Built for the Act, not around it.
Model cards, transparency templates and prohibited-use enforcement — surfaced in the catalog and enforced at the router edge.
GPAI transparency template
Every model in the catalog carries an auto-populated GPAI template: training-data summary, energy footprint estimate, evaluation results, known limitations.
Systemic-risk flags
Models above the 10^25 FLOP threshold are flagged in the catalog with the additional obligations that apply to deployers.
Per-request risk tier
Tag a request with X-LLMCloud-AI-Risk-Tier: high|limited|minimal — the audit log carries the tier so downstream reporting is auditable.
Prohibited-use enforcement
Policies can block requests matching the Act's Article 5 prohibitions. Attempts are logged and returned as 451 Unavailable For Legal Reasons.
Content marking
Optional invisible watermark on generated text/image outputs to help downstream deployers comply with Article 50 disclosure duties.
Downstream-provider info
The technical documentation you need as a downstream provider is exportable from the trust portal per model, per version.
Article 5 — prohibited practices we enforce
- Subliminal, manipulative or deceptive techniques causing significant harm
- Exploitation of vulnerabilities of specific groups
- Social scoring by public authorities causing detrimental treatment
- Predictive policing based solely on profiling
- Untargeted scraping of facial images to build biometric databases
- Emotion recognition in workplaces and educational institutions
- Biometric categorization inferring race, political opinions, union membership, religion, sex life
- Real-time remote biometric identification in public spaces for law enforcement (narrow exceptions)
Are you a provider or deployer under the Act?+
Both, depending on the flow. When we host and route a model we act as a downstream provider; when a customer uses our platform to serve their own end users, they are the deployer and we are the infrastructure provider. Responsibilities are laid out in the DPA.
How do you handle Article 50 disclosure duties?+
For synthetic content, we support machine-readable marking on generated outputs. Deployer-facing UI disclosures remain your responsibility.
When do the obligations apply to us?+
Prohibited practices apply from Feb 2025. GPAI obligations from Aug 2025. High-risk AI-system obligations from Aug 2026. We're tracking each milestone and updating this page.