Compliance with the EU AI Act
v1.0.02026-08-20Draft
What this document is, and what it is not. It is the public version of our classification assessment, the one Article 6(4) of Regulation (EU) 2024/1689 requires us to document before putting a system into service and to hand over if an authority asks for it.
It is derived from the internal record of each system; it is not written separately. That rule is deliberate: a hand-written public version of something declared internally becomes a second truth that diverges the same day.
If what you want is what this means for you as a user, the page is How DOPPLOS’s AI works. This one is the formal record.
This document is not final: it is pending legal review.
0. What is already in place, in one page
This summary does not replace the sections that follow: it condenses them. Every claim here is developed further down, with its article and its table.
All eight DOPPLOS AI systems are identified, classified and dated. None is running without a record. Article 6(4) requires that assessment to be documented before a system is put into service, and handed over if an authority asks for it: it exists, it is dated, and it gets handed over.
None of them is high-risk, and we explain why. All eight areas of Annex III are worked through one by one, not just the convenient ones. None applies, which is why the Article 6(3) clause never fires: the one that makes any Annex III system high-risk whenever it profiles natural persons.
No input is biometric, and an automated check watches that. Half the classification hangs on it: nothing infers from a face, a voice or a body. What the system knows about you comes from what you write and configure. It is not left to anyone’s memory: if a biometric input appeared in any of the eight systems, the check fails.
All eight Article 5 prohibitions are answered, including the ones that do not apply. And where one genuinely came close, the system was redesigned rather than argued around: section 5 sets out which element of Article 5(1)(a) made it fall inside, and what was changed so that element no longer holds.
Your Twin does not carry your personal data with it. Your email, your phone, your exact location and your surname never reach the model or the other person. Section 6 lists, field by field, what the AI receives and what it does not.
There is human oversight and a complaints route that reaches a person, not a form that goes nowhere. It is in section 8.
Staff operating these systems have documented training on what each one does and what its limits are, which is what Article 4 requires.
And one thing this document does on purpose: section 10 states what remains open, with dates. A compliance page that only shows finished work is not a compliance page, and anyone reading it seriously (a regulator, an investor, an app store) will look for exactly that. We would rather they find it written by us.
1. The role we play
Under the Regulation we are both at once, and the obligations stack:
- Provider (Article 3(3)): we develop the systems and put them into service under our own name.
- Deployer (Article 3(4)): we operate them in production.
Two things that are commonly assumed the other way round:
- A free tier does not exempt us. The definition says expressly “whether for payment or free of charge”.
- Third-party models do not either. Chapter V obligations fall on whoever provides the model; we are providers of systems built on top of one.
2. The eight systems
DOPPLOS operates eight AI systems. All eight pass the Article 3(1) test (they infer from the input how to generate outputs) and are therefore within the scope of the Regulation.
| System | What it does | High-risk | Article 5 | Article 50 |
|---|---|---|---|---|
| Avatar conversation | Talks to other avatars on your behalf | no | redesigned on 2026-08-20 | 50(1) partial |
| Compatibility assessment | Scores two profiles from 0 to 100 | no | ✅ | its reasoning not yet marked |
| Reading the other party | Writes what your avatar believes about them | no | ✅ | ✅ |
| Handover to human chat | Estimates whether two people should talk | no | ✅ | together with 50(1) |
| Safety moderation | Flags content that may break our rules | no | ✅ | ✅ |
| Per-chat personality | Writes the avatar’s intent within one chat | no | redesigned on 2026-08-20 | ✅ |
| Avatar personality | Writes how your avatar speaks | no | ✅ | ✅ |
| Avatar illustration | Turns a photo into a drawing | no | ✅ | 50(2) unverified |
Six further modules are NOT AI systems and therefore fall outside the Regulation entirely: candidate pre-filtering, the arithmetic score, the feed refresh, nudge delivery, demonstration account generation, and instruction assembly. None of them infers: they are queries, formulas and rules written by people, and Recital 12 excludes them expressly. We say so because half the classification hangs on that statement, and because it is the first one a third party will ask to verify.
3. None is high-risk, and why that can be asserted
The eight areas of Annex III, one by one:
| Annex III | Area | Applies? |
|---|---|---|
| 1(a) | Remote biometric identification | No. No system identifies anyone biometrically |
| 1(b) | Biometric categorisation by sensitive attributes | No. The avatar illustration is the only thing that sees a face, and it produces a drawing, not an attribute |
| 1(c) | Emotion recognition | No. Article 3(39) requires the inference to start from biometric data; ours starts from written text |
| 2 | Critical infrastructure | No |
| 3 | Education and vocational training | No |
| 4(a) and 4(b) | Employment, recruitment, worker management | No. DOPPLOS does not assess anyone for a job |
| 5 | Essential services, creditworthiness, emergencies | No |
| 6, 7 and 8 | Law enforcement, migration, justice | No |
Because none falls within Annex III, the Article 6(3) clause is not triggered. That clause, “an AI system referred to in Annex III shall always be considered high-risk where it performs profiling of natural persons”, only reaches systems already within one of the eight areas. DOPPLOS profiles, and heavily, but it does so outside them.
And we say out loud what this rests on. The whole classification rests on no input being biometric. The day audio or video of a person entered the conversation or the reading of the other party, DOPPLOS would become high-risk, and with it Articles 9 to 15, 27 and 49. We do not leave that to anyone’s memory: an automated check fails if a biometric input appears in any of the eight.
4. The eight prohibitions of Article 5
All of them are answered, including those that do not apply, because a classification that only answers the comfortable questions is not a classification.
| Article 5(1) | Prohibition | Our answer |
|---|---|---|
| (a) | Subliminal, manipulative or deceptive techniques | We had a real problem here and we redesigned it. See section 5 |
| (b) | Exploiting vulnerabilities due to age, disability or situation | The service is 18+ only, and no system uses age or economic situation as a behavioural criterion. Formal measurement pending |
| (c) | Social scoring | No. The compatibility score is computed and used within the same service and for its purpose; it does not travel across contexts nor produce disproportionate detrimental treatment |
| (d) | Predicting the risk of someone committing an offence | Not applicable. No system does this |
| (e) | Building facial recognition databases by untargeted scraping | No. The illustration processes only the photo uploaded by its own subject, and no facial database is built. Demonstration account photos come from a stock image bank and pass through no model |
| (f) | Inferring emotions in the workplace or in education | Not applicable. Neither context |
| (g) | Biometric categorisation to infer race, religion, opinions, sex life or sexual orientation | No. See section 6 |
| (h) | Real-time remote biometric identification for law enforcement | Not applicable |
5. What we found and changed: Article 5(1)(a)
We tell this because hiding it would be worse, and because the Regulation penalises misleading information separately.
What we measured on 2026-08-20: the platform had 20 real people and 6,590 demonstration accounts, and 164 out of every 165 matches involving a real person were against an account with nobody behind it. Nothing signalled this, and in three cases someone was invited to talk “directly with the person” behind an account that had no person.
Which element of the prohibition we broke. Article 5(1)(a) requires all its elements to be present: a deceptive technique, material distortion of behaviour, impairment of informed decision-making, and significant harm. It is enough that one is absent. We broke the deceptive character, which is the cleanest and also improves the product:
- Demonstration accounts identify themselves as such to the application, so they can be seen before any decision is made.
- Nobody is ever invited to talk “with the person” behind a demonstration account.
- A demonstration avatar’s intent is no longer built out of your profile.
- Turns spent against a demonstration account do not consume paid quota.
The product goal was untouched. It existed so the service would not feel empty and so the engine had someone to run against, and that still holds.
What is missing, with its date: the label has to be visible in the application. It is specified and has been requested from the application team. A change nobody can see does not break the deceptive element: the rule catches conduct “with the objective, or the effect”.
6. What data the AI receives, and what it never does
This is the most asked-about table, and it comes from reading what actually enters each model, not from what we assume enters it.
| Does reach the model | Never reaches it |
|---|---|
| The avatar’s name (not yours) | Your real name |
| Your age | Your email address |
| The genders you are interested in, because you declared them | Your phone number |
| What you are looking for, your occupation, your education | Your exact GPS coordinates |
| Your interests and bio, as you wrote them | Your password |
| Your star sign | Your payment method |
| The approximate distance to the other person | Your address |
| The turns of the conversation between avatars | Your photos, except in the avatar illustration |
Why that boundary exists. Your avatar needs an identity in order to converse (that is the product), but it never needs your civil identity. The data that would let someone locate you, impersonate you or charge you does not travel to the model, and the systems that touch that data are not AI systems.
And the case that decides the whole classification: your orientation reaches the model because you wrote it in your profile, not because anyone inferred it from your face. Inferring it from a face, a voice or a body is exactly what Article 5(1)(g) prohibits, carrying the highest fine in the Regulation. No photo enters the compatibility assessment, the reading of the other party, or the conversation.
7. Transparency (Article 50)
| Obligation | Status |
|---|---|
| 50(1) · that people know they are interacting with an AI | Partial, and we say so. The product presents itself as AI avatars, and an avatar asked whether it is one admits it straight away. But the conversation does not yet carry a visible notice inside the application: it is specified and requested |
| 50(2) · machine-readable marking of synthetic text | Done. Every message we deliver states whether a model wrote it and which one, in the data itself, not on the screen |
| 50(2) · marking of the generated image | Unverified. The model embeds its own, but we have not checked that it survives our saving step, so we do not claim it |
| 50(5) · clear, distinguishable and accessible information | Depends on the point above |
8. Human oversight and complaints
- No automated decision restricts or closes an account. Since 2026-08-20 the moderation system proposes; a person reviews before it takes effect.
- You can request human review of any automated outcome by writing to legal@dopplos.com. That is your right under Article 22 GDPR.
- The full complaints route is at Contact and complaints.
9. AI literacy (Article 4)
Article 4 requires those operating these systems to know what they do and what their limits are. We keep an internal document covering the eight systems, what each one does, its limits and who supervises it, reviewed every quarter.
10. What remains open, stated with its date
We publish this because a compliance page that only shows finished work is not a compliance page.
| Open | Since |
|---|---|
| The visible AI notice inside the application (Art. 50(1)) | 2026-08-20 |
| Making the demonstration-account label visible in the application | 2026-08-20 |
| Verifying that the generated image’s mark survives saving (Art. 50(2)) | 2026-08-20 |
| Marking the compatibility assessment’s reasoning | 2026-08-20 |
| Formal measurement of Article 5(1)(b) | 2026-08-20 |
| Legal review of this document | 2026-08-20 |
11. References
- Text applied: Regulation (EU) 2024/1689, Official Journal version of 12 July 2024. Applicable since 2 August 2026.
- Date of this assessment: 2026-08-20.
- Contact: legal@dopplos.com.
If you are an authority and want the full per-system classification documentation, request it at that address: it exists, it is dated, and it will be provided.