Skip to content

EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) governs the provision and use of AI systems in the European Union. This page describes noris’s role within this regulatory framework, as well as the obligations that apply to our customers as operators of their own applications.

noris operates the AI infrastructure and provides access to models via standardized API endpoints. Within the EU AI Act, noris takes on the role of distributor. noris is explicitly not the provider (model developer) and not the entity placing the models on the market.

This clear separation is essential for assigning obligations: noris is responsible for infrastructure, API access, and transparency of model selection, while model development remains with the respective provider.

All models offered on the noris platform are General Purpose AI Models (GPAI). Under the EU AI Act, the models are classified as follows:

AttributeValue
ClassificationGPAI (General-Purpose AI Model)
Risk levelLimited Risk (Article 52)
Transparency obligationYes

None of the offered models are classified by noris as high-risk systems. However, classifying a specific use case always remains your responsibility as deployer.

noris’s Transparency Obligations as Distributor

Section titled “noris’s Transparency Obligations as Distributor”

As distributor, noris fulfills the following transparency obligations:

  • Model cards for all offered models, uniformly structured, with technical specifications, use cases, and limitations
  • Links to original sources: HuggingFace pages, license texts, and technical reports from the respective providers
  • Traceability of model selection: every model decision is documented and justified
  • Infrastructure documentation: locations, security certifications, and data processing are transparently disclosed
RoleWhoObligations
DistributornorisInfrastructure, API access, model cards, transparency
ProviderModel developer (OpenAI, Google, etc.)Model documentation, training-data disclosure
DeployerYour companyUse-case risk assessment, transparency toward end users, logging

For limited-risk systems, the central obligation is transparency toward end users (“you are interacting with AI”). Through the OpenAI-compatible APIs, noris provides the building blocks needed to easily integrate these notices into existing interfaces.

Should you pursue a use case classified as high-risk, noris supports you with the technical requirements:

  • Data governance: vector databases remain under your full control; noris never persists prompts or results.
  • Logging: all API requests can be fully logged by you, since noris itself doesn’t persist any content (zero-data-retention).
  • Human oversight: the APIs serve as building blocks for human-in-the-loop processes; final decisions remain with humans.

Details on all models and their individual risk assessments are available under Models.

  • Regulation (EU) 2024/1689