EU AI Act: Unique's view
7 min read
Executive Summary
Unique's role under the AI Act is not fixed — it depends on the system and deployment mode in view, not on the company as a whole. When Unique places the SaaS platform on the EU market under its own name to banking clients, Unique is the provider of that AI system (Art. 3(3)); the client, using it under its own authority for its business, is the deployer (Art. 3(4)). When Unique itself uses the platform, or third-party AI tools, for its own operations, Unique classifies as a deployer. Unique is not a provider of the underlying general-purpose AI models (that sits with model suppliers such as Anthropic, OpenAI and Azure OpenAI, under Chapter V) and, outside occasional pure resale of an unmodified third-party component, is not a distributor either — building and branding the platform makes Unique the provider, not just a intermediary.
Our Unique AI platform is a general productivity, retrieval and analysis tool for financial professionals, its intended use stays outside Annex III, and Unique explicitly does not support the use cases (credit scoring, insurance pricing, recruitment, workplace emotion recognition) that would place it as as High Risk AI System. As a provider, Unique's obligations centre on Article 50 transparency (AI disclosure, content labelling, machine-readable marking — relying on upstream LLM watermarking where applicable), Article 4 AI literacy, and the Article 5 prohibitions. Where clients extend the platform through the SDK or AI Factory, or white-label it to their own users, the client becomes the provider of that system (and remains its deployer). This does not elevate it to high-risk either, and Unique supplies the technical documentation clients need to meet their own light obligations.
What applies to Unique
The Digital Omnibus deferred the high-risk obligations by 16 months but left the transparency obligations on their original date. The obligations that apply to us are:
Date | What applies | Relevance to Unique |
|---|---|---|
2 Feb 2025 | Prohibited practices (Art. 5), AI literacy (Art. 4) | In force. Applies to us as provider and as deployer. |
2 Aug 2026 | Transparency obligations (Art. 50) become enforceable; breaches carry fines of up to EUR 15 million or 3% of worldwide annual turnover | In force. |
2 Dec 2026 | Art. 50(2) machine-readable marking extends to systems already on the market before 2 Aug 2026; new prohibitions on AI-generated intimate imagery and CSAM | Marking work in progress. New prohibitions are outside our product scope. |
2 Feb 2027 | Interoperability requirements for detecting and reading content markings | Monitored. |
Two sets of obligations sit outside this table. The high-risk requirements (Annex III from 2 December 2027, Annex I from 2 August 2028) do not apply to our systems. The GPAI model provider obligations, in force since 2 August 2025, fall on our model suppliers rather than on Unique.
Commission guidance now available and used in our assessment: guidelines on the definition of an AI system and on prohibited practices (July 2025), on GPAI model obligations (July 2025), on Art. 50 transparency (20 July 2026), and draft guidelines on high-risk classification under Art. 6 (May 2026, final version expected end-2026).
Regulation
The AI Act takes a horizontal, risk-based approach: minimal obligations for low-risk AI, transparency duties for certain systems, strict requirements for high-risk AI, and outright prohibitions for unacceptable risk.
The EU AI Act's risk-based approach
Role of Unique
Roles under the AI Act attach per system, not per company. Unique holds more than one role depending on deployment setup and client’s agreements (mainly handeled in Master Service Agreememt between client and Unique).
Not a GPAI model provider. Unique does not train general-purpose AI models. A downstream modifier becomes a GPAI model provider only where the modification significantly changes the model, indicatively above one third of the original training compute. Our retrieval, prompting and light adaptation is far below that.
Configuration is not building. Setting prompts, connecting knowledge sources and configuring agents inside the platform leaves Unique as the provider and the client as deployer. The boundary between configuration and building a separate system is not yet addressed by Commission guidance and is assessed case by case.
What this means for our clients
Because our clients deploy a system that is not high-risk, their obligations under the AI Act are limited but not absent.
Three apply directly:
Ensure the people using the platform have sufficient AI literacy for the way they use it (Art. 4), which is a training and awareness duty rather than a documentation exercise.
They must not put the platform to any of the uses prohibited under Art. 5, the most plausible of which in a financial institution is inferring the emotions of employees from their communications or behaviour (this is covered in Unique’s responsible AI standards and respective terms of use).
They must meet the deployer-side disclosure duties in Art. 50(4) where these arise. The heavier deployer obligations, meaning the human oversight arrangements, input data governance, log retention, monitoring and incident reporting in Art. 26 and the fundamental rights impact assessment in Art. 27, attach only to high-risk systems and so do not apply as long as the platform is used for its intended purpose.
Beyond the AI Act, the rules that already governed this kind of processing continue to apply unchanged: the GDPR or FADP for personal data, including a lawful basis, transparency towards data subjects and a data protection impact assessment where the processing warrants one; professional secrecy and banking confidentiality for the content clients bring into the platform; and the client's own supervisory framework, which for FINMA-supervised institutions means Guidance 08/2024 and its expectations on an AI inventory, materiality assessment and clear accountability.
Clients who build on our platform
Clients can extend the platform through our SDK. Where a client builds its own AI system this way, or offers our system to its own users under its own brand, the client is the provider of that system under Art. 3(3) and its deployer at the same time.
This does not make the system high-risk. Classification depends on the intended purpose, not on who built it, so the obligations that follow remain light: AI literacy (Art. 4), the Art. 5 prohibitions, and Art. 50 transparency where the system interacts with people or generates content. Unique supplies the technical documentation, instructions for use and model information clients need to meet them.
What this means in practice
Our systems are not high-risk. The platform is a general productivity, retrieval and analysis tool for financial professionals. Its intended purpose, as stated in our documentation and marketing, does not fall within Annex III. Classification is reassessed for each new agent or module.
Transparency (Art. 50) is our main obligation. Measures on Unique AI side are in place: disclosure that the user is interacting with AI, with agents disclosing both their artificial nature and on whose behalf they act; visible labelling of generated content; terms of use for end users; and AI literacy training for staff and clients.
Art. 50(2) requires generated content to be marked in a machine-readable format. As Unique AI works with pre-trained models offered by large LLM providers like Anthropic, we do rely on the watermarking of those providers.
Example:
Use cases we do not support
We explicitly distance ourselves from the following and do not advise clients to implement them on our platform:
Creditworthiness assessment and credit scoring (Annex III, 5(b))
Risk assessment and pricing for life and health insurance (Annex III, 5(c))
Recruitment, selection and employment decision-making (Annex III, 4)
Emotion recognition in the workplace, which is prohibited outright under Art. 5(1)(f)
Governance basis
Our AI management system is certified to ISO/IEC 42001, alongside ISO 27001, ISO 9001 and SOC 2 Type II. This is the primary evidence base for the governance, documentation and monitoring measures described above.
Beyond the AI Act, Unique aligns with FINMA Guidance 08/2024 on governance and risk management when using AI, which supersedes the FINMA Risk Monitor 2023 as the operative Swiss supervisory reference. Its expectations: governance and a maintained AI inventory, risk identification and materiality assessment, robustness and correctness, explainability, and clear accountability.
Switzerland. Following the Federal Council decision of 12 February 2025, Switzerland is not adopting a horizontal AI act, relying instead on ratification of the Council of Europe AI Convention, implementation focused on public-sector actors, and sector-specific law alongside the FADP. A consultation draft is expected by end 2026.
Assessment and review. Classification is assessed against the AI Act, the Commission's guidelines and Annex III, and is performed by the CISO and CDO within our ISO/IEC 42001 management system. Last reviewed September 2026. Reviewed annually and on material product change.