Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
Legal · version 1.2 · in force from 15 July 2026

Notes on the use of artificial intelligence

Where we use generative models, on what data, which decisions remain human and how to object. Written because we are asked in every tender, and because it is right to say it up front.

Where AI is involved

  • Descriptive draft of the nature of the event, generated from the text of the report received and always marked as “to be verified”.
  • Proposed summary for the notice to users and for the report to the maintainer of the component.
  • Rewording suggestions at the user’s explicit request, on text the user is already writing.

Where it never decides

  • The qualification of the event: whether the obligation applies is decided by a person, step by step.
  • The calculation of deadlines: it is deterministic, based on the recorded time of awareness and the applicable article.
  • The filing of communications: no automation sends anything to the authorities.
  • The assessment of severity and decisions with legal effects on the client or on third parties.

1. Why we use a generative model

The slowest part of a report is not the decision: it is writing, at three in the morning, a technical description understandable to an authority. Starting from a pre-set draft reduces preparation time and the risk of omitting elements required by the form.

The draft is a starting point, not authoritative content. In the interface it is graphically distinguished from the other fields and accompanied by an indication of its source: calculated from the regulation, taken from your data, proposed as a draft.

2. Mandatory human validation

The proposed content cannot be filed without an explicit approval. The approval records the author, the time and the final text, and locks the content: from that moment corrections go through the 72-hour notification. In the activity log the entry bears the wording “human validation”.

3. Data used and not used

To generate the draft, only the necessary fields are transmitted to the model: the text of the report, the product and version indicated, the channel of receipt. We do not transmit historical logs, complete records, binary attachments or data of other clients.

Clients’ content is not used to train or fine-tune models, neither by the company nor by the suppliers. Inference runs on Amazon Bedrock in the EU (Milan) on Anthropic Claude models; the no-training condition is contractually guaranteed and applies also to temporary storage, limited to the time necessary for generation.

4. Suppliers and location

Inference runs on Amazon Web Services, identified as a sub-processor in the data processing agreement, through Amazon Bedrock in the EU (Milan) region on Anthropic Claude models. Service data is hosted in the European Union and the text you send to the assistant is processed there: it does not leave the EU. The provider does not use client content to train models. AWS is listed in the sub-processor list, which is updated with prior notice to clients in the event of a change.

5. How to disable generation

Draft generation can be disabled at company level by an administrator: in that case the fields remain empty and are filled in manually, without any limitation of the other functions. The deactivation is recorded and reversible.

6. Declared limitations

A generative model can produce plausible but inaccurate texts, omit elements or reuse wordings not relevant to the case. For this reason the draft never contains generated regulatory references: articles, recipients and deadlines come exclusively from the deterministic engine.

We do not use models to estimate severity, to decide whether a piece of evidence is reliable or to automatically classify a case: these are assessments that require human responsibility and remain so.

7. Relationship with the artificial intelligence regulation

The function described is an assisted drafting tool under human control. It does not fall within the prohibited practices and does not perform the functions that Reg. (EU) 2024/1689 qualifies as high-risk; we nonetheless fulfil the transparency obligations by clearly indicating in the interface which content is generated.

8. Reporting a problem

If a draft contains a significant error, the report button in the interface sends the case to our team: we analyse, correct the system instructions and, when necessary, disable the function for the affected cases. The reports received feed a documented quarterly review.

Summary data sheet

  • Purpose Assisted drafting of descriptive and summary drafts for compliance obligations
  • Human oversight Mandatory approval with recording of author and time
  • Data transmitted Text of the report, product and version, channel of receipt
  • Training Contractually excluded on all client content
  • Location Data hosted in the EU; inference on Amazon Bedrock in the EU (Milan) through the sub-processor AWS — the text does not leave the EU
  • Deactivation At the request of the company administrator, independently
  • Review Quarterly, with a log of error reports and corrections

To object to the use of draft generation or for requests concerning processing: privacy@cranotify.eu. See also Privacy Policy and Terms & Conditions.