Skip to content

EU AI Act · Transparency

How Kasp uses artificial intelligence.

Last updated: 2026-09-09. This information describes the intended purpose, AI functions, human oversight and limits of the system.

01 Status

Provider and deployer roles are determined for each function

Anel Alicic, trading as KASP provides the integrated Kasp application under its own name and defines its intended purpose. Depending on the specific function, Kasp may therefore be a provider of an integrated AI system. When using AI systems under its own responsibility, Kasp may also be a deployer. Providers of underlying models and infrastructure remain independently responsible for their respective services.

These roles must be determined for each model, function, data flow and purpose, and documented in the applicable model and provider records. Current provider and data flow information is set out in the Privacy Policy. A change of model or purpose may be made available to users only after a new privacy, security and AI Act assessment.

02 Purpose

Intended purpose

Kasp is an AI-supported analysis and work tool. It can structure occupational roles into tasks and use evidence to assess how AI assistance, partial automation and substitution potential may change tasks. Other work areas support research, summarisation, scenarios, learning and transformation planning, and the creation of documents and artifacts.

Personal Kasp chats support individual questions. Orbit is the workspace for organisational and system context, scenarios and shared artifacts. Both paths use the same human-controlled intake; neither a workspace nor an assistant role gives the system autonomous decision-making authority.

Within personal Kasp chats and Orbit, 'research' means working with qualified Kasp evidence; it is not live Perplexity research using customer inputs. Where Kasp uses a separate service to obtain public sources, that service must not receive customer, account, authentication, chat, file, workspace, Orbit or billing data. Discovered candidates may be incorporated into customer results only after Kasp independently reviews the source, rights, attribution and substantive validity.

Calculations based on fixed rules and generated AI text must be distinguished. A reproducible calculation does not establish that its assumptions or input data are correct. An official occupation or task description alone does not demonstrate measured AI effects, time savings or permissible automation. The sources, comparison data, assumptions and limitations stated for the specific result are decisive. Further explanations are provided in the methodology.

Kasp is an information and decision-support system. It is not career, HR, legal, tax, medical or financial advice and does not guarantee the future development of an occupation, company or job.

No function is approved that assesses, ranks, monitors, selects, admits or rejects an identified or identifiable person, or makes or recommends a legally or practically significant decision about them. This applies in particular to employment, admission to and assessment in education, creditworthiness, insurance risk or pricing, public benefits, migration, law enforcement, justice, and biometric identification, categorisation and emotion recognition. Subsequent human review does not extend this intended purpose.

03 Oversight

Four binding principles

  • 01Recognisable AI interactionKasp must clearly inform people that they are interacting with an AI system no later than the start of a direct interaction. Notices must be perceivable and accessible.
  • 02Human reviewAI outputs are probabilistic work results. Sources, assumptions, uncertainties and limits must be reviewed by a competent person before important decisions. Kasp does not make legally binding decisions for users.
  • 03No decisions about individualsKasp is intended for roles, tasks, programmes, tools and aggregated organisations—not individual decisions concerning employment, admission to education, credit, insurance, benefits, migration, law enforcement, justice or biometrics.
  • 04Traceable evidenceAssessments should make the source, data date, scope and uncertainty recognisable. Missing evidence must not be presented as established fact.

04 Orbit & Organisation

Analyses without decisions about individuals

The approved purpose of Kasp's organisational analyses, including Orbit, covers only role-, task-, skill- and organisation-based analyses. Names, personnel numbers, CVs, and performance, behavioural, health or disciplinary data of identified or identifiable applicants and employees must not be entered to assess, rank or prepare a personnel decision.

In particular, Kasp must not decide on hiring, selection, access to employment, promotion, termination of employment, performance monitoring or allocation of tasks to individuals, or automatically recommend such a decision. Individual decisions on admission, grading, credit, insurance, benefits, migration, law enforcement, justice and biometrics are likewise excluded. General, aggregated and non-personal analyses remain permitted where sources, user context, Kasp inference, assumptions, uncertainties and unknowns remain separately visible.

Many of these individual uses are described as high-risk cases in Annex III of the EU AI Act; certain practices are already prohibited under Article 5. Kasp excludes the entire group as a stricter product limit. The exception in Article 6(3) is not assumed merely because human review takes place. Profiling natural persons in an Annex III use always remains high-risk.

Before any change of purpose, the function remains blocked until a new classification, technical documentation, logging, human oversight, privacy review and clear responsibilities have been approved. This product limit is a governance measure, not an official classification or certification.

05 Organisation

Obligations of organisational customers

Employers and other organisational customers remain responsible for their specific use. Before processing employee data, they must review in particular the purpose, necessity and legal basis, information obligations, allocation of roles and erasure periods. Consent in an employment relationship is not automatically freely given.

Where processing is likely to pose a high risk to rights and freedoms, the need for a data protection impact assessment must be examined before processing begins and an assessment carried out where required. Where technical systems can monitor behaviour or performance, the participation and co-determination rights of employee representatives must be observed. A workplace system actually classified as high-risk is additionally subject to the EU AI Act's information, oversight and logging obligations. Under Regulation (EU) 2026/1744, the substantive requirements in sections 1 to 3 of the high-risk chapter generally apply to systems under Article 6(2) and Annex III from 2 December 2027; this does not postpone the duty to block, classify and prepare changes of purpose beforehand.

Under Regulation (EU) 2026/1744, the Chapter III obligations for Annex III systems, including Articles 26 and 27, generally apply from 2 December 2027. Depending on the use, Article 26 then requires, among other things, use in accordance with instructions, authorised and trained human oversight, monitoring, controlled logs generally retained for at least six months, and reporting of risks and incidents. Article 27 does not require a fundamental rights impact assessment for every deployer, but in particular for public bodies, private providers of public services, and certain credit and life and health insurance cases. These uses are not approved at Kasp; an internal risk review must not be described as a completed Article 27 FRIA.

Kasp replaces neither review by data protection officers, employee representatives and responsible specialists nor legal approval by the respective employer.

06 Labelling

Interaction notices and AI-generated content

Article 50 of the EU AI Act has applied since 2 August 2026. Direct interaction with Kasp must therefore already be recognisable as AI interaction from the start. Depending on the role, format and publication, further visible or machine-readable labelling obligations may apply to generated or manipulated content.

According to the European Commission's current guidance, a limited transition period until 2 December 2026 applies exclusively to the marking and detection obligation under Article 50(2) for systems placed on the market before 2 August 2026. Kasp does not rely on this transitional rule without a documented individual assessment.

Kasp makes no blanket commitment that all chat, copying, sharing and export formats contain machine-readable provenance, watermarks or cross-format labelling. The notices on the respective content and the statutory obligations applicable to its use are decisive. Users and organisational customers must check before publication whether additional visible or machine-readable labels are required.

Published AI-generated or manipulated text on matters of public interest, and deepfakes, may trigger additional labelling obligations for the respective deployer. Users must not misleadingly remove existing notices.

07 Literacy

AI literacy and change management

Article 4 has applied since 2 February 2025. Under the version in force since 27 July 2026, providers and deployers must take measures to support the development of AI literacy. A particular individual level of competence need not be guaranteed. People who develop, operate, administer or use Kasp for organisations are equipped, according to their role, with knowledge of system limits, data quality, privacy, information security, bias, human oversight and incident reporting. Training measures, model changes and material changes of purpose must be documented traceably.

08 Supply chain

GPAI documentation for downstream use

When a general-purpose AI model is integrated, its provider remains responsible for the model obligations under Article 53. These include in particular technical documentation for authorities, information about capabilities and limits for downstream system providers, a copyright policy and a public summary of training content. Kasp remains responsible for the purpose, interface, system instructions, safeguards and transparency of its own integrated system.

Normal API, prompt, retrieval, tool or UI integration does not automatically make Kasp the provider of the underlying GPAI model. A substantial model modification may change that role and must be reassessed in advance. For every production model, the model register must record provider, version, documented capabilities and limits, market introduction and change status, data paths, incidents and escalation contact. Missing downstream documentation blocks approval or switching.

09 Reporting

Report errors, risks and rights concerns

Incorrect, discriminatory or misleading outputs, security issues and suspected use beyond the intended purpose can be reported to kontakt@kasp.ai . For important decisions, a competent person should always review sources, context, uncertainties and possible counterarguments.

Kasp documents the report, containment, human assessment, any suspension or withdrawal, and necessary escalation to model providers, customers or authorities. This readiness process asserts neither that a reportable serious incident has occurred nor that it replaces assessment of the applicable statutory deadline.

Information on personal data processing is set out in the Privacy Policy. Contractual limits are set out in the Terms. Binding limits of use are set out in the Acceptable Use Policy.

10 Sources

Official sources

This page provides product-specific transparency information, not a conclusive official classification. Classification must be reassessed when the purpose, user group, data, model or decision-making impact changes. The European Commission's final guidelines on high-risk classification were not yet available on 31 August 2026; a draft had been published.