GDPR & EU AI Act

GDPR-compliant AI: the EU AI Act considered from day one

Habicht is an AI platform from Austria, built to the requirements of the GDPR: data minimisation, access, export and deletion handled directly in the application, complete audit logging, and operation on your own premises or in an EU data centre. Every use case is additionally classified automatically by EU-AI-Act risk class, including exportable documentation for auditors.

Goshawk portrait with a watchful gaze, standing for data protection with transparency and traceability. Image generated with AI.
Close-up of the watchful goshawk's eye, standing for transparency and traceability. Image generated with AI.

What the platform handles for you

  • Automatic risk classificationEvery app and AI endpoint is classified by EU-AI-Act risk, with traceable reasoning.
  • Audit evidence at the push of a buttonOne compliance documentation (PDF/Word) per version, designed for the AI Act, GDPR Art. 30, NIS2 and CRA.
  • Complete audit loggingEvery AI action traceable, retained for 7 years; every result carries a transparency marker.
  • Data-subject rights without a ticket queueAccess, export and deletion under the GDPR are handled by your users directly in the application.
Annex VII fields for technical documentation, an SBOM snapshot per release, transactional deletion cascades across all data stores, breach notification within 72h, and a supply chain designed for NIS2/CRA with signed container images. These functions are in implementation or designed for the respective requirements.
EU AI Act

The EU AI Act in three sentences

  1. The EU AI Act classifies AI applications by risk and attaches obligations to that, from transparency to technical documentation.
  2. Most obligations have applied since 2 August 2026; transition periods for certain high-risk systems run until 2027 (Art. 113, Regulation (EU) 2024/1689).
  3. Any organisation using AI needs to know the risk class of its applications and be able to demonstrate it.
Assess your risk class in 2 minutes

Promised or implemented

Data protection can be promised in a contract or implemented in the application. You notice the difference in daily operations.

Only in the contract

Compliance is in the small print; implementation stays your job.

  • Compliance lives in the terms and the data-processing agreement, not in the product.
  • Data sits in a US cloud; third-party access is excluded contractually, not technically.
  • Evidence has to be gathered manually.
  • Deletion and access are a ticket process.
In the application

Risk class, audit log and evidence are produced automatically as you use it.

  • Data protection and risk classification are an integral part of the platform.
  • Operation on your own premises or in an EU data centre: no data outflow to the US cloud.
  • Compliance documentation is produced automatically per version.
  • Access, export and deletion are handled by users themselves, no ticket needed.
Sovereignty & data protection

Sovereignty is part of data protection.

Your data stays on your own premises or in an EU data centre. It is not used for training and does not flow to US cloud services.

More on operations & sovereignty
FAQ

Frequent questions on GDPR & the EU AI Act

Habicht is built to the requirements of the GDPR: data minimisation, access, export and deletion directly in the application, complete audit logging, and operation on your own premises or in an EU data centre, with no data outflow to the US cloud.

Every use case is automatically classified by risk class, and you receive an exportable compliance documentation for auditors.

No. Your data is neither used to train models nor stored beyond processing (zero retention).

Either fully in your own data centre (on-premise), hybrid, or as SaaS in an EU data centre, never in the US cloud.

See Habicht in your own environment.

A short demo, tailored to your use case: on-premise, hybrid or in the EU cloud.