Voltar ao Trust Center
Em vigor desde: 2026-07-30
Disponível apenas em inglês. Este documento jurídico é fornecido em inglês como versão oficial. A interface do Trust Center está traduzida para o seu idioma.

EU AI Act Transparency: ISMS Copilot

Effective Date: 2026-07-30.

Purpose of this page

This page describes how Better ISMS (ISMS Copilot) approaches the transparency obligations of Regulation (EU) 2024/1689 (the EU AI Act), in particular Article 50. It is our public transparency statement for customers and evaluators. It is not a certificate of conformity, a regulator attestation, or legal advice.

Who we are and what we ship

ISMS Copilot is a family of B2B tools that help compliance and security professionals with guidance, document drafting, and related workflows. Relevant surfaces include:

  • The ISMS Copilot chat application (including logged-out free chat)
  • The embeddable chat widget
  • heyGRC (GitHub pull-request compliance review, by ISMS Copilot)
  • Optional Slack integration (heyGRC bot)
  • Related APIs and account integrations used by customer systems

These products use third-party general-purpose AI models. We do not train foundation models on customer conversations for our own model development. AI routing, retention, and sub-processors are described in the Privacy Policy, DPA, and the sub-processors section of this Trust Center.

Our current classification assessment

Under our current assessment of the EU AI Act:

  • Not a prohibited practice under Article 5 (we do not implement the banned categories such as social scoring or prohibited biometric identification).
  • Not high-risk under Annex III for the intended purpose of these products: advisory compliance guidance and code-review assistance for professional users. The human user remains responsible for decisions. The products do not make automated decisions about natural persons in employment, credit, education, law enforcement, migration, or similar Annex III contexts.
  • Article 50 transparency obligations apply (interaction disclosure and, for AI-generated synthetic content such as exported documents, machine-readable marking where required).

This is Better ISMS's current assessment, based on intended purpose and product design. It is not a determination by a market surveillance authority or the EU AI Office. If product purpose changes (for example, autonomous actions that decide or execute on behalf of a user without meaningful human review), we will reassess.

High-risk system obligations for Annex III use cases apply from 2 December 2027 under the AI Omnibus amendments (for stand-alone high-risk systems). That stack does not currently apply to ISMS Copilot under the assessment above.

How we inform users they are interacting with AI (Article 50(1) and 50(5))

SurfaceHow users are informed
Logged-in chatPersistent notice that ISMS Copilot is an AI assistant, with a "More info" dialog that states users are interacting with an artificial intelligence system and that outputs are AI-generated
Logged-out / free chatPersistent notice: users are interacting with an AI, with a link to this Trust Center
Embed widgetPersistent "AI-generated" notice in non-removable widget chrome, plus Privacy link
heyGRC on GitHubReviews posted by the heyGRC bot; review summaries identify heyGRC as AI agents for GRC engineering
Slack botMessages from the heyGRC bot in the customer's Slack workspace

Users remain responsible for reviewing outputs before relying on them for certification, audit, or regulatory purposes.

AI-generated documents and machine-readable marking (Article 50(2))

ISMS Copilot can generate text documents (for example policies and procedures) that users may download as DOCX, PDF, or Markdown.

Status (2026-07-30): Machine-readable marking of those export files is in progress. Systems already on the market before 2 August 2026 have a transitional period until 2 December 2026 for the Article 50(2) marking and detection obligation (AI Omnibus / Commission guidance). We are implementing export-time metadata marking (DOCX custom properties and PDF XMP) that does not pollute document titles or visible body text used by consultants.

Chat messages and UI disclosures above already identify AI involvement at the interaction layer (Article 50(1)). Article 50(2) is the separate file-level detectability control.

We will update this page when export marking is live.

What we do not claim

  • We do not claim ISO/IEC 42001 certification (we maintain an AI management system documentation set for our own operations; certification is a separate, later track after ISO 27001 readiness work).
  • We do not claim that any regulator has certified ISMS Copilot under the EU AI Act.
  • We do not claim that outputs are free of error or that they replace qualified professional judgment.

Customer and deployer responsibilities

If you integrate ISMS Copilot (API, embed, or similar) into a product that end users interact with, you must ensure those end users are informed they are interacting with an AI system where Article 50 requires it. Do not use ISMS Copilot outputs as the sole basis for automated decisions about individuals in Annex III high-risk contexts. Do not use the products for Article 5 prohibited practices.

Contact

Questions about this statement: contact@ismscopilot.com.

Last updated: 2026-07-30.