> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/certifications/ai-act.md).

# AI Act

Why AIsuru complies with Regulation (EU) 2024/1689 and which documents attest to it

### What it is

Regulation (EU) 2024/1689, known as the AI Act, is the world's first comprehensive regulatory framework on artificial intelligence. It introduces a system for classifying AI systems by risk level — minimal, limited, high and unacceptable — and defines proportionate obligations for developers, providers and deployers.

> **Memori's self-assessment:** Memori s.r.l. has carried out an in-depth self-assessment of the AIsuru platform against the obligations of Regulation (EU) 2024/1689 (AI Act). The analysis shows that AIsuru — in its proprietary NLP component and in the conversational system — is well below all the relevant thresholds for designation as a systemic-risk GPAI. The system is classified as low-risk AI for standard use cases, with transparency obligations already fully implemented.

### AI system classification

The classification of the system varies depending on the context of use:

* **Limited risk (standard case):** AIsuru used as a virtual assistant, customer support, corporate knowledge base or training tool falls into the limited-risk category, with transparency obligations towards the end user already implemented in the platform
* **High risk (deployer responsibility):** AIsuru can be configured by the customer in regulated contexts (personnel selection, credit scoring, medical diagnostics, etc.) that fall under Annex III of the AI Act. In this case the responsibility for assessment and compliance lies with the customer in its capacity as deployer
* **Systemic risk analysis — MemoriNLP:** MemoriNLP does not exceed any of the quantitative or qualitative thresholds set by Art. 51 of the AI Act for designation as a systemic-risk GPAI. The system is well below the thresholds set by the regulation in terms of computational capacity, market impact and number of users. Supporting technical documentation is available on request to qualified parties (auditors, supervisory authorities).

### Documents supporting compliance

* **Internal technical documentation:** available on request at <privacy@memori.ai>
* **Public documentation:** the description of Memori's proprietary NLP system is available in the dedicated section of this trust center

**AI Act responsibility by delivery model** The distribution of responsibilities between Memori and the customer varies depending on the chosen contractual model:

| Model          | Memori responsibility                                                 | Customer responsibility                                                        |
| -------------- | --------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
| **SaaS**       | Platform compliance, transparency towards users, provider obligations | Use in line with the intended purpose                                          |
| **PaaS**       | Platform compliance, configuration support                            | Agent configuration, user management, compliance as deployer                   |
| **On-Premise** | Supply of compliant software                                          | Installation, configuration, operational management and compliance as deployer |

In all delivery models, data entered into the platform (Agent content, conversations, uploaded files) remains the exclusive property of the customer. Memori does not collect any data to train, modify or improve its own models. Data is used exclusively to provide the contracted service.
