EU AI ACT - Compliance statement
Version 1.0 — Last updated: 01/06/2026
1. Purpose and scope
This Statement describes the position of IAMONES S.r.l. ("IAMONES", "we") with respect to Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (the "AI Act"), as it applies to the IAMONES Conversational Identity platform (the "Platform").
It sets out the regulatory role assumed by IAMONES, the risk classification of the Platform's functionalities, and the technical and organisational measures implemented to meet the applicable obligations.
This Statement is provided for information purposes and does not constitute legal advice. It does not form part of any contract between IAMONES and its customers, and does not modify the terms of any agreement in force. It should be read together with the IAMONES Privacy Policy and the applicable service documentation.
2. Regulatory framework
The AI Act classifies AI systems into four categories, with obligations increasing in proportion to risk: prohibited, high-risk, limited-risk and minimal-risk. It applies to providers (persons developing and placing AI systems on the market), deployers (persons using AI systems under their authority), and to importers and distributors.
The AI Act further establishes specific requirements concerning transparency, human oversight, data governance, and conformity assessment procedures for high-risk systems.
4. Regulatory role of IAMONES
In respect of the Platform, IAMONES generally acts as a deployer of AI systems within the meaning of the AI Act, in that it uses, rather than develops, the AI components integrated into its services. Its principal obligations accordingly arise under Article 26 and Article 50 of the AI Act.
5. Characteristics relevant to risk classification
The following characteristics of the Platform are material to its classification under the AI Act:
- The Platform does not use biometric data, does not perform behavioural analysis.
- The Platform performs no automatic learning from user actions.
- The reasoning engines operate purely on inference and are not machine learning systems trained on collected customer data.
6. Technical and organisational measures
- Data minimisation. Personally Identifiable Information, including names, email addresses and job titles, is programmatically stripped from all input prior to any interaction with an LLM.
- Separation of reasoning tasks. Reasoning tasks are distributed across distinct LLM providers for each user interaction-
- Visibility policies expressed in natural language are translated into Row-Level Security rules enforced at the database layer.
- Input control. A dedicated LLM Firewall intercepts all input queries and blocks code injection, prompt injection, privilege escalation attempts, unsafe queries and content violating semantic policies. Queries falling outside the IGA domain are automatically blocked. Only pre-approved prompts are routed to the reasoning agents.
- Statelessness. The Platform is session-based and stateless at the LLM interaction level. No inputs or outputs are retained within the inference layer.
- Human oversight. Outputs of the AI components are strictly advisory and are never executed automatically within customer systems.
- Logging and auditability. Each user action, AI query and model response is logged with contextual metadata, including timestamp, user identifier and purpose.
- Tenant segregation and resource control. Each customer is assigned a dedicated TIG.
- Data residency. Third-party LLMs are accessed via API with data residency within the European Union and without reuse of data for model training.
- Security validation. Periodic Vulnerability Assessment and Penetration Testing campaigns are conducted, addressing OWASP-listed threats relevant to the generative AI domain, including prompt injection and data exfiltration scenarios.
7. Conclusion
On the basis of its current architecture, security controls and operational safeguards, IAMONES considers the Platform to present a low-to-limited risk profile under the AI Act in respect of its core functionalities. Adherence to Personally Identifiable Information stripping, European Union data residency options, human oversight mechanisms and role-based access controls substantially mitigates regulatory exposure for IAMONES and for its customers.
8. Amendments to this Statement
IAMONES keeps this Statement under review and may amend it to reflect changes to the Platform.
9. Further information
The full IAMONES white paper "IAMONES and the EU AI Act - Positioning, Risk Profile and Compliance Assessment", which sets out the complete mapping of the Platform against AI Act requirements, may be requested using the button below.
This website uses cookies. Please refer to the Privacy & Cookie policy for more details.
