PRE-DEPLOYMENT ETHICS REVIEW GDPR COMPLIANT EU AI ACT ALIGNED 100% EUROPEAN INFRASTRUCTURE
EU AI Act 2024 GDPR Compliant Pre-Deployment Phase 100% European Infrastructure
Legal · Regulatory Compliance

EU AI Act Compliance

ANBORELA is designed in full alignment with the EU Artificial Intelligence Act (Regulation EU 2024/1689). This document details our risk classification, applicable obligations, and the architectural decisions that ensure compliance from the first line of code.

Regulation EU AI Act · Regulation (EU) 2024/1689
System status Pre-deployment · Under ethics review
Last updated May 2026
01

What Is the EU AI Act and Why It Applies

The EU Artificial Intelligence Act (Regulation EU 2024/1689) is the world's first comprehensive legal framework for artificial intelligence systems. It entered into force in August 2024 and establishes a risk-based classification system that determines the obligations applicable to each AI system based on its potential impact on people's rights and safety.

ANBORELA is a conversational AI system designed to provide non-clinical behavioural support in the context of addiction recovery. Because it operates in a domain adjacent to health and interacts with potentially vulnerable users, the EU AI Act is directly applicable to its design, deployment, and governance.

ANBORELA's compliance with the EU AI Act is not reactive — it was built into the system's architecture from the outset.

02

Risk Classification

The EU AI Act classifies AI systems into four risk categories: unacceptable risk (prohibited), high risk, limited risk, and minimal risk. ANBORELA's classification is determined by its scope, its non-clinical design boundaries, and its pre-deployment ethics-first approach.

Classification Limited Risk category · EU AI Act Annex III analysis

ANBORELA does not make clinical diagnoses, autonomous treatment decisions, or medical recommendations. It is a non-clinical conversational support tool. It does not fall under Annex III high-risk categories because it explicitly excludes itself from clinical decision-making by architectural design. However, given its health-adjacent context and interaction with vulnerable populations, ANBORELA voluntarily applies high-risk obligations as a matter of ethical best practice.

03

Applicable Articles and How We Comply

Although ANBORELA is classified as limited risk, we voluntarily apply the obligations set out in the following articles of the EU AI Act as a founding commitment to institutional trust and user safety.

Art. 9 Risk management system · A documented risk management process is maintained throughout the system lifecycle — covering identification, analysis, evaluation, and mitigation of risks. Updated continuously as the system evolves.
Art. 10 Data governance · Training data is drawn exclusively from public linguistic corpora, academic sources, and synthetic dialogue examples. No personal medical records are used. Data practices are fully documented and auditable.
Art. 11 Technical documentation · Full technical documentation of the system architecture, training methodology, safety constraints, and performance evaluation is maintained and available to approved institutional partners on request.
Art. 13 Transparency and provision of information · Users are always informed they are interacting with an AI system. The system's non-clinical nature, limitations, and emergency referral pathways are disclosed at every interaction without exception.
Art. 14 Human oversight · Human oversight is maintained at all stages of the research programme. No autonomous clinical decisions are made. Academic and regulatory partners may request full model behaviour audits at any time.
Art. 17 Quality management system · Documented procedures for monitoring, incident reporting, corrective action, and system updates are in place. The system does not update autonomously without human review.
Art. 50 Transparency obligations for GPAI-adjacent systems · ANBORELA discloses the nature of the AI system clearly to all users. No synthetic content is presented as human-generated. No deceptive design patterns are used.
04

Prohibited Practices — What ANBORELA Never Does

Title II of the EU AI Act prohibits certain AI practices absolutely. ANBORELA's architecture excludes all of them by design.

No subliminal manipulation The system does not use techniques that operate below the threshold of consciousness to influence user behaviour. All interactions are transparent, voluntary, and stoppable at any moment.
No exploitation of vulnerability The system does not exploit the specific vulnerabilities of people in addiction recovery. Its design is oriented toward autonomy and referral to professional care, not dependency on the AI.
No social scoring ANBORELA does not evaluate, rank or classify users based on their behaviour, social conduct, or personal characteristics. No user profiles are created or retained.
No real-time biometric identification The system operates exclusively through text. No biometric data — voice, facial recognition or otherwise — is collected, processed or analysed under any circumstances.
05

Independence from Big Tech as a Compliance Advantage

Architectural decision

Why not using AWS, Azure or Google Cloud matters for EU AI Act compliance

Many EU AI Act obligations — particularly around data governance (Art. 10), transparency (Art. 13), and human oversight (Art. 14) — become significantly harder to fulfil when the underlying infrastructure is controlled by a non-EU third party. ANBORELA runs entirely on European infrastructure, governed exclusively by EU law. There are no contractual barriers to institutional audit, no data transfers outside the EEA, and no dependency on a provider whose terms of service could override our compliance obligations.

The conversational model is built and controlled by Anborela OÜ — it is not licensed from OpenAI, Anthropic, Meta or any US-based AI provider. This ensures that the full technical documentation required by Art. 11 is available without restriction, and that model behaviour audits (Art. 14) can be granted to approved institutional partners without third-party constraints.

06

GPAI — General Purpose AI Considerations

Title VIII of the EU AI Act introduces specific obligations for providers of General Purpose AI (GPAI) models. ANBORELA is a purpose-specific system — not a general-purpose AI — designed exclusively for non-clinical behavioural recovery support. Accordingly, GPAI obligations do not directly apply.

However, ANBORELA voluntarily applies the transparency and documentation standards recommended for GPAI systems, given the sensitivity of its operational domain and its interaction with vulnerable populations. This includes maintaining a public-facing description of the system's capabilities, limitations, and safety constraints.

07

Ongoing Compliance and Institutional Audit

EU AI Act compliance is not a one-time certification — it is an ongoing process. ANBORELA maintains the following mechanisms to ensure continuous compliance throughout the system's lifecycle.

Monitoring Continuous monitoring of system behaviour against defined safety constraints. Any deviation triggers human review before the system continues operating.
Audit access Approved academic and regulatory partners may request full architecture review, model documentation, training data documentation, and interaction log analysis at any time.
Incident log A documented incident log is maintained for any interaction that triggers safety protocols. Logs are reviewed by the responsible person and used to improve system constraints.
Regulatory contact Francisco Moreno · ai@anborela.ee · Anborela OÜ · Pärnu mnt 139c, Tallinn, Estonia. Available for regulatory enquiries from national AI supervisory authorities.

Full technical documentation and architecture review available to approved institutional partners on request.

Anborela OÜ · Registration 14746683 · Estonia · Regulation (EU) 2024/1689 · GDPR (EU) 2016/679
EU AI Act Compliance v1.0 · May 2026 · Subject to revision as regulatory guidance evolves