Skip to main content

How Easygenerator complies with the EU AI Act

Learn how Easygenerator meets EU AI Act obligations as provider of our AI features: EasyAI, EasyCoach, EasyVideo. Including risk classification, human oversight, and AI-content transparency labeling.

Written by Veronica

Easygenerator is the provider, under the EU AI Act, of the AI features we build and ship under our own name (EasyAI, EasyCoach, EasyVideo, and more). Our AI features support human decision-making — they don't replace it. We don't train third-party models on your data, we don't use AI to profile or emotionally analyze people, and every AI-generated output stays subject to human review before it reaches a learner.

1. Our approach to AI governance

  • A cross-functional AI governance team (security, engineering, legal, and privacy) reviews new AI features, model changes, and sub-processors before they ship.

  • Our internal AI Policy and supporting procedures are aligned with ISO/IEC 42001, the international standard for AI management systems, and are integrated with our existing ISO 27001-certified information security program.

  • Every new AI capability goes through a documented impact assessment covering risk classification, data protection, fairness, and human oversight before release.

  • We maintain an incident-reporting process for AI-related concerns, available to employees and customers alike.

2. Where our AI features sit under the Act

The Act builds around two main roles. A provider develops an AI system (or has one developed) and places it on the market or puts it into service under its own name. A deployer uses an AI system in a professional context.

Our model vendors — OpenAI, Mistral AI, Microsoft Azure — are the providers of the underlying general-purpose AI models. Easygenerator builds specific, named AI features on top of those models — EasyAI, EasyCoach, EasyVideo, and our translation add-on — and places them on the market under the Easygenerator name. For those features, Easygenerator is the provider. Your organization, using them as part of your training operations, is the deployer.

EasyAI — course-creation assistant

  • Purpose: helps authors brainstorm, draft, and structure course content.

  • Risk tier: limited/minimal risk. As the provider, we've assessed the intended use — assisting content creation — and it does not fall within the Act's high-risk (Annex III) categories.

  • Human oversight: authors review and approve all AI-generated content before it is published to learners; nothing is published automatically.

  • Data handling: your inputs are not used to train the underlying models. OpenAI processes prompts under an Enterprise API agreement with model training disabled by default.

EasyCoach — AI roleplay practice and feedback

  • Purpose: gives learners a safe space to practice conversations (e.g. sales or service scenarios) and receive structured, formative feedback.

  • Risk Tier: limited/minimal risk. As the provider, we've assessed the intended use — purely educational roleplay creation — and it does not fall within the Act's high-risk (Annex III) categories.

  • Design principle: feedback is practice-oriented, not an assessment of record. It's scored against the scenario's author-defined criteria, one attempt at a time — there's no persistent scoring, ranking, or profile built up about an individual across sessions.

  • No emotion inference: EasyCoach does not infer or score a learner's emotional state. The Act prohibits this kind of emotion recognition in the workplace and in education, and we don't build it.

  • Human oversight: results are recommendations, not automated decisions. We ask customers not to use EasyCoach output as the sole basis for hiring, promotion, pay, discipline, or certification decisions.

EasyVideo, Automated Translation, and other add-ons

  • These add-on features (video generation, translation, text-to-speech) use third-party AI services under the same governance program: human review of outputs, data-minimization guidance, and sub-processor due diligence.

  • They are content-generation tools, not systems that make or influence decisions about people, and sit in the same limited-risk category as EasyAI.

3. Changing how a feature is used

Our provider assessment covers each feature's intended use, as documented in our instructions for use. If your organization uses a feature beyond that intended purpose — for example, using AI feedback as the sole, determinative basis for an employment decision — you may take on provider obligations of your own for that modified use, in addition to your responsibilities as deployer.

Please talk to your legal/compliance team about your specific use case, and to us about configuring or disabling the feature accordingly.

4. What being the provider means we do

  • Maintaining technical documentation and a risk-management process for each AI feature we ship.

  • Publishing clear instructions for use, including intended purpose and any limitations.

  • Carrying out and documenting the Article 6 risk-classification assessment for any feature that touches an Annex III use case (like EasyCoach), before it goes to market.

  • Monitoring how features perform after release and maintaining an incident-reporting process for AI-related issues.

  • Meeting Article 50 transparency duties (see below) at the product level, so you don't have to build that labeling yourself.

5. Transparency — you'll always know it's AI

  • Learners interacting with an AI-driven feature (like EasyCoach roleplay) are told they're interacting with AI, in line with Article 50 of the Act.

  • AI-generated images (created via OpenAI, Microsoft Azure, and Google Cloud models) carry embedded Content Credentials (the C2PA provenance standard) — machine-readable metadata that lets an image be verified as AI-generated wherever that metadata is preserved.

  • AI-generated voice (via ElevenLabs, used in EasyCoach and voice features) is watermarked using SynthID across all generated audio; downloaded audio additionally carries C2PA provenance metadata.

  • We're extending the same machine-readable labelling approach to AI-generated video as our video sub-processors roll out equivalent content-credential support.

6. Data protection, alongside AI compliance

Our AI Act program runs alongside our GDPR compliance:

  • Data Protection Impact Assessments are carried out for AI features that process personal data.

  • Every AI-related sub-processor is vetted, listed publicly, and bound by Standard Contractual Clauses where data leaves the EU (full list at trust.easygenerator.com/subprocessors).

  • We practice data minimization by design — for example, guiding customers to avoid submitting unnecessary personal data into translation or content-generation prompts.

  • Human-in-the-loop review and periodic fairness checks help guard against bias in AI-assisted outputs.

7. Staying current

The EU AI Act is being phased in over several years, and parts of it (including some high-risk obligations) have had their timelines adjusted by the EU's “Digital Omnibus” process. We track these changes and update our AI governance program — and this document — as the regulatory picture develops.

8. Roles summarized

Layer

Role & responsibility

General-purpose AI model

Provided by our model vendors (e.g. OpenAI, Mistral AI, Microsoft Azure), who carry provider obligations for the underlying model itself.

Easygenerator AI features

Easygenerator is the provider of each named feature (EasyAI, EasyCoach, EasyVideo, etc.) — we build it, classify its risk, document it, and carry the associated provider obligations under the Act.

Your organization

As the customer, you are the deployer: you use these features within your own processes, following our instructions for use. If you use a feature beyond its documented intended purpose — especially for consequential decisions about people — you may take on additional obligations of your own for that use.

9. Learn more

For questions specific to your organization's use case — including deployer obligations for high-risk scenarios — please contact your account manager or reach us at [email protected].

This information is provided for general knowledge and does not constitute legal advice. Please consult your own legal counsel to assess your organization's specific obligations under the EU AI Act.

Did this answer your question?