Brief Statement on the EU AI Act
• •
LoyJoy GmbH as an operator (deployer) of an AI system using Microsoft Azure OpenAI Services, Mistral, Scaleway or Anthropic
Role of LoyJoy
- Operator/Deployer under Art. 3(5) AI Act – we deploy an AI system (LLM) in our SaaS platform and make it available to enterprise customers.
- The model provider is Microsoft Azure (OpenAI Services), Mistral AI, Scaleway SAS, or Anthropic PBC. LoyJoy does not develop its own foundation models.
Operator obligations and implementation
| Obligation (Art. AI Act) | Implementation at LoyJoy |
|---|---|
| Transparent use (Art. 28) | AI-generated responses are labeled “AI”. |
| Data & system logs (Art. 29) | Logging of all prompts & outputs for 30 days; encrypted storage in the EU. |
| Human oversight (Art. 27) | Customers can manually review any response at any time; optional live-chat takeover. |
| Risk management (Art. 9) | Annual risk analysis in line with ISO 23894; register of remedial measures. |
| Cybersecurity (Art. 15) | ISMS, regular penetration tests. |
Data protection
- Processing as a processor pursuant to Art. 28 GDPR.
- Hosting exclusively in Google Cloud’s EU regions; models run in Azure EU.
- Encrypted storage and transmission of personal data.