EU AI Act Compliance
Last updated: June 2026
The EU AI Act (Regulation (EU) 2024/1689) sets rules for artificial intelligence systems placed on the EU market. Insight Squid uses AI to assist researchers with transcription, summarisation, and thematic analysis. This page explains how we meet our obligations under the Act and what you need to know as a researcher.
1. How We Use AI in the Platform
Insight Squid integrates AI for the following helper functions:
Speech-to-text transcription – converting audio and video recordings into text via Speechmatics.
Session summarisation – generating concise overviews of what was discussed via Together.ai.
Thematic analysis – suggesting common topics, patterns, and sentiment across sessions via Together.ai.
These features are designed to reduce manual work for researchers. They do not replace human judgment, and they do not make autonomous decisions about participants.
Human oversight is mandatory by design. Every AI output is presented to a researcher for review, editing, and approval before it is used in any report, insight, or decision.
2. Risk Classification and Our Position
Under the EU AI Act, AI systems are classified by risk level. We do not believe our AI features fall into the "high-risk" categories because:
We do not use AI for biometric identification in real-time or remote biometric identification.
We do not use AI to make decisions about recruitment, employment, credit scoring, or access to essential services.
We do not use AI for social scoring or subliminal techniques.
Our AI operates as a research assistant, not an autonomous decision-maker.
We classify our AI features as limited-risk (transparency obligations) or minimal-risk, depending on the specific use case. We comply with the transparency requirements in Article 50 regardless of classification as a matter of best practice.
3. Transparency Obligations
We meet transparency obligations in the following ways:
Clear disclosure to researchers: AI-assisted features are labelled in the interface. Researchers know when a transcript, summary, or theme suggestion has been AI-generated.
Clear disclosure to participants: We recommend (and provide template language for) researchers to inform participants that sessions may be transcribed and analysed using AI. This is included in our consent guidance.
No hidden AI: We do not process participant data through AI systems without the researcher's explicit initiation or awareness.
4. Human Oversight
The EU AI Act requires that high-risk and certain limited-risk AI systems allow effective human oversight. We go further:
Researchers can edit, reject, or regenerate any AI output.
AI-generated quotes and themes are linked back to source timestamps so researchers can verify accuracy.
Observers and stakeholders see only what the researcher chooses to share; raw AI outputs are never automatically published.
Researchers can disable AI features entirely at the project or organisation level.
5. Data Quality and Governance
AI outputs are only as good as the inputs. We maintain data quality through:
Using reputable, commercially established AI providers (Speechmatics, Together.ai) with their own data governance and security certifications.
Processing data within the UK/EU or under Standard Contractual Clauses for any necessary transfers.
Regular testing of transcription accuracy across common accents and audio qualities.
Video recordings and AI outputs are stored for a maximum of 12 months, after which they are automatically deleted.
Your research data is never used to train AI models. We have contractual agreements with our AI providers that prohibit them from using your recordings, transcripts, or any research content to train, fine-tune, or improve their models. All research data is processed solely to generate outputs for your project and is never retained or used for model training.
Privacy by design: For participants recruited through the platform, we collect only surname, email address, and contact number. This information is hidden from researchers and used solely for recruitment, scheduling, and on-platform messaging. No other identifiable information is captured about participants. All researcher-participant communication happens through the platform's built-in messaging system.
6. Accuracy, Robustness, and Limitations
We are transparent about what our AI can and cannot do:
Transcription accuracy varies with audio quality, background noise, overlapping speech, and strong accents.
Summaries may miss nuance, sarcasm, or culturally specific references.
Theme suggestions are statistical patterns, not definitive truths. A theme appearing in AI output does not mean it is the most important finding.
AI does not understand context the way a human researcher does. It cannot infer intent or emotion with certainty.
Do not rely solely on AI outputs for high-stakes decisions. Always verify AI-generated content against the original recordings and your own research expertise before including it in reports shared with stakeholders or used to influence product, policy, or design decisions.
7. No Fully Automated Decision-Making
Insight Squid does not make fully automated decisions that produce legal effects or similarly significant effects on participants. Our AI does not:
Score, rank, or profile participants for employment, credit, or benefits.
Determine whether a participant is eligible for a reward, incentive, or opportunity.
Make any decision that affects a participant's rights or interests without a human in the loop.
Researchers may use screeners (short questionnaires) to help select suitable participants for a study. These screeners are set and reviewed by human researchers. They are not AI-driven and do not constitute automated decision-making under the EU AI Act. Screener responses are retained only for the duration of the study and are deleted once the study is complete.
8. Record-Keeping and Accountability
We maintain technical documentation of the AI systems we integrate, including their intended purpose, known limitations, and performance metrics.
We keep logs of AI processing for audit and debugging purposes, subject to our 12-month data retention limit.
We review AI provider terms and capabilities regularly to ensure continued compliance as the AI Act is enforced.
9. What Researchers Must Do
As the deployer of the AI (in the research context), you share responsibility for compliance:
Inform participants that AI will be used for transcription and analysis as part of your consent process.
Review and verify all AI outputs before using them in reports or decisions.
Do not use Insight Squid AI for purposes that would classify the system as high-risk (e.g., automated hiring decisions, social scoring) without our prior written agreement and a full conformity assessment.
Report any serious incidents or malfunctions (e.g., AI generating harmful or discriminatory content) to us immediately.
10. Contact
If you have questions about our AI Act compliance, or if you need additional documentation for your own conformity assessment, contact us at legal@insightsquid.com.