Skip to main content
Bernio
EU AI Act

Where Bernio sits under the AI Act, and where you do.

Most of the Act’s obligations fall on you, the deployer — not on us. This page states our own classification, what we carry, what you carry, and what we hand you for your file.

Who carries what

We are the provider. You are the deployer.

That distinction decides almost every obligation under the Act, and vendors are often vague about it because the deployer side is the larger half. It is yours, and pretending otherwise would leave a gap in your file rather than in ours.

01

Provider

Bernima Inc.

We develop Bernio and place it on the Union market under our own name, which makes us a provider of an AI system within the meaning of the Act. Being established in the United States does not change that where the system is used in the Union.

  • Technical documentation and instructions for use
  • Transparency about what is AI-generated, under Article 50
  • Logging capability sufficient for you to meet your own record-keeping duties
  • Accuracy, robustness and cybersecurity appropriate to the intended purpose
  • Cooperation with your assessments, and notification of relevant changes
02

Deployer

Your firm or department

You use Bernio under your own authority, in the course of your professional activity. That makes you a deployer, and it is where the operational obligations sit — the ones about oversight, competence and how the output is actually used.

  • Use the system in accordance with the instructions for use
  • Assign human oversight to people with the competence, training and authority to exercise it
  • Ensure input data is relevant and sufficiently representative for your purpose
  • Retain logs for the period required for your use
  • Inform affected persons where the Act requires it
  • AI literacy among staff dealing with the system, under Article 4
03

Substantial modification

Where the line moves

A deployer can become a provider. If you put your name on the system, change its intended purpose, or substantially modify it, the Act treats you as a provider for that system — with the obligations that follow.

  • Configuring agents, policies and templates inside Bernio does not do this
  • Re-purposing outputs into a use we have not documented may
  • Tell us before you do, and we will document the change with you
Classification

Our own reading, including where it is not clean.

Prohibited practices (Art. 5)

Not applicable

No. Bernio performs no social scoring, no emotion inference in work or education, no biometric categorisation, and no predictive policing on individuals.

General-purpose AI model provider

Not applicable

No. We train small models for specific legal tasks rather than general-purpose models, and we do not place a GPAI model on the market as such.

High-risk under Annex III

Depends

Depends on your deployment. Bernio used by a law firm or in-house team on its own matters is not administration-of-justice use within Annex III point 8(a). Bernio deployed by or on behalf of a judicial authority to assist in researching or interpreting facts and law may fall within it — and we will say so, in writing, before that deployment rather than after.

Transparency obligations (Art. 50)

Applies

Yes, and they apply now. Bernio generates synthetic text, so output is marked as machine-generated and identifiable as such, and the interface states what was model-generated, what was retrieved, and what a person confirmed.

AI literacy (Art. 4)

Depends

Yours, and we support it. The obligation to ensure a sufficient level of AI literacy sits with you as deployer; onboarding, the instructions for use and the governance metrics exist to make it evidenceable.

Dates

What applies now, and what moved.

The Digital Omnibus on AI deferred the high-risk obligations six days before they were due to apply. The transparency duties were not deferred.

DateObligationStatusNote
2 Feb 2025Prohibited practices and AI literacyIn forceIn force. Article 4 AI literacy is a deployer duty and applies to your staff, not to us.
2 Aug 2025GPAI obligations and governanceIn forceIn force. We are not a GPAI model provider; the frontier models we can route to are.
2 Aug 2026Article 50 transparencyIn forceIn force now. Not deferred by the Digital Omnibus, apart from a narrow carve-out for systems already on the market.
2 Dec 2026Art. 50(2) marking for pre-existing generative systemsUpcomingMachine-readable marking of synthetic output for generative systems placed on the market before 2 August 2026.
2 Dec 2027Annex III high-risk obligationsDeferredMoved from 2 August 2026 by Regulation (EU) 2026/1744, in force 27 July 2026 — six days before the original date.
2 Aug 2028Annex I embedded high-riskDeferredAI embedded in products already covered by EU product-safety law.
What you can evidence

The architecture already produces most of the file.

None of this was built for the Act — it was built because supervision and provenance are what legal work requires. It happens to be what a deployer is asked to demonstrate.

Art. 14 · Art. 26(2)

Human oversight

Approval is a state the matter is in, not a habit. An agent cannot act on a matter until a named practitioner is bound to it, and no output reaches a client without that person releasing it. The oversight is enforced in the runtime, so evidencing it is a query rather than an attestation.

Art. 12 · Art. 26(6)

Record-keeping and logs

Append-only and signed: who ran what, on which matter, with which model version, and who approved it. In on-premise deployments the log sits in your environment and retention is yours to set; on the hosted tier retention is contractual and the log is exportable in full.

Art. 50

Transparency of output

The interface distinguishes what was model-generated, what was retrieved from a real corpus, and what a person has confirmed. Citations carry their verification state.

Art. 15

Accuracy and robustness

Retrieval grounding for authorities, refusal and logging of out-of-scope requests, and governance metrics — four-eyes pass rate, citation verification, escalation rate — computed from your own audit trail rather than a vendor benchmark.

Art. 10 · GDPR Art. 5

Data governance

Matter-scoped retrieval with ethical screens applied, memory provisioned per matter and sealed at close, and no client data in training or fine-tuning of any model.

Art. 11 · Annex IV

Technical documentation

Instructions for use, the deployment architecture for your tier, and the model and subprocessor inventory — sent on request, without an NDA. The Trust Center that will publish them opens shortly.

Primary sources

Read it yourself.

Reviewed 22 August 2026

This page states our own classification and is not legal advice. AI regulation is moving quickly — the high-risk deadline moved six days before it was due to apply — so we date this page and re-check it. If you are assessing Bernio for a specific deployment, ask us and we will put the analysis for that deployment in writing.

Ready to Begin

The infrastructure your practice deserves.

We are taking on design partners: firms that run real matters through Bernio, shape what gets built next, and come in on founding terms. We run the demo on a matter type your team handles.

Read the security architecture