GDPR-compliant AI: the EU AI Act considered from day one
Habicht is an AI platform from Austria, built to the requirements of the GDPR: data minimisation, access, export and deletion handled directly in the application, complete audit logging, and operation on your own premises or in an EU data centre. Every use case is additionally classified automatically by EU-AI-Act risk class, including exportable documentation for auditors.


What the platform handles for you
- Automatic risk classificationEvery app and AI endpoint is classified by EU-AI-Act risk, with traceable reasoning.
- Audit evidence at the push of a buttonOne compliance documentation (PDF/Word) per version, designed for the AI Act, GDPR Art. 30, NIS2 and CRA.
- Complete audit loggingEvery AI action traceable, retained for 7 years; every result carries a transparency marker.
- Data-subject rights without a ticket queueAccess, export and deletion under the GDPR are handled by your users directly in the application.
The EU AI Act in three sentences
- The EU AI Act classifies AI applications by risk and attaches obligations to that, from transparency to technical documentation.
- Most obligations have applied since 2 August 2026; transition periods for certain high-risk systems run until 2027 (Art. 113, Regulation (EU) 2024/1689).
- Any organisation using AI needs to know the risk class of its applications and be able to demonstrate it.
Promised or implemented
Data protection can be promised in a contract or implemented in the application. You notice the difference in daily operations.
Compliance is in the small print; implementation stays your job.
- Compliance lives in the terms and the data-processing agreement, not in the product.
- Data sits in a US cloud; third-party access is excluded contractually, not technically.
- Evidence has to be gathered manually.
- Deletion and access are a ticket process.
Risk class, audit log and evidence are produced automatically as you use it.
- Data protection and risk classification are an integral part of the platform.
- Operation on your own premises or in an EU data centre: no data outflow to the US cloud.
- Compliance documentation is produced automatically per version.
- Access, export and deletion are handled by users themselves, no ticket needed.
Sovereignty is part of data protection.
Your data stays on your own premises or in an EU data centre. It is not used for training and does not flow to US cloud services.
More on operations & sovereigntyFrequent questions on GDPR & the EU AI Act
See Habicht in your own environment.
A short demo, tailored to your use case: on-premise, hybrid or in the EU cloud.