Anthilla

AI Policy

AI Policy — AI Act Compliance (EU 2024/1689)

Transparency, accountability, and user rights in the use of artificial intelligence.

This page declares how Anthilla Srl uses artificial intelligence, in compliance with EU Regulation 2024/1689 (AI Act) and the GDPR (EU Regulation 2016/679).

Fundamental principles

Anthilla adopts the following principles in the use of AI:

  • Local AI before cloud — most AI models run on local or dedicated infrastructure, not on public clouds. Data does not leave Anthilla's controlled perimeter.
  • Transparency — every use of AI is declared. Users know when they are interacting with an AI system.
  • Human accountability — every significant decision based on AI output is verified by a human operator.
  • Privacy by design — AI systems are designed to minimize processed data and comply with the GDPR.
  • Non-discrimination — models are evaluated for bias and discrimination. No automated decision with significant impact is taken without human supervision.

AI models used

Anthilla uses the following artificial intelligence systems:

System Type Where it runs Data processed
Local LLMs Open-source language models (e.g., Llama, GLM) Anthilla local servers User-entered text, not stored
Speech-to-text Whisper / local models Anthilla local servers Transient audio, not persistent
Text-to-speech Edge-TTS (Microsoft Neural) — Isabella (IT), Giuseppe (EN) voices Client-side (browser) or local server Page text, not stored
AI agents Automation systems (e.g., MagiSys) Anthilla local servers Client operational data, under contract

No AI model used by Anthilla falls within the "high risk" (Annex III AI Act) or "unacceptable" (Art. 5 AI Act) categories.

Data processing

Data processed by Anthilla's AI systems is managed according to GDPR principles:

  • Minimization — only data necessary for the specific purpose is processed
  • Retention limitation — transient data (STT audio, LLM text) is not permanently stored unless explicitly requested
  • Right of access — users can request information about processed data by contacting privacy@anthilla.com
  • Right to erasure — users can request deletion of their data at any time
  • No automated profiling — no decision based solely on automated profiling with legal or significant effect is taken without human supervision (Art. 22 GDPR)

Risk management

In compliance with Art. 9 AI Act, Anthilla applies a risk management process for the AI systems used:

  • Risk assessment before deploying any AI system to production
  • Continuous monitoring of performance and outputs
  • Mitigation measures for identified risks
  • Documentation of risk assessments
  • Periodic review (at least annual) of AI systems in use

Transparency to users

When a user interacts with an AI system on platforms managed by Anthilla:

  • The user is informed that they are interacting with an AI system, except in obvious cases
  • AI-generated content is identifiable (metadata, watermark, or explicit declaration)
  • TTS (text-to-speech) features use clearly synthetic artificial voices
  • No deepfake or voice synthesis imitating real persons is used

Accountability and human oversight

Anthilla maintains human control over all AI systems:

  • Every AI output that influences operational decisions is verified by a human operator
  • Automation systems (AI agents) operate within defined limits with human override available
  • In case of malfunction or incorrect output, the system can be stopped manually
  • Decisions with significant financial, legal, or operational impact always require human approval

Contacts and reports

For questions regarding the AI Policy, AI Act compliance, or to report concerns related to AI use:

This policy was updated on 2026-07-30 and will be reviewed within 12 months or upon regulatory changes.

Version and legal references

Version: 1.0 (2026-07-30)

References:

  • Regulation (EU) 2024/1689 — AI Act (entered into force August 1, 2024, gradual application)
  • Regulation (EU) 2016/679 — GDPR
  • ISO/IEC 42001:2023 — AI Management System
  • EDPB guidelines on AI and GDPR