AI is a core part of what we build at WinSphere. That is why we set out concretely below who is responsible for what when we build an AI system for you, how we deal with risk classification, human oversight and transparency, and which principles we always apply.
Who is responsible for what?
WinSphere builds and delivers AI workflows, but does not put them on the market under its own name. In most assignments you, as the client, are the deployer under the EU AI Act (Regulation (EU) 2024/1689) for the system we build for you: you determine how and for what purpose it is used within your own organisation. We only act as a provider within the meaning of the AI Act if this has been agreed in writing in advance for a specific assignment, or when we are ourselves designated as a provider under Article 25 of the AI Act, for example if we substantially modify an existing high-risk system under our own name.
Risk classification
Some applications fall under the high-risk categories, such as AI in the recruitment and selection of candidates (Annex III, point 4 of the AI Act). Because you know best how and for what purpose the system is used, you are responsible for assessing whether this applies to your use case and for complying with the resulting obligations (Article 26 AI Act), including oversight by a natural person and keeping log files. We provide the technical information you need for this on request.
Humans stay in control
We build our systems with built-in checkpoints for human oversight, so that Article 14 of the AI Act can be complied with. Whether and how that oversight is set up and carried out within your organisation is up to you. That certainly applies to decisions that may affect people.
Transparency
We are transparent ourselves about where and how AI is used in the systems we build. Are you the one informing end users, candidates or other data subjects about AI use? Then that is, just as under the GDPR, your responsibility, including the obligations under Article 50 of the AI Act. We ourselves never have a direct relationship with them.
Principles we always apply
Data minimisation: we only process the data that is truly necessary and handle data with care. No black-box decisions without control: we build systems that are auditable and explainable, with human control over the outcomes. Foundation first: we only deploy AI once the underlying data and systems are in order. AI literacy: we make sure our own people have sufficient knowledge of AI and support you in meeting the AI literacy requirement of Article 4 of the AI Act within your organisation.
This policy is also contractually recorded in our terms and conditions. Questions about our AI use? Contact us at info@winsphere.ai.
WinSphereAI & automatisering die je laat groeien, zonder extra mensen aan te nemen.