Roles, Responsibilities & Regulatory Notices
Last updated: August 2026
EVE is governance infrastructure — the customer is the decision-maker
EVE AI Core provides deterministic governance enforcement, signed decision evidence, and audit support for AI systems. EVE does not make credit, insurance, clinical, employment, or other regulated decisions. The customer that deploys EVE remains the controller and the regulated decision-maker, and is solely responsible for its own legal, regulatory, and policy obligations, including model-risk governance, configuration of policy packs, and the correctness of its decisions.
Consumer lending (FCRA / ECOA)
Where EVE governs lending or credit workflows, EVE is not a consumer reporting agency as defined in the Fair Credit Reporting Act, 15 U.S.C. § 1681a(f). EVE does not assemble, evaluate, generate, or furnish consumer reports or credit scores, and its governance outputs (for example, policy verdicts and signed evidence) are not consumer reports and are not "furnished" information within the meaning of the FCRA. The creditor customer retains sole responsibility for FCRA permissible purpose, accuracy and dispute handling, and for compliance with the Equal Credit Opportunity Act and Regulation B, including any adverse-action notice and the statement of specific reasons for a decision.
Healthcare
EVE is not a covered entity and, where it processes protected health information on a customer's behalf, acts only as a business associate under a signed Business Associate Agreement. EVE does not provide medical advice, diagnosis, or treatment and is not a substitute for professional clinical judgment.
EU AI Act (Regulation (EU) 2024/1689)
The customer is the provider or deployer of its own AI system, and those obligations remain with the customer. EVE supplies governance infrastructure and evidence that support them; it does not assume them, and it does not certify conformity.
EVE CoreGuard's decision path is deterministic: a proposed action is evaluated against a policy set and returns an allow, block, or modify disposition. No model inference takes place in that path. EVE is not a provider of a general-purpose AI model — it neither trains nor places a general-purpose model on the market, and it integrates whichever model the customer selects or supplies.
Where EVE is used as a component of a customer's high-risk AI system, EVE is a supplier of that component. Article 25 assigns the provider role by conduct, not by label: any distributor, importer, deployer or other third party — including EVE — becomes the provider of a high-risk system in its own right if it puts its name or trademark on that system, makes a substantial modification to it, or changes its intended purpose. On the deployments described here EVE does none of those things, and the customer's own deployment decisions determine whether the test is met on its side; but the test is the same test, and it applies to EVE on the same terms.
Which obligations apply depends on the role the customer holds, and the two sets are different. As a provider, the customer is responsible for classifying the system under Annex III, the conformity assessment, the Article 13 instructions for use, the Article 17 quality management system governing its own development and compliance organisation, the declaration of conformity and the CE marking. As a deployer, the customer is responsible for the Article 26 operational duties — using the system in accordance with the provider's instructions, assigning trained human oversight, ensuring input data it controls is relevant and sufficiently representative, monitoring operation, reporting serious incidents, suspending use where a relevant risk arises, informing workers before workplace use, and any Article 27 fundamental rights impact assessment where it applies. Article 25 is what can move a deployer or other downstream actor into the provider role.
EVE's logging, decision records, and signed evidence are intended to support the record-keeping and human-oversight obligations in Articles 12 and 14 under either role; they are inputs to the customer's assessment, not a substitute for it.
EVE has not appointed an authorised representative under Article 22 of the AI Act, and the GDPR representatives described below are not one. Article 22 obliges a provider established outside the Union to appoint an authorised representative before placing a high-risk AI system on the Union market. On the deployments described here the customer, not EVE, is that provider. The EU and UK representatives EVE has appointed are GDPR Article 27 representatives for data protection only; they hold no role under the AI Act. If a deployment would put EVE in the provider role, the Article 22 appointment is a separate obligation that has to be met before placement.
See the obligation mapping for how specific articles relate to EVE's capabilities, and the gap analysis for what EVE does not cover.
EU data protection
For personal data processed on a customer's behalf, EVE acts as a processor and the customer as controller, on the terms of the Data Processing Addendum. The Services are hosted in the United States. EVE has designated an EU representative and a UK representative under Article 27 of the GDPR and Article 27 of the UK GDPR; both are named, with their addresses and a contact route, in Section 7C of the Privacy Policy and in the DPA. Transfer safeguards and sub-processors are described in the DPA, the Privacy Policy, and the Sub-processor List. Customers requiring processing within the EU should use the customer VPC, private cloud, or on-premises deployment models.
Insurance, government, and other regulated use
For insurance underwriting and rating, government use, and other regulated contexts, the customer remains responsible for compliance with the applicable rules of its jurisdiction and regulator. EVE provides infrastructure and evidence; it does not certify compliance.
No reliance; no professional advice
EVE's outputs are provided for informational and governance purposes and must be validated within the customer's own compliance and risk framework. They are not legal, financial, medical, or regulatory advice, and are not a guarantee, certification, or warranty of compliance. See our Terms of Service and Disclaimer.
Contact
Compliance and regulatory questions: [email protected].