Brief Statement on the EU AI Act
• •
TariffPilot GmbH as an operator (deployer) of an AI system using Microsoft Azure OpenAI Services, OpenAI etc.
Role of TariffPilot
- Operator/Deployer under Art. 3(5) AI Act – we deploy an AI system (LLM) in our SaaS platform and make it available to enterprise customers.
- The model providers are Microsoft Azure (OpenAI Services), OpenAI etc. TariffPilot does not develop its own foundation models.
Operator obligations and implementation
| Obligation (Art. AI Act) | Implementation at TariffPilot |
|---|---|
| Transparent use (Art. 28) | Responses are declared to be AI generated |
| Data & system logs (Art. 29) | Logging of all prompts & outputs for 30 days; encrypted storage in the EU. |
| Human oversight (Art. 27) | Customers can manually review model output at any time. |
| Risk management (Art. 9) | Annual risk analysis in line with ISO 23894; register of remedial measures. |
| Cybersecurity (Art. 15) | ISMS. |
Data protection
- Processing as a processor pursuant to Art. 28 GDPR.
- Hosting exclusively in Google Cloud’s EU regions; models run in Azure EU.
- Encrypted storage and transmission of personal data.