Skip to main content

    EU AI Act safeguards

    How Keypra complies with Article 4 (literacy) and Article 14 (human oversight) — and what we will not do.

    Your journey:DiscoverFirst WinDaily PracticeLibraryTeamCompliance
    ClarityContextConfidence

    We treat the EU AI Act as a design constraint, not a checkbox. Two articles shape the product more than any other: Article 4 (AI literacy) and Article 14 (human oversight of AI-graded assessments).

    Article 4(b) — no employer-side classification

    Employers must promote AI literacy without classifying their staff. We mirror this in the product: org admins, managers and lecturers never see per-person mastery scores, AI literacy tiers or derived badges.

    Aggregate-only on employer surfaces

    Manager portal, Reporting Hub and admin dashboards show group-level signals only. Personal data stays with the member.

    k≥3 suppression

    Any aggregate covering fewer than 3 members is suppressed — preventing de-anonymisation through small-group exclusion.

    Enforced at the database

    The rule is enforced inside the RPC layer, not just the UI. Client requests for per-person classifications return nothing, regardless of frontend.

    Member view preserved

    Each member keeps the full picture of their own competence in their private workspace.

    Article 14 — human oversight on AI-graded assessments

    Where AI contributes to a competence call, the user must be able to understand and contest it. Our safeguards:

    Server-side consent gate

    AI-graded competence flows are off until the member explicitly consents. No quiet enrolment.

    Contestability

    Each AI-graded result includes the inputs and the rule that produced it, plus a one-click contest path.

    Behavioural over inferential

    Wherever possible we measure what people did, not what we infer they "are".

    Retention floors

    7-, 30- and 90-day retention checks frame learning as a curve, not a verdict.

    ⚠️Things we will not build

    An AI literacy "score" visible to managers. Hidden classification of staff for performance reviews. Surveillance dashboards. We've turned down feature requests for all three.

    Article 5(1)(f) — why typing cadence is not emotion recognition

    Keypra collects optional Behavioural Telemetry — pause counts, deletion ratios, session duration — to render a private "Crafting Fluency" chart for the member. The Article 5(1)(f) prohibition targets systems that infer emotions or affective states in the workplace. Crafting Fluency does no inference: it counts pauses and deletions and divides them by duration. There is no AI model, no affective label, and the result is shown only to the member who produced it. Full disclosure on the Behavioural Telemetry methodology page.

    Annex III §4 — why Keypra is not workplace performance monitoring

    Annex III §4 covers AI systems used to monitor and evaluate worker performance. Keypra is contractually prohibited from being used this way: the "Prohibited Uses" section of our Terms of Service and the Behavioural Telemetry annex of our Data Processing Agreement bind Customers and Organisations not to use the Service, or any data derived from it (including ALI scores, Crafting Fluency metrics, retention checks or behavioural telemetry), as the basis for hiring, promotion, performance evaluation, disciplinary action or termination. Combined with our database-level ban on per-person classifications on employer surfaces, this keeps Keypra outside the Annex III §4 scope.