Skip to content
PokutsoftPokutsoft

EU AI Act Compliance Statement

Updated: 2026-07-23

Regulation (EU) 2024/1689

Pokutsoft has reviewed its application catalog against the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). This statement explains our role, which of our applications fall within the Act, and the measures we have put in place. It is provided for transparency and does not constitute legal advice.

Our role and the BYOK model

We are a provider of business application software. Where our applications use large language models, they operate on a Bring-Your-Own-Key (BYOK) basis: the customer supplies and controls their own model credentials (for example OpenAI or Anthropic). We do not train or supply general-purpose AI models, so the Act's obligations for providers of general-purpose AI (GPAI) do not apply to us. Obligations that attach to the AI functionality within our applications are addressed as described below.

Scope

The AI Act applies only to AI systems. The majority of our catalog is conventional business software driven by deterministic logic (accounting, payroll, logistics, point of sale, e-invoicing and similar) and is outside the scope of the Act. A defined subset of our applications performs genuine AI inference; the measures below apply to that subset.

Transparency (Article 50)

Our AI-bearing applications implement the following transparency measures:

  • AI-interaction disclosure. Where an application replies to a person using an AI model (for example automated customer messaging), the recipient is informed that the reply is generated by an AI assistant.
  • AI-generated content marking. Content produced by AI — such as product descriptions, fields extracted from documents, and generated dashboards or insights — is labelled as AI-generated, with a prompt to review it before it is used or published.
  • Human review retained. AI output that feeds business records (for example extracted invoice data) is created as a draft and requires human confirmation before it takes effect.

Human oversight (Article 14)

Where an application could influence work-related task allocation, the AI operates in a suggestion mode by default: it proposes an outcome and a human must approve it before any action is taken. Automatic action remains available only as an explicit, opt-in configuration.

High-risk systems (Annex III)

Any application that would qualify as high-risk under Annex III (for example a system that evaluates or ranks candidates for recruitment) is either withdrawn from the EU market or placed on a dedicated conformity roadmap ahead of the applicable date. Following the Digital Omnibus simplification package (final Council approval on 29 June 2026), the application date for Annex III high-risk obligations is 2 December 2027.

Applicable dates (post Digital Omnibus)

DateObligation
2 Aug 2026Article 50 transparency disclosures (chatbot notice, AI-content labelling, deepfake labelling).
2 Dec 2026Article 50(2) machine-readable marking for generative AI already on the market before 2 August 2026 (four-month transition).
2 Dec 2027Annex III high-risk obligations (deferred from 2 August 2026).

Data protection

Where an AI feature processes personal data, this occurs under the customer's control and their responsibilities under the GDPR. Depending on the use case, a Data Protection Impact Assessment (DPIA) may be required. Because our applications use the customer's own model credentials, the customer determines which third-party model provider processes their data.

Contact

Questions about this statement or the AI functionality in a specific application: support@pokutsoft.com

This statement is provided for transparency and does not constitute legal advice. Final classification and compliance for a specific deployment should be confirmed with qualified counsel.