Compliance
AI Act assessment
Enret srl's self-assessment under Regulation (EU) 2024/1689: how we classify the systems we develop and integrate, and the duties we apply.
Last updated: 18 September 2026
This self-assessment is provided for information. It does not replace a formal conformity assessment or legal advice and must be reviewed for each new AI system.
1. Our roles
- Provider when we develop and release an AI system under our name or substantially modify a third-party model.
- Deployer when we internally use third-party AI systems.
- Distributor or integrator when we integrate third-party models and services into client systems.
- The applicable role is agreed in writing for each project.
2. Risk classification
- Prohibited practices: we do not develop or integrate social scoring, subliminal manipulation, exploitation of vulnerabilities, workplace or education emotion recognition, real-time remote biometric identification or sensitive biometric categorisation.
- High risk: systems used for recruitment, promotion, termination, task allocation, performance monitoring, admission or assessment in education receive a dedicated screening before work starts.
- Limited risk: chatbots, conversational assistants and content generation, subject to transparency duties.
- Minimal risk: internal support tools without an impact on people's rights or opportunities.
3. This website
- The public website does not run AI systems, profile visitors or make automated decisions.
- The restricted area can extract public page titles, descriptions and previews through deterministic automation.
- Future AI-assisted features will be classified, clearly labelled and reviewed by a person before publication.
4. Controls for high-risk systems
- Documented lifecycle risk management and data governance.
- Technical documentation, event logs and clear deployer instructions.
- Effective human oversight with the ability to review, correct or override outcomes.
- Accuracy, robustness and cybersecurity proportionate to intended use.
- Fundamental-rights assessments and worker information where required.
5. Transparency and AI literacy
People interacting with an AI assistant are told that it is an AI system. Synthetic content is labelled where required. We provide initial and continuing AI training to our team and include AI literacy in client adoption projects.
6. Third-party models and GDPR
We review provider documentation, terms, input-data policies and copyright information. We minimise personal data and favour configurations that prevent client data from being used for retraining. The AI Act complements GDPR; see our privacy policy.
7. Governance
- An internal owner maintains a register of systems, roles and risk classes.
- Compliance screening takes place at project start and after substantial changes.
- Report incidents or concerns to info@enret.it.
- This document is reviewed at least annually.