Trust Center

EU AI Act

How neuland.ai AG implements the AI Regulation (EU) 2024/1689: roles, risk classification, intended purpose and the obligations of provider and deployer.

The AI Regulation at a glance

Regulation (EU) 2024/1689 on artificial intelligence — the AI Regulation or EU AI Act — entered into force on 1 August 2024 and has applied in stages since then. It does not regulate AI systems across the board but according to the risk of their specific use, and it distributes the obligations across different roles along the value chain.

For you as a customer, one distinction matters most: neuland.ai AG is the provider of the neuland.ai HUB platform, and you are the deployer within your own organisation. Both roles carry different obligations — and both can be met. This page describes what they are, what the neuland.ai HUB is intended for and which applications are expressly excluded.

Allocation of roles

Provider

neuland.ai AG

  • Development and provision of the neuland.ai HUB AI platform under its own name
  • Definition and documentation of the intended purpose pursuant to Art. 3 No. 12 AI Act
  • Technical documentation of the models used and their origin
  • Transparent labelling of AI-generated content in the user interface
  • Provision of the information you need as a deployer to meet your obligations
  • Selection and contractual binding of the model and infrastructure providers used

Deployer

Your organisation

  • Use of the neuland.ai HUB within the intended purpose and the terms of use
  • Ensuring sufficient AI literacy among employees (Art. 4 AI Act)
  • Human oversight of the results — especially before decisions with external effect
  • Informing the persons concerned where required in the specific use case
  • Observing works council participation rights where applicable
  • Checking whether your own use case falls into a higher risk class

If you deploy the neuland.ai HUB under your own name or brand, or substantially modify its intended purpose, you may yourself become a provider under Art. 25 AI Act. Please contact us in that case — we will help you draw the line.

Risk classification

The AI Regulation regulates AI systems according to four risk levels — the higher the risk of the specific use, the stricter the obligations.

Unacceptable risk

Prohibited · Art. 5 AI Act

Practices that violate fundamental rights are entirely prohibited.

e.g. social scoring, emotion recognition in the workplace, manipulative techniques

High risk

Strict requirements · Art. 6, Annex III

Significant risk to health, safety or fundamental rights — permitted only with conformity assessment, risk management and human oversight.

e.g. candidate selection, employee performance evaluation, credit scoring

Classification of the neuland.ai HUB

Limited risk

Transparency obligations · Art. 50 AI Act

AI systems that people interact with or that generate content. Users must be able to recognise that AI is in use.

e.g. AI assistants, AI-generated content

Minimal risk

No specific obligations

All other AI systems — the regulation imposes no additional requirements.

e.g. spam filters, spell checkers

The neuland.ai HUB as a platform: limited risk — not a high-risk AI system

  • The neuland.ai HUB is a general-purpose AI system: a workspace for text processing, research, document analysis and evaluation along the processes defined by the controller.
  • The platform makes no automated decisions about individuals. Results are provided as suggestions; the decision rests with a human.
  • The intended purpose expressly excludes the employment-related applications listed in Annex III No. 4 AI Act — in particular monitoring and evaluating the performance and behaviour of employees. The exclusion is part of the DPA as an annex.
  • There is no biometric identification, no social scoring and no emotion recognition in the workplace — the practices prohibited under Art. 5 AI Act are excluded.
  • What follows for the neuland.ai HUB are the transparency obligations under Art. 50 AI Act: users can tell at all times that they are working with an AI system.

Intended purpose and excluded applications

Whether an AI system qualifies as high-risk depends under the AI Act on what it is “intended to be used for”. What matters is therefore the intended purpose defined by the provider (Art. 3 No. 12 AI Act). neuland.ai defines it as follows — and expressly delimits it.

What the neuland.ai HUB is intended for

Professional support

Support of professional activities: text processing, research, and the analysis and evaluation of documents and data.

Automation of work steps

Automation of recurring work steps within the business processes defined by the controller.

Humans decide

Results are provided exclusively as suggestions — the decision is always made by a human.

Employee data for administration only

Processing of employee data exclusively for the provision and administration of the platform (user accounts, authentication, rights management, security logging) and insofar as employees use the platform in the course of their work and enter content in doing so.

Expressly excluded applications

The following applications are not part of the intended purpose of the neuland.ai HUB. They are neither provided as functionality nor contractually permitted:

Monitoring and evaluating the performance and behaviour of employees

Annex III No. 4 lit. b AI Act

The neuland.ai HUB is not intended to monitor or evaluate the performance or behaviour of employees. Usage and log data are evaluated exclusively for information security, error analysis and proof of system integrity — not for monitoring the performance or conduct of individual employees.

Decisions affecting the terms of employment relationships

Annex III No. 4 lit. b AI Act

No use for decisions on the establishment, terms, remuneration, promotion or termination of employment relationships.

Task allocation based on individual behaviour or personal traits

Annex III No. 4 lit. b AI Act

No allocation or prioritisation of tasks based on the individual behaviour or personal traits or characteristics of employees.

Recruitment and selection of natural persons

Annex III No. 4 lit. a AI Act

No use for targeted job advertisements, for analysing and filtering applications or for evaluating candidates.

Emotion recognition in the workplace

Art. 5(1) lit. f AI Act

The neuland.ai HUB does not recognise or infer emotions of employees. This practice is prohibited under the AI Act and is not technically part of the platform.

Biometric identification, biometric categorisation and social scoring

Art. 5(1) lit. c and g, Annex III No. 1 AI Act

No biometric identification or categorisation of natural persons and no evaluation or classification of persons based on their social behaviour.

Other high-risk areas of Annex III

Annex III No. 2, 3, 5–8 AI Act

No intended use as a safety component of critical infrastructure, in education, for creditworthiness or risk assessment of natural persons, in law enforcement, in migration and asylum matters or in the administration of justice.

Contractually agreed, not merely described

The intended purpose is defined by neuland.ai as the provider (Art. 3 No. 12 AI Act) — it is not an option but part of the product definition. That is why the annex “Intended purpose under the AI Act and exclusion of high-risk applications” is part of the DPA export. The exclusion works contractually in both directions: neuland.ai does not provide the corresponding functionality, and the controller is not permitted to use the platform in such a way.

If the controller modifies the intended purpose in a way that creates a high-risk AI system, the controller is itself deemed a provider under Art. 25(1) lit. c AI Act and bears the associated obligations. Extending the intended purpose requires a separate written agreement — please contact us in advance.

Note on co-determination: since the neuland.ai HUB is not intended to monitor the performance and behaviour of employees, the platform is not a technical device aimed at such monitoring. Whether works council participation rights nevertheless exist in an individual case — for example under section 87(1) No. 6 of the German Works Constitution Act (BetrVG) or under an internal agreement on AI use — depends on the specific implementation within the organisation and is the responsibility of the controller.

Obligations in detail

For each central obligation of the AI Regulation, this section shows what neuland.ai delivers and what remains your responsibility as deployer.

Application dates

The AI Regulation applies in stages. These dates are relevant to the use of the neuland.ai HUB.

1 August 2024

Already applies

Entry into force

The AI Regulation enters into force; the transition periods begin to run.

2 February 2025

Already applies

Prohibited practices and AI literacy

The prohibitions under Art. 5 apply. At the same time, the AI literacy obligation under Art. 4 takes effect for providers and deployers.

2 August 2025

Already applies

Obligations for GPAI models

The obligations for providers of general-purpose AI models and the governance structure of the Member States apply.

2 August 2026

Current

General applicability

The majority of the regulation is applicable — including the transparency obligations under Art. 50 and the obligations for high-risk systems under Annex III.

2 August 2027

Upcoming

High-risk systems in products

The obligations for high-risk AI systems embedded as safety components in regulated products (Annex I) become applicable.

How neuland.ai supports you

Your obligations as deployer cannot be outsourced — the evidence for them can. We provide these building blocks:

  • Intended purpose with exclusion of the high-risk applications of Annex III — part of the DPA as an annex
  • Configurable DPA pursuant to Art. 28 GDPR including TOMs as an annex
  • Public list of subprocessors with location and certifications, always up to date
  • Hosting and model inference optionally on-premise, in German data centres or in the EU — transparent in the platform setup generator
  • Contractual exclusion of the use of your data and content for training AI models
  • Supplementary agreements for professions bound by professional secrecy as an annex to the DPA
  • A contact for questions on classifying your specific use case
Questions about classifying your use case?datenschutz@neuland.ai

Note

This overview summarises the current state of the AI Regulation and describes how neuland.ai deals with it. It does not replace legal advice. For the classification of your specific use case — especially if you are considering a deployment in one of the areas listed in Annex III — we recommend an individual legal review.