1. Our role under the AI Act
Trusteed acts as a deployer of third-party AI systems - OpenAI and Anthropic models - and complies with the obligations the Regulation places on that status. We are not a general-purpose AI model provider: we do not train, fine-tune, or place GPAI models on the market, so Chapter V does not apply to us.
That description doesn't cover the whole of our role. When we build our own system on top of a third party's model and put it into service under our own name, we also act as a provider of an AI system within the meaning of Art. 3(3) and as a downstream provider under Art. 3(68). This is the case for the conversational shopping assistant and the checkout intent-resolution adapter.
not activeBoth surfaces are deployed but not operational: no LLM provider key is configured in production, so no text directed at buyers is generated today. Once activated, AI disclosure on first interaction (Art. 50(1) and (5)) and machine-readable labeling of generated text (Art. 50(2), with a deadline of December 2, 2026 for systems already on the market as of August 2, 2026) will be required.
2. Obligations applicable today
The timeline reflects the dates in force after the Digital Omnibus, which delayed the high-risk blocks and extended the deadline for synthetic content labeling.
ObligationApplicable fromStatus
Art. 5 - Prohibited practicesFeb 2, 2025compliant
Art. 5 - Non-consensual intimate material and child sexual abuse materialDec 2, 2026under assessment
Art. 4 - AI literacyFeb 2, 2025in progress
Chapter V - GPAI providersAug 2, 2025not applicable
Art. 26 - Obligations of deployers of high-risk AI systemsDec 2, 2027not applicable
Art. 50(1) - Informing about AI interactionAug 2, 2026compliant
Art. 50(2) - Synthetic content labelingDec 2, 2026latent
Arts. 10-25 - High-risk, Annex IIIDec 2, 2027not applicable
High-risk, Annex I (product)Aug 2, 2028not applicable
Art. 71 - EU database registrationHigh-risk onlynot applicable
2a. The two new Art. 5 prohibitions, and why they reach us
The Omnibus added to Art. 5 a prohibition on AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material. This is a deferred obligation: the new Art. 113(3)(a) of the AI Act expressly carves these two prohibitions out of the block otherwise in force since February 2, 2025, and defers them to December 2, 2026.
As a deployer we are outside the scope: the prohibition reaches whoever uses a system for that purpose, which is not our case. Where we do have to look at ourselves is in our capacity as provider of the conversational assistant (see section 1), because the Regulation is not limited to systems intended to generate such material: it also reaches those where such generation is a reasonably foreseeable and reproducible outcome absent reasonable technical measures to prevent it.
under assessmentToday the assistant generates nothing — there is no LLM provider key in production — so there is no possible output to prohibit. We mark this "under assessment" rather than "compliant" because complying by being switched off is not the same as complying: before activating it we must document the safeguards (content filtering, prompt guardrails, misuse detection and a reporting channel), and that assessment is pending. We would rather say so than award ourselves a green that only holds while the system is off.
3. Transparency (Art. 50): what we signal, and where
Transactions initiated by agents are identified through response headers, so the merchant and its systems can distinguish a delegated action from a human one. Coverage is not uniform across surfaces, and we state it as such.
SurfaceHeadersStatus
Agent APIX-Agent-Commerce · X-AI-Act-Transparencyactive
MCP gatewayX-Agent-Commerce · X-AI-Act-Transparencyactive
MCP · Checkout bucketX-Agent-Commerce · X-AI-Act-Transparencyactive
MCP · Discovery bucketpendingrolling out
MCP · Customer bucketpendingrolling out
A2A and outbound webhooksX-Initiated-By: ai-agentactive
The Customer bucket includes cancellations and returns - actions that act on a consumer's contract - so its coverage is a priority.
4. Human oversight
We apply human oversight out of diligence and by contract, not because Art. 26 of the AI Act requires it: that article governs deployers of high-risk systems, and none of our systems is one (see §6). We say so because an earlier version of this page cited it as the basis while simultaneously ruling out high risk, and both cannot be true.
Configuring human-in-the-loop controls is mandatory in the merchant panel. The merchant defines the threshold above which a delegated action requires a human's confirmation before it executes: amount, category, purchase pattern, or origin protocol. If the merchant disables those confirmations, it assumes the risk of actions executed without oversight, as set out in the Terms of Service.
Audit logs are retained for incident investigation and security, and form the basis of the evidence a merchant can provide in a claim.
5. AI literacy (Art. 4)
Art. 4 remains in force after the Digital Omnibus, reformulated as an obligation of means: adopting measures that support developing a sufficient level of AI literacy among staff, not guaranteeing a result. Its national oversight has been operational since August 2026.
We maintain an internal AI literacy policy and a dated record of training given to staff with access to AI systems, available on request to a competent authority.
6. Trust Score risk classification
The merchant Trust Score is a limited-risk system. It does not fall under Annex III: it does not assess the creditworthiness of natural persons, and it does not intervene in employment, education, essential services, or the administration of justice. It applies a deterministic, fixed-weight algorithm over operational metrics; it does not learn or infer profiles.
It does produce automated effects on a merchant's visibility in the agentic channel. The status ladder, the thresholds, and the right of appeal with human review are detailed in the Privacy Policy, since the applicable legal basis is Art. 22 GDPR and not the AI Act's high-risk regime.
7. Disclosure in your store
The data processing agreement (Art. 28 GDPR) is incorporated into the Terms of Service and is accepted on registration: there is no separate signature pending. On the technical side, what we provide is the identification of agent-initiated transactions through response headers, with the per-surface coverage published in section 3.
Informing the buyer on the merchant's own storefront is the merchant's responsibility, and we do not currently ship a drop-in badge that covers it. We would rather say so than have anyone assume their obligation is settled by ours.
8. Oversight and penalty regime
The Regulation is directly applicable with or without national law. In Spain, AESIA will be the market surveillance authority for AI and will exercise sanctioning power once the organic law designating it enters into force; the planned allocation of competencies places the AEPD over biometric data, the CGPJ over the judicial domain, and the Bank of Spain and the CNMV over the financial domain. The penalty range the Regulation provides for reaches €35 million or 7% of global annual turnover, depending on the infringement.
The draft Organic Law on the good use and governance of artificial intelligence was approved by Spain's Council of Ministers on May 26, 2026 and remains in parliamentary process, so it may still change.
Being subject to the AI Act framework describes the applicable regime; it does not imply any individual review, oversight, or certification of Trusteed by AESIA.