Compliance · EU AI Act
EU AI Act Risk Classification
Keypra's self-classification under Regulation (EU) 2024/1689 — what risk tier each part of the platform falls into, and the obligations we discharge in each role.
Last updated: August 2026
1. Why we publish this
Enterprise procurement, DPIA reviewers, and works councils increasingly ask AI vendors for a single, citable statement of where the product sits in the AI Act risk hierarchy. Rather than leave that determination to be reconstructed from scattered policy pages, we state it here in one place.
The classification below reflects Keypra's own assessment as a deployer of general-purpose AI models accessed via the Lovable AI Gateway (Google, OpenAI), and as a provider of the Keypra application layer that wraps those models. We are not a provider of a general-purpose AI model.
2. Our role under the AI Act
- Deployer (Art. 3(4)). Keypra uses third-party general-purpose AI models under their published API terms to deliver application functionality (prompt analysis, coaching, content generation, image generation for Rafy slides). We do not train, fine-tune, or place those models on the EU market.
- Provider (Art. 3(3)) of the Keypra application. We are the provider of the Keypra-branded application as a whole, which means we take responsibility for Art. 50 transparency obligations at the surface where users interact with our product.
- Not a provider of a GPAI model. Keypra does not place a general-purpose AI model on the EU market, so the GPAI provider obligations under Art. 53–55 do not apply to us directly. They apply to the upstream model providers (Google, OpenAI), with whom we contract via the Lovable AI Gateway.
3. Risk tier — overall product
Keypra is operated as a Limited-Risk AI system for its user-facing surfaces and as a Minimal-Risk AI system for its background analytics. We do not operate any surface that meets the criteria for the High-Risk tier under Annex III, and we do not engage in any practice listed in Art. 5 (Prohibited Practices).
The walk-throughs in §4 and §5 below explain how we reached that conclusion for each Annex III category and each Art. 5 prohibition.
4. Not Annex III (High-Risk) — walk-through
| Annex III § | Category | Keypra position |
|---|---|---|
| §1 | Biometric identification, categorisation, emotion recognition | No biometric data is collected. Behavioural Telemetry measures keystroke timing, not biometric identifiers. See Behavioural Telemetry Methodology. |
| §2 | Critical infrastructure management | Keypra is a SaaS productivity tool. It does not control water, gas, electricity, transport, or digital infrastructure operations. |
| §3 | Education & vocational training — access, evaluation, proctoring | Keypra is a self-led professional development tool. It does not gate access to educational institutions and is not used to evaluate students in formal education. Competence scoring is voluntary, self-led, and contestable. See Competence Methodology. |
| §4 | Employment, worker management, recruitment, performance evaluation | Contractually prohibited from being used for employment decisions (Terms §10a). Per-person scores are never exposed to org admins, managers, or lecturers; employer surfaces show k-anonymised aggregates only. See Behavioural Telemetry Methodology. |
| §5 | Access to essential private/public services (credit, social benefits, insurance) | Keypra does not score or determine access to credit, benefits, healthcare, or any essential service. |
| §6 | Law enforcement | Keypra is not used by, marketed to, or designed for law enforcement bodies. Use by law-enforcement deployers is not contemplated in our Terms. |
| §7 | Migration, asylum, border control | Not applicable. Keypra is not used in immigration, asylum, or border-management decisions. |
| §8 | Administration of justice and democratic processes | Not applicable. Keypra is not used by courts, tribunals, or in electoral processes. |
5. Not Art. 5 (Prohibited Practices) — walk-through
- Art. 5(1)(a) Subliminal manipulation. Keypra does not deploy subliminal techniques to materially distort behaviour. The platform is overtly an AI tool; nothing about its operation is hidden from the user.
- Art. 5(1)(b) Exploitation of vulnerabilities. Keypra does not target users based on age, disability, or socio-economic vulnerability for manipulative purposes.
- Art. 5(1)(c) Social scoring by public authorities. Not applicable. Keypra is a private B2B/B2C product, not operated by a public authority for social-scoring purposes.
- Art. 5(1)(d) Real-time remote biometric identification in public spaces. Not applicable. No biometric processing, no camera, no public- space deployment.
- Art. 5(1)(e) Predictive policing on profiling alone. Not applicable. Keypra does not produce policing risk scores.
- Art. 5(1)(f) Emotion recognition in the workplace or education. Behavioural Telemetry is a deterministic typing-cadence counter, not an emotion-inference system. It is member-private, never employer-visible, and contractually banned from workplace decisions. Full reasoning at Behavioural Telemetry Methodology.
- Art. 5(1)(g) Biometric categorisation by protected characteristic. Not applicable. No biometric data is processed.
- Art. 5(1)(h) Untargeted scraping of facial images for biometric databases. Not applicable. Keypra does not scrape or store facial images.
6. Transparency obligations under Art. 50
- Art. 50(1) Chatbot disclosure — ours. Every surface where a user converses with an AI carries a visible point-of-interaction disclosure before the first message, including the Prompt Coach, Self Discovery, Rafy, the learning coach, the lesson consultant and the Context Harvester.
- Art. 50(2) Machine-readable marking — the model provider’s. Marking raw synthetic output in a machine-readable format falls on the provider of the generative model, not on Keypra as a deployer. Keypra additionally renders a shared AI Output Disclaimer at the point of every AI-generated text output. See AI Content Marking.
- Art. 50(4) Publication disclosure — ours. Where Keypra publishes AI-assisted text as information of public interest, the content carries the Keypra AI label and names a human editor of record. Rafy-generated slide images carry a visible “AI-generated image” label and machine-readable C2PA / IPTC metadata where the upstream provider supports it. Full method at AI Content Marking.
7. Art. 4 — AI literacy
Keypra discharges its own Art. 4 obligation for its team via the measures described in the DPIA Summary §5a.
Enterprise customers who deploy Keypra outputs in their own workflows become deployers in their own right and inherit the Art. 4 obligation for their own staff. We surface this responsibility in our Enterprise Terms (§10b). The AI Literacy Index methodology is published to help customers measure and document their own literacy programmes.
8. Review cadence and change log
This classification is reviewed at least annually and immediately upon any material product change that could affect the risk tier — for example, the addition of a feature that processes biometric data, scores access to an essential service, or evaluates worker performance.
| Date | Change |
|---|---|
| August 2026 | Art. 50 review at the transparency milestone. Corrected the split between Art. 50(2) (machine-readable marking — model provider duty) and Art. 50(4) (publication disclosure — Keypra's duty); extended Art. 50(1) chatbot disclosure to every conversational surface; added explicit Art. 5 prohibited-practice terms to the Usage Policy. |
| May 2026 | Initial consolidated risk-classification statement published. |
9. Contact
Questions on this classification, or requests to challenge it, should go to compliance@keypra.com.