Where Bernio sits under the AI Act, and where you do.
Most of the Act’s obligations fall on you, the deployer — not on us. This page states our own classification, what we carry, what you carry, and what we hand you for your file.
We are the provider. You are the deployer.
That distinction decides almost every obligation under the Act, and vendors are often vague about it because the deployer side is the larger half. It is yours, and pretending otherwise would leave a gap in your file rather than in ours.
Provider
Bernima Inc.
We develop Bernio and place it on the Union market under our own name, which makes us a provider of an AI system within the meaning of the Act. Being established in the United States does not change that where the system is used in the Union.
- Technical documentation and instructions for use
- Transparency about what is AI-generated, under Article 50
- Logging capability sufficient for you to meet your own record-keeping duties
- Accuracy, robustness and cybersecurity appropriate to the intended purpose
- Cooperation with your assessments, and notification of relevant changes
Deployer
Your firm or department
You use Bernio under your own authority, in the course of your professional activity. That makes you a deployer, and it is where the operational obligations sit — the ones about oversight, competence and how the output is actually used.
- Use the system in accordance with the instructions for use
- Assign human oversight to people with the competence, training and authority to exercise it
- Ensure input data is relevant and sufficiently representative for your purpose
- Retain logs for the period required for your use
- Inform affected persons where the Act requires it
- AI literacy among staff dealing with the system, under Article 4
Substantial modification
Where the line moves
A deployer can become a provider. If you put your name on the system, change its intended purpose, or substantially modify it, the Act treats you as a provider for that system — with the obligations that follow.
- Configuring agents, policies and templates inside Bernio does not do this
- Re-purposing outputs into a use we have not documented may
- Tell us before you do, and we will document the change with you
Our own reading, including where it is not clean.
Prohibited practices (Art. 5)
Not applicableNo. Bernio performs no social scoring, no emotion inference in work or education, no biometric categorisation, and no predictive policing on individuals.
General-purpose AI model provider
Not applicableNo. We train small models for specific legal tasks rather than general-purpose models, and we do not place a GPAI model on the market as such.
High-risk under Annex III
DependsDepends on your deployment. Bernio used by a law firm or in-house team on its own matters is not administration-of-justice use within Annex III point 8(a). Bernio deployed by or on behalf of a judicial authority to assist in researching or interpreting facts and law may fall within it — and we will say so, in writing, before that deployment rather than after.
Transparency obligations (Art. 50)
AppliesYes, and they apply now. Bernio generates synthetic text, so output is marked as machine-generated and identifiable as such, and the interface states what was model-generated, what was retrieved, and what a person confirmed.
AI literacy (Art. 4)
DependsYours, and we support it. The obligation to ensure a sufficient level of AI literacy sits with you as deployer; onboarding, the instructions for use and the governance metrics exist to make it evidenceable.
What applies now, and what moved.
The Digital Omnibus on AI deferred the high-risk obligations six days before they were due to apply. The transparency duties were not deferred.
| Date | Obligation | Status | Note |
|---|---|---|---|
| 2 Feb 2025 | Prohibited practices and AI literacy | In force | In force. Article 4 AI literacy is a deployer duty and applies to your staff, not to us. |
| 2 Aug 2025 | GPAI obligations and governance | In force | In force. We are not a GPAI model provider; the frontier models we can route to are. |
| 2 Aug 2026 | Article 50 transparency | In force | In force now. Not deferred by the Digital Omnibus, apart from a narrow carve-out for systems already on the market. |
| 2 Dec 2026 | Art. 50(2) marking for pre-existing generative systems | Upcoming | Machine-readable marking of synthetic output for generative systems placed on the market before 2 August 2026. |
| 2 Dec 2027 | Annex III high-risk obligations | Deferred | Moved from 2 August 2026 by Regulation (EU) 2026/1744, in force 27 July 2026 — six days before the original date. |
| 2 Aug 2028 | Annex I embedded high-risk | Deferred | AI embedded in products already covered by EU product-safety law. |
The architecture already produces most of the file.
None of this was built for the Act — it was built because supervision and provenance are what legal work requires. It happens to be what a deployer is asked to demonstrate.
Art. 14 · Art. 26(2)
Human oversight
Approval is a state the matter is in, not a habit. An agent cannot act on a matter until a named practitioner is bound to it, and no output reaches a client without that person releasing it. The oversight is enforced in the runtime, so evidencing it is a query rather than an attestation.
Art. 12 · Art. 26(6)
Record-keeping and logs
Append-only and signed: who ran what, on which matter, with which model version, and who approved it. In on-premise deployments the log sits in your environment and retention is yours to set; on the hosted tier retention is contractual and the log is exportable in full.
Art. 50
Transparency of output
The interface distinguishes what was model-generated, what was retrieved from a real corpus, and what a person has confirmed. Citations carry their verification state.
Art. 15
Accuracy and robustness
Retrieval grounding for authorities, refusal and logging of out-of-scope requests, and governance metrics — four-eyes pass rate, citation verification, escalation rate — computed from your own audit trail rather than a vendor benchmark.
Art. 10 · GDPR Art. 5
Data governance
Matter-scoped retrieval with ethical screens applied, memory provisioned per matter and sealed at close, and no client data in training or fine-tuning of any model.
Art. 11 · Annex IV
Technical documentation
Instructions for use, the deployment architecture for your tier, and the model and subprocessor inventory — sent on request, without an NDA. The Trust Center that will publish them opens shortly.
Read it yourself.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), text on EUR-Lex
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 as regards simplification (Digital Omnibus on AI), OJ 24 July 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation), consolidated text on EUR-Lex
Reviewed 22 August 2026
This page states our own classification and is not legal advice. AI regulation is moving quickly — the high-risk deadline moved six days before it was due to apply — so we date this page and re-check it. If you are assessing Bernio for a specific deployment, ask us and we will put the analysis for that deployment in writing.
The infrastructure your practice deserves.
We are taking on design partners: firms that run real matters through Bernio, shape what gets built next, and come in on founding terms. We run the demo on a matter type your team handles.
