Our Act posture, written before procurement asks.
A summary of how Arcken's builds are made under the EU AI Act: classification, oversight, logging, and the ownership boundary between our tooling and your product.
We publish this early so it’s on the site when procurement asks for it. The content here updates as engagements require. Material changes land with a new “last updated” date and a note in the footer.
01 · Classification
Arcken’s builds use general-purpose AI models at the inference layer. Per engagement, the deployed agent is classified in the SOW as either limited-risk (most renewal and content-generation use cases) or high-risk (when the agent’s output triggers a legally significant decision without a human in the loop, something we do not ship).
We do not deploy agents in any of the Article 5 prohibited categories. If an engagement would require that, we say so on the first call and pass on the work.
02 · Human oversight
Every build ships with explicit escalation paths. Renewal agents hand off to a named human when a signal crosses a guardrail. Internal-tool agents propose actions; a named operator presses the button. A hands-off, unattended agent is not a shape we ship.
Guardrail thresholds and escalation targets are written into the customer environment and into the SOW. Updated with the customer, not behind their back.
03 · Logging and audit
Every agent interaction is logged with a timestamp, the customer identifier, the guardrails that were active, and the action taken. Redaction policies on personal data are defined per engagement.
Retention is named in the SOW. A machine-readable export of the audit log is available on request. We build it into the engagement, not as an afterthought.
04 · Model layer and sub-processors
Customers choose the model provider where it matters: an EU-hosted instance of a major foundation model, an open-weight model running in-region, or a hybrid. The sub-processor list is named in the SOW before the engagement starts. If the model we’d recommend changes, you hear about it.
05 · The line between our tooling and your product
We use global vendors inside Arcken itself (coding assistants, meeting recorders, design tools) where they ship best. None of that tooling is in the path of your product or your customer data. The AI-Act obligations attach to the agents we ship into your environment; our internal tooling is our problem to govern, and we do.
This line is the reason we can honestly claim the moat without claiming “European pure.” Purity overstates what’s true. Your data, your infrastructure, European is accurate and sells harder.
Questions
For anything on this page (a missing clause, a clarification, a request), email the founders directly. Named human on the other end, reply within a business day.