• About
  • Pricing
  • Ready team blueprintsStart from a proven business outcome, then match real specialists.
  • Partnership
  • Signals
  • Insights
  • Login →Create account +Client Office →Team Studio →Pro Workspace →
    My account Upgrade $Support Sign out ×
Main/
InsightsArticles & newsSignalsPeople & project graphPartnershipCollaborate with usAboutWhat is Collty?PricingPlans and capacity
Login →Create account +Client Office →Team Studio →Pro Workspace →My account Upgrade $Support Sign out ×
PrivacyTermsCookiesGDPREU AI Act
Responsible AI governance

EU AI Act Compliance

This page describes how Collty governs AI-assisted team assembly, project planning, collaboration intelligence and agents across their lifecycle, including classification, data governance, human control, transparency, evaluation and monitoring.

Framework

Regulation (EU) 2024/1689

Control status

Technical governance implemented and evolving

Classification

Per-system conservative legal assessment

Updated

July 29, 2026

01

System-by-system governance

Each AI capability has a versioned intended purpose, owner, provider/deployer role assessment, risk classification and review date.

02

Evidence before activation

Private evals, domain graders, provenance, holdout testing, canary controls and human approval gate changes to ranking behavior.

03

People retain the decision

Collty recommends project-team options and explains supporting professional evidence. Users review profiles and make the final team and project decisions.

Contents
  • 1. Governance position
  • 2. Prohibited uses and product boundaries
  • 3. Current application timeline
  • 4. AI system inventory and classification
  • 5. Data governance and minimization
  • 6. Quality, evaluation and controlled learning
  • 7. Human control and user transparency
  • 8. Risk management and technical controls
  • 9. Post-market monitoring and incidents
  • 10. Documentation and quality management
  • 11. AI literacy
  • 12. Status and limitations

Alignment describes Collty's engineering and operating controls. It is not an official conformity assessment, CE marking, regulator approval or legal classification. Final obligations depend on each system's intended purpose, deployment and applicable dates.

Explore Intelligence CoreRead TermsEuropean Commission AI Act
01

Governance position

Collty treats itself as the provider of its proprietary AI-assisted product systems and evaluates customer roles as deployer roles where applicable. External foundation-model and embedding providers are replaceable processing components; Collty retains product purpose, evidence selection, permissions, domain logic, evaluation, provenance and action controls.

Team recommendations are intended to help users assemble project teams from professional evidence, not to make employment, dismissal, worker-management, credit, insurance, education, law-enforcement or public-benefit decisions. Intended-use restrictions do not eliminate the need to assess actual use and foreseeable misuse.

02

Prohibited uses and product boundaries

Collty is not designed, offered or permitted for AI practices prohibited by the EU AI Act. Collty does not provide biometric identification or categorisation, facial-image scraping, emotion recognition, social scoring or criminal-risk prediction capabilities.

  • Do not use Collty to manipulate or deceive a person, exploit age, disability or social or economic vulnerability, or materially impair a person's ability to make an informed decision in a way likely to cause significant harm.
  • Do not use Collty to create social scores or to make unrelated detrimental decisions based on inferred personality, social behaviour or protected characteristics.
  • Do not use Collty to infer race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation from biometric or behavioural data.
  • Do not repurpose professional recommendations as automatic employment, dismissal, worker-management, credit, insurance, education, law-enforcement, migration or public-benefit decisions.
  • Do not bypass human review, profile inspection, permission boundaries or recorded approval controls where a decision can materially affect a person.

Actual use and reasonably foreseeable misuse remain part of each system's documented risk review. Collty may restrict, suspend or investigate use outside these product boundaries.

03

Current application timeline

Collty tracks the application dates published by the European Commission and records the applicable date in each system assessment. The current timeline reflects the AI Omnibus that entered into force in July 2026 and may be updated if the legal framework changes.

Application dateRelevant rules
2 February 2025Prohibited AI practices and the applicable definitions entered into application.
2 August 2025Governance rules and obligations for providers of general-purpose AI models entered into application; Collty separately assesses its role and the role of external model providers.
2 August 2026The AI Act becomes generally applicable and Article 50 transparency obligations apply to covered AI interactions and generated or manipulated content.
2 December 2027High-risk requirements apply to systems in the sensitive areas covered by Annex III under the current AI Omnibus timeline.
2 August 2028High-risk requirements apply to AI systems embedded in regulated products covered by Annex I.

A date in this table does not classify every Collty feature into that category. Classification and resulting obligations are assessed per system, intended purpose, deployment context and foreseeable use.

04

AI system inventory and classification

The protected versioned inventory records the intended purpose, owner, provider and deployer role assessment, model categories, input and output categories, people affected, human-oversight requirement, Article 50 transparency requirement, risk class, assessment state and review date for each system.

System areaGovernance focus
Team AssemblyCapability relevance, verified evidence, team composition, ranking bias, exclusions and final human selection.
SignalsApplicant evidence, project fit, client approval and safe use of general-database candidates when response coverage is insufficient.
Team IntelligenceCompetence, role balance, availability, collaboration evidence, confidence and non-public data boundaries.
Project ArchitectGrounded phases, tasks, roles, dependencies, duration, commercial consistency and absence of invented specialists.
Project Advisor and agentsProject evidence, permitted actions, approval gates, mutation provenance, rollback and monitoring.
Smart Console and generative interfacesClear AI interaction notice, source grounding, permissions and user review.

Features that may affect access to professional opportunities remain in conservative assessment scope. The recorded classification can be changed only through a new version with documented rationale.

05

Data governance and minimization

  • The system uses professional competencies, services, experience, role evidence, availability, capacity, permitted collaboration signals, project outcomes and user feedback relevant to the requested task.
  • Private context is minimized, structurally filtered and permission-scoped before an external model call.
  • Protected characteristics are outside the intended ranking contract; proxy discrimination and unsupported evidence are assessed as risks.
  • Vector retrieval identifies semantically relevant evidence; domain algorithms validate capability coverage, role fit, availability, compatibility and constraints.
  • Models interpret and synthesize bounded evidence. They do not receive unrestricted database access or authority to invent people, roles or evidence.
  • Evidence IDs and provenance connect an output to the records and algorithm version that supported it.
06

Quality, evaluation and controlled learning

Collty uses versioned private evaluation datasets and task-specific graders. Team Assembly evaluation measures request relevance, mandatory capability coverage, unsupported or unsuitable specialists, invented roles or evidence, role allocation, availability, capacity, collaboration compatibility, stability, human rating and project outcomes.

Project Architect evaluation measures phase and task completeness, dependency validity, realistic duration, sprint consistency, role and assignee correctness, absence of invented professionals and commercial consistency.

  • Expert-authored golden references are separated from captured production output.
  • A fixed baseline and holdout comparison are retained for candidate ranking calibration.
  • Signals use a versioned normalization contract, recency weighting and recorded source type.
  • Calibration candidates remain shadow-only until minimum evidence and quality gates are met.
  • Canary exposure and outcome coverage are measured before promotion.
  • Promotion requires human approval; a previous verified version remains available for rollback.
  • Selection bias, confounding and causal-attribution limitations are documented instead of being hidden by a single aggregate score.
07

Human control and user transparency

  • Interfaces identify AI-generated recommendations, interpretations and agent activity where a user interacts with an AI system.
  • A user can inspect the real professional profiles, roles and available evidence included in a team option.
  • Multiple team options and replacement controls support comparison rather than a single unchallengeable result.
  • The final team, project, commercial and access decision remains with the authorized user.
  • Material agent actions follow configured approval and permission boundaries and are recorded with the resulting change.
  • Collty can explain the principal professional evidence supporting an included recommendation without exposing hidden candidate pools, another person's private data or proprietary ranking weights.

A professional can update or delete their profile, change visibility and report inaccurate or unsupported evidence associated with their own account. This correction mechanism addresses data and system error; it does not make Collty the adjudicator of an independent customer's final team choice.

08

Risk management and technical controls

The versioned risk register covers discrimination, ranking and selection bias, erroneous exclusion, hallucinated evidence, private-data leakage, prompt injection, model or provider failure, over-reliance, drift, unauthorized actions, weak evidence and misuse outside intended scope.

  • Capability and evidence validation before a person is included in a recommended team.
  • Grounded IDs and schema validation for model output.
  • No invented professional profiles or unverified team members.
  • Low-evidence states that preserve uncertainty instead of forcing a fabricated recommendation.
  • Provider timeouts, retries, deduplication and deterministic fallbacks that preserve verified evidence.
  • Token, latency, error, quality and drift accounting by task and provider.
  • Durable outbox processing for evidence and provenance events.
  • Shadow provider comparison, canary activation and rollback controls.
09

Post-market monitoring and incidents

Production monitoring records quality, pass rate, latency, provider errors, timeouts, token cost, drift, duplicate calls, eval coverage, calibration exposure and observed outcomes. Reports of incorrect evidence, unexpected exclusion, unsafe recommendations or unauthorized action can be recorded against the applicable AI-system version.

  • Incident severity, affected people, source and protected narrative.
  • Serious-incident candidate status and lifecycle state.
  • Containment, corrective action and final resolution.
  • Linked system version, evidence and audit events.
  • Review of whether rollback, suspension, notification or model/provider change is required.
10

Documentation and quality management

Collty's technical file is assembled from versioned system inventory, intended-purpose records, data-flow and privacy controls, risk assessments, DPIAs, evaluation datasets and graders, model/provider configuration, provenance, monitoring, incidents, literacy records, release evidence and change history.

The operating quality system separates build, validation, shadow evaluation, human approval, canary activation, monitoring and rollback. A code deployment alone does not silently promote new ranking weights.

11

AI literacy

Collty maintains a role-specific AI literacy register for administrators, product owners, engineers, support staff and deployer-facing roles. Records include programme version, module, role scope, assignment, completion, expiry and protected evidence.

  • Responsible operation and intended-use boundaries.
  • Human oversight and review of generated output.
  • Data governance, privacy and security.
  • Bias, uncertainty and evidence quality.
  • Incident identification, escalation and corrective action.
12

Status and limitations

Collty has implemented the technical foundations described above and continues to validate legal classification, documentation completeness, supplier evidence, deployment contexts and applicable transition dates. High-risk classification, conformity assessment, registration or notification obligations are determined per system and use case.

Architecture aligned, certification not claimed

Collty's architecture is designed around risk management, data governance, traceability, transparency, human oversight, accuracy, cybersecurity and lifecycle monitoring. This does not mean Collty has received official EU AI Act certification or regulator approval.