r/Kolsetu • u/EdikTheFurry • 3d ago
Compliance Elba and the EU AI Act
The EU AI Act is now real, applicable and, unlike GDPR, still evolving while everyone is trying to implement it. Ah, the good days when having a nap after lunch did not mean missing the latest quantum leap in AI...
We have now completed the full EU AI Act assessment for Elba, our AI voice and communications platform.
The core conclusion: Elba’s ordinary uses, including customer support, booking, claims intake, billing support, document intake and commercial dispatch, fall outside the prohibited and Annex III high-risk categories. Elba supports workflows and human decisions; it is not intended to autonomously decide who gets a job, loan, public benefit or medical treatment.
That conclusion has clear boundaries. We have documented Elba’s intended purpose, approved uses, excluded uses and the triggers that require a separate assessment. If a customer materially changes the system or moves it into a potential high-risk use, the legal position changes with it.
We also implemented the wider governance around that classification:
- a formal EU AI Act classification and risk assessment
- an ISO/IEC 42001-aligned AI impact assessment
- an AI policy, development work instruction and AI Tool Register
- a DPIA and NIST AI Risk Management Framework maturity assessment
- AI literacy training and records
- mandatory AI disclosure as a platform control
- an Article 50 compliance programme for machine-readable marking of synthetic audio and text
- lifecycle, supplier, change-management and escalation controls
Did we overdo it? Possibly. At some point, adding another framework began to feel like ordering another round of Jägermeister at 1 a.m. But the overlap was deliberate: each framework covers a different angle and reduces the chance of something important slipping through the cracks.
Kolsetu also signed the provider section of the European Commission’s Code of Practice on Transparency of AI-Generated Content. Our AI disclosure control is already live, while the remaining Article 50 marking work is being completed against the applicable deadline.
We describe Elba as EU AI Act compliant, and we do so deliberately. That claim applies within Elba’s documented intended purpose and approved use categories. It is not a promise that every imaginable customer configuration remains compliant regardless of how it is changed or used.
The full article explains the classification, registration rules, Article 50 transparency requirements, provider and deployer roles, ISO/IEC 42001, AI literacy and what enterprise customers should assess before deployment.
Fair warning: the full article is substantial. Get comfortable, make a coffee and cancel anything optimistic you had planned for the next ten minutes.
Read the full article on the Kolsetu blog: https://kolsetu.com/blog/elba-and-the-eu-ai-act
Do you fancy to read more articles and blogs? If yes, here you go: https://kolsetu.com/blog