EU AI Act Compliance

Last updated: July 17, 2026

Regulation (EU) 2024/1689

Conversify is an AI system provider established in the European Union. As such, the EU Artificial Intelligence Act (the "AI Act") applies to our operations and to the AI systems we place on the market, regardless of where our customers or their end-users are located. This page describes our compliance posture and the measures we have implemented.

1. Risk Classification

Under the AI Act, AI systems are classified into four risk levels: unacceptable, high-risk, limited risk, and minimal risk. Conversify's systems have been assessed as follows:

  • Unacceptable risk (Article 5): Conversify does not engage in any prohibited AI practices. We do not deploy social scoring, real-time biometric identification, untargeted facial scraping, manipulative techniques, or emotion recognition in workplace or education contexts.
  • High-risk (Article 6, Annex III): Conversify's core AI communication system is not classified as high-risk under Annex III. Our emergency keyword detection and escalation feature is a safety routing mechanism, not a medical assessment or decision-making system. It does not evaluate, classify, prioritise, or make clinical assessments. It detects crisis keywords and routes to a human for review. We have documented this assessment pursuant to Article 6(3) and confirmed it with external legal counsel.
  • Limited risk (Article 50): Conversify's AI systems interact directly with natural persons and generate synthetic text and audio content. We are subject to the transparency obligations under Article 50.
  • Minimal risk: Most platform features (appointment booking, CRM, analytics, customer portal) are minimal risk with no specific AI Act obligations beyond voluntary codes of conduct.
  • 2. Transparency Obligations (Article 50)

    We have implemented the following transparency measures required by Article 50:

  • AI interaction disclosure (Article 50(1)): All AI systems that interact directly with natural persons disclose that the user is interacting with an AI system. This disclosure is built into the initial greeting, cannot be disabled by customers, and is sent at the time of first interaction. The greeting explicitly references "AI" or "artificial intelligence" in the user's language.
  • Synthetic content marking (Article 50(2)): All AI-generated outputs (text, voice, and email content) are marked as artificially generated. Text outputs include a visible disclosure footer. Voice responses include an audible AI-generated disclosure. Email outputs include both a visible disclosure and machine-readable metadata headers (X-AI-Generated: true).
  • Emotion recognition (Article 50(3)): Conversify does not deploy biometric emotion recognition systems. Our sentiment analysis operates on text only and is used internally for business analytics, not exposed to the persons being analysed.
  • Deep fakes (Article 50(4)): Conversify does not generate deep fake content.
  • Timing and clarity (Article 50(5)): All disclosures are provided at the latest at the time of first interaction or exposure, in a clear and distinguishable manner.
  • 3. Risk Management

    Although Conversify is not classified as a high-risk AI system, we have implemented the following risk management measures as best practice:

  • High-risk keyword blocking: Our compliance module scans AI inputs and outputs for prohibited content categories (medical diagnosis, financial advice, creditworthiness, insurance underwriting, legal advice, employment decisions) and blocks the AI from engaging with these topics.
  • Safety escalation: Crisis keywords (chest pain, suicide, overdose, etc.) trigger immediate notification to practice staff. The AI does not evaluate, classify, prioritise, or assess medical situations. It sends a standard safety message and alerts a human for review and handling.
  • Human oversight: Every business using Conversify must configure a fallback escalation contact (WhatsApp or email) before the AI can go live. The AI can escalate to human agents at any time.
  • Opt-out management: End-users can opt out of AI interactions at any time using standard keywords (stop, unsubscribe, opt out, etc.) in English and Spanish.
  • Audit logging: All AI interactions, compliance decisions, disclosure deliveries, and opt-out events are logged with timestamps for audit purposes.
  • 4. Data and Privacy

    The AI Act complements existing EU data protection law. Conversify's data practices are governed by:

  • GDPR (Regulation (EU) 2016/679): Full compliance as a data processor/controller. See our Privacy Policy and DPA.
  • Data minimisation: AI training data is limited to business configuration data and conversation context necessary for the system's intended purpose.
  • No profiling: Conversify does not profile natural persons for automated decision-making with legal or similarly significant effects.
  • 5. General-Purpose AI Models

    Conversify integrates general-purpose AI models (Google Gemini) as a downstream provider. We are not a provider of general-purpose AI models under Articles 53-55. Our obligations are to:

  • Follow the instructions for use provided by the GPAI model provider (Google)
  • Report serious incidents to the GPAI model provider
  • Implement appropriate technical and organisational measures when integrating GPAI models into our system
  • 6. Safeguards and Prohibited Uses

    Conversify's Terms of Service explicitly prohibit using the platform for:

  • Medical diagnosis, treatment planning, or clinical decision-making
  • Creditworthiness assessments, lending decisions, or insurance pricing/eligibility
  • Employment decisions (hiring, firing, performance evaluation, workplace discipline)
  • Legal advice or legal representation
  • Any decision that produces legal effects or similarly significantly affects a person without human review
  • These prohibitions are enforced both contractually and technically through our compliance module's keyword scanning and blocking system.

    7. Territorial Scope

    Because Conversify is a provider established in the European Union (Madrid, Spain), the AI Act applies to all AI systems we place on the market, regardless of where our customers or their end-users are located. This includes:

  • EU and EEA member states (direct application)
  • Customers in LATAM, the US, and other regions whose AI outputs may reach EU persons
  • Any future markets where Conversify's output is used
  • 8. Enforcement and Penalties

    As an SME/startup, Conversify is subject to the AI Act's penalty framework with the lower of the percentage or fixed amount applicable. Non-compliance with transparency obligations (Article 50) carries fines of up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is lower for SMEs. We take our compliance obligations seriously and continuously monitor for regulatory updates.

    9. Contact

    For questions about our AI Act compliance, contact legal@conversify.app.

    How Conversify Complies with the EU AI Act | Conversify