API documentation

EU AI Act

Our position under Regulation (EU) 2024/1689, on one page. Provider self-assessment of 8 July 2026, restated for publication on 2 September 2026.

Roles

  • Stonewake is the provider of an AI system that is not high-risk. The system integrates general-purpose language models through their providers' interfaces, behind a provider-neutral seam; the model providers' own duties under the Regulation stay with them. The model endpoint is modular by design, and an EU endpoint is a configuration change.
  • Your institution is the deployer. The intended purpose is research and monitoring over public sources about organizations and countries, plus bank-instructed adverse-media screening of natural persons in their professional capacity as a customer due diligence measure. Excluded uses: creditworthiness evaluation of natural persons, employment or tenant screening, sanctions or PEP list checks (no person or organization is screened against a list; country-level list memberships feed the country score only), and any decision without human review. A deployer that repurposes the system takes on the provider's obligations for that use (Art. 25).

Why Annex III does not apply

Annex III 5(b) covers systems that evaluate the creditworthiness of natural persons or establish their credit score. Stonewake does neither: scores apply to organizations and countries only, no person-level score, rating or ranking exists anywhere in the product, and the build fails if a person-typed surface acquires one. Person screening returns cited findings and draft verdicts that an analyst must confirm or dismiss; the system takes no decision and executes no action.

Transparency (Art. 50)

  • AI involvement is disclosed in the product: the dashboard states that research content is AI-assisted, and AI-drafted memos carry a label.
  • Machine-readable marking of AI-drafted text in API responses and exports is in progress. Until it ships, AI-drafted content is identified by its visible label and by this documentation.

AI literacy (Art. 4)

  • What the model does: it extracts, verifies and drafts text over fetched public sources. Its outputs are draft findings, draft verdicts and memo text, each tied to the sources it was given.
  • What the deterministic gates do: a claim that cannot be matched verbatim to its source text is escalated or suppressed; scores ship with their per-component breakdown, weights and citations, computed from rubrics that are inspectable data; no person-level score can be built; every external call runs under budget and rate guards; the review ledger is append-only. A reported figure is accepted only when its amount, scale and currency are stated in the quoted source text, and the model cannot overrule that check.
  • What the analyst must do: read the cited source before relying on a finding, confirm or dismiss every draft verdict, and treat every output as research input to a human decision, never as the decision.

Review

This page is reviewed with every material change to the model integration or the intended purpose. The internal self-assessment, including the intended-purpose boundary and the human-oversight measures, is available to customers on request.

Related: Security overview, Data handling, API security.