escalated and reported to competent authorities as required under applicable law
  • Post-Incident Review: Root cause analysis and policy updates following significant incidents

11. Contact & Compliance

For questions about our EU AI Act compliance, to report AI-related incidents, or to exercise rights related to AI systems:

AI Compliance, Incident Reporting & General Inquiries: [email protected]

12. Updates to This Statement

This statement will be reviewed and updated as:

  • New AI systems or providers are integrated into the platform
  • The EU AI Act application timeline reaches new milestones (next: 2 August 2026)
  • New guidance or implementing acts on the EU AI Act are published by the European AI Office
  • The European Commission updates its Code of Practice on transparent generative AI or its transparency labels
  • Our risk assessment identifies new considerations or obligations

This EU AI Act compliance statement was last updated on July 2026. faktry is committed to ongoing compliance with the EU AI Act and will update this document as regulations evolve and new guidance is issued by the European AI Office.

Related legal documents: Privacy Policy · Terms of Service