AI Transparency Notice
Last updated: 2 July 2026 · Factual corrections: 1 August 2026 · Art. 50 applies from 2 August 2026
This notice describes how AI is used in Alethe and the transparency obligations under EU AI Act Art. 50 that apply to us and to you.
1. You are interacting with AI
The Alethe platform uses artificial intelligence to run agent workflows on your behalf — chat-based agents, scheduled agents, event-triggered agents, content generators, and analysis tools. You are not interacting with a human, unless explicitly stated for a specific interaction (e.g. live support handoff to an Alethe team member).
When you chat with an AI agent on Alethe (whether your own internal agent or our marketing assistant on alethe.eu), the chat surface displays a clear disclosure at or before the first turn:
"You're chatting with an AI agent powered by [MODEL NAME]. It can make mistakes — verify important information."This disclosure is required by Art. 50(1) EU AI Act.
2. What the AI does
The following AI features are used in Alethe:
| Feature | What it does | Underlying AI model providers | Your data sent to model? |
|---|---|---|---|
| AI agents (chat) | Answer questions, draft replies, run workflows defined by you | OpenAI / Anthropic / Google (Gemini) / Groq via OpenRouter and direct APIs | Yes — your prompts, attached files, and context |
| Content generation (text, images, video) | Generate marketing content, drafts, summaries based on your prompts | Text: OpenAI / Anthropic / Google. Media: fal.ai (including models fal forwards to a further third-party host), and — on direct APIs — Google (Imagen), OpenAI (image endpoints), Black Forest Labs (FLUX) and Ideogram. Full list on our Subprocessors page. | Yes — your prompts and reference materials |
| Skill activation / tool use | Decide which connected tools to invoke for a given user request | Same models | Yes — tool descriptors + user message |
| Workflow orchestration (multi-agent) | Coordinate multiple agents to complete a task | Same models | Yes — shared workflow context |
| Embeddings / vector search | Power semantic search over your knowledge base | OpenAI embeddings (or alternative) | Yes — document text |
| Web research tools | Search and summarise the public web via Brave / Serper / Apify | (search providers, not LLMs) — results then summarised by an LLM | Search queries you trigger |
3. How AI-generated content is marked
Two separate duties are frequently confused, so we state them apart. Art. 50(2) is a machine-readable marking duty and it is ours. Art. 50(4) is the visible disclosure duty for synthetic media depicting a real person, and who carries it depends on who publishes — see Section 5.
The machine-readable marker — deployed
Media and text generated on Alethe carry a machine-readable marker applied at the moment they are produced:
- Images — an XMP packet embedded in the file bytes, using the IPTC/C2PA
digitalSourceType = trainedAlgorithmicMediavocabulary term, plusgenerator="Alethe"and the model where known. It is re-applied after our own pipeline re-encodes an image, and it survives download. - Video — freeform metadata atoms in the MP4 (
aiGenerated=true,generator="Alethe", and the model where known). - Text — when an AI message is copied out of the platform chat, the HTML clipboard flavour carries a
data-ai-generated="true"wrapper. The plain-text flavour stays clean, and messages you wrote yourself are never marked.
Four limits we state rather than gloss
- This is metadata marking, not cryptographic signing. Full C2PA Content Credentials are a planned upgrade, pending the finalised EU Code of Practice on Art. 50(2). We do not currently issue a C2PA claim.
- Metadata can be stripped by third-party tools, including by a social platform at upload. We re-apply it after our own processing, and we never remove markings applied upstream by a model provider (C2PA, Google SynthID).
- Media generated before 31 July 2026 is not marked. The marker is applied at generation and was not applied retroactively to files already in storage.
- One generation path is still unmarked — video persisted through our Go media tool service. Everything produced through the main generation pipeline, which is what the creative studio uses, is marked.
The visible label — deployed in the Creative Studio
Generated images and video are displayed in the Alethe Creative Studio with a visible "AI generated" badge, carrying the description "This content was generated by AI. It is not a photograph or recording of a real event." for screen readers and on hover. We apply it to every generated asset, not only to media depicting real people: we cannot reliably tell at generation time which outputs would fall inside the Art. 3(60) "deep fake" definition, so we label the superset rather than risk one slipping through unlabelled.
Three limits on the visible label, stated rather than glossed
- It does not travel with the file. The badge lives in our interface, not in the bytes. Every download affordance for generated media carries a notice saying exactly that.
- It is not yet on every surface. The badge ships on the Creative Studio surfaces where media is generated, listed and previewed. Generated media rendered elsewhere in the product — inside a chat thread, for example, or a campaign preview — does not carry it yet. Extending it is in progress.
- The Art. 50(4) disclosure where you publish is still yours. If you export synthetic media made here and publish it anywhere outside Alethe, you are the Deployer in that context: you must make the visible disclosure there, and you must not strip the machine-readable marker.
4. Our role under the EU AI Act
For each AI feature in Alethe, our role is:
| Feature category | Our role | Why |
|---|---|---|
| Chat / generation / orchestration on third-party models | Deployer | We integrate third-party LLMs (OpenAI, Anthropic, Google, OpenRouter, Groq, fal.ai) unchanged — provider obligations rest with those model providers |
| Search tools | Deployer | Same — search results from Brave / Serper, then summarised by an LLM acting as Deployer |
| Embeddings | Deployer | OpenAI / alternative embeddings used unchanged |
Provider = the entity that develops or substantially modifies an AI system and places it on the EU market under its own name.
Deployer = the entity that uses an AI system under its authority in a professional capacity.
For the chat, search, orchestration and embedding features above, Alethe does not fine-tune or substantially modify the underlying models and acts as Deployer. If we ever do (e.g. ship a finely-tuned Alethe-branded model), we will update this notice and assume the relevant provider obligations under Art. 16 + Art. 50.
Generative image and video is treated differently. We expose generation under our own brand, so we do not push the Art. 50(2) machine-readable marking duty onto you — we operate it. The precise allocation of provider/deployer roles for these features is being confirmed with counsel; whatever the answer, the marking described in Section 3 is done by us.
Generative media marking
For generative image and video features we assume the Art. 50(2) machine-readable marking duty ourselves — we expose generation under our own brand, so we do not push that duty onto you. Alethe applies the marker described in Section 3 (with the limits stated there) and never strips upstream provider markings (C2PA Content Credentials, Google SynthID).
5. Your role as our customer
If you are a B2B customer of Alethe and you use the platform to interact with your own end-users (e.g. you deploy an agent that talks to your customers), you are also a Deployer under the AI Act in respect of that interaction. As Deployer you are responsible for:
- Art. 50(1) chatbot disclosure to your end-users (Alethe provides ready-made disclosure copy in the chat UI; you must keep it visible)
- Art. 50(3) emotion-recognition / biometric-categorisation disclosure (if you enable such features — currently not standard in Alethe)
- Art. 50(4) deepfake labelling (if you generate synthetic media depicting real people). Alethe shows a visible "AI generated" badge in the Creative Studio and embeds a machine-readable marker in the file (Section 3). Neither one travels with a file you export and publish elsewhere, so the visible disclosure in your own downstream context is still yours to make. You must also not strip the machine-readable marker.
- Art. 26 deployer duties generally, including registration in the EU AI Database under Art. 49 if your deployment falls within Annex III
Our DPA and MSA allocate these obligations expressly (provided at onboarding; request at info@alethe.eu).
6. What this AI cannot do
- It cannot make legally binding decisions on your behalf or your end-users' behalf.
- It may make mistakes ("hallucinations") — verify critical information before acting on it.
- It does not have access to information outside the data you provide and the underlying model's training cutoff.
- It is not a substitute for professional advice (legal, medical, financial, regulatory).
- It is not permitted to be used for any Art. 5 prohibited practice (subliminal techniques, exploitation of vulnerabilities, social scoring by public authorities, real-time biometric ID in public spaces).
7. Automated decision-making (Art. 22 GDPR)
Alethe does not, by default, make automated decisions producing legal or similarly significant effects on individuals within the meaning of Art. 22 GDPR.
AI agents on the platform produce outputs (drafted replies, classifications, recommendations); the decision to act on those outputs is taken by you or your authorised users.
If you configure an agent to act autonomously in a way that would constitute Art. 22 decision-making (e.g. an automated approval flow), you are responsible for offering a human-review right to affected individuals.
8. How we trained / configured the AI
| Feature | Base model(s) | Customisation | Training data |
|---|---|---|---|
| Chat agents | Third-party LLMs (OpenAI / Anthropic / Google / Groq / OpenRouter routing) | None — system prompts only, set by you | N/A (we do not train) |
| Content generation | Same + fal.ai for media | System prompts only | N/A |
| Embeddings | OpenAI embeddings (or alternative) | None | N/A |
We do not use your conversations or content to train shared / foundation models. That is our promise about what Alethe does.
It is not a promise we can make for every provider. Where an AI provider offers an API-tier training opt-out we apply it — OpenAI, Anthropic and Google default to opt-out for API customers. We do not hold a negotiated no-training commitment with every provider. In particular, our media-generation supplier's no-training commitment engages only under an enterprise contract, which we do not currently hold; on its self-serve terms it may use anonymised or aggregated derivatives to improve its own models. We name who the providers are on our Subprocessors page so you can assess this yourself.
9. Deepfake and synthetic media
Alethe offers AI image and video generation through fal.ai. We do not ship a "generate deepfake of a named real person" feature; if you use the generic image/video tools to create synthetic media of real people, you are the Deployer and must apply Art. 50(4) labelling (clear and prominent disclosure embedded in the artifact). Alethe shows a visible "AI generated" badge on generated media in the Creative Studio and embeds a machine-readable marker in the file (Section 3). Neither discharges your duty once the file leaves the platform — the badge is part of our interface and does not travel with a download, and the marker is invisible to a person and does not survive re-encoding. Make the visible disclosure yourself wherever you publish, and do not strip the machine-readable marker.
10. Emotion recognition and biometric categorisation
Alethe does not include emotion-recognition or biometric-categorisation features in its default product. If we add such features (or you wire third-party providers via custom MCP tools), we will update this notice and surface in-product Art. 50(3) disclosures.
11. Your rights
In relation to AI features, you (and your end-users, via you as Controller) have the right to:
- Request a human review of any AI-driven decision affecting you
- Receive a meaningful explanation of how the AI reached a specific output (limited by the explainability of the underlying third-party model)
- Opt out of AI features where opt-out is offered (e.g. disable AI in your organisation's settings)
- Request deletion of any AI-generated content based on your data
12. Provider obligations cascade
We require our AI-model subprocessors to:
- Be compliant with their respective AI Act obligations as Providers
- Honour API-tier training-opt-out defaults where they offer one — see Section 8 for where that is not yet contractually secured
- Disclose their own sub-processors (the chip vendors, hosting providers, etc.) under their respective DPAs
- Notify us of material changes to model behaviour, model retirement, or regulatory incidents
Failure of an AI subprocessor that affects our service triggers our incident-response and customer-notification flow (DPA Section 9).
13. Changes
Material changes to AI features, models, or our AI Act role (provider/deployer) are notified at least 30 days before taking effect, via email to active account holders.
14. Effective date and penalties
The Art. 50 transparency obligations apply from 2 August 2026. Under the AI Act's penalty framework, Art. 5 prohibited-practice violations carry penalties of up to €35 million or 7% of global annual turnover (Art. 99(3)), and transparency-obligation violations, including Art. 50, up to €15 million or 3% (Art. 99(4)).
15. Contact
AI-related questions: info@alethe.eu