> For the complete documentation index, see [llms.txt](https://docs.ionos.com/cloud/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ionos.com/cloud/ai/ai-model-hub/governance-and-compliance/eu-ai-act.md).

# European Union AI Act

This page outlines the compliance framework of the <code class="expression">space.vars.ionos\_cloud\_ai\_model\_hub</code> in relation to the European Union's (EU) AI Act. It details our responsibilities as a service operator, the different roles we hold under the Act, and the technical foundation our platform provides for you to meet your own regulatory obligations.

{% hint style="info" %}
**Note:** Article 50 of the EU AI Act requires the marking of AI-generated content. AI Model Hub constitutes an AI system within the meaning of Regulation (EU) 2024/1689, of which <code class="expression">space.vars.ionos\_cloud</code> is the provider. We are implementing the machine-readable marking and detection measures required under Article 50(2) for generative models, together with the corresponding documentation, in line with the transitional period applicable to AI systems placed on the market before 2 August 2026. This page will be updated as those measures become available per media type.
{% endhint %}

## Service infrastructure and data protection

A core component of AI Act compliance is data governance and security. Our platform is built on the following principles:

* **EU Data Residency and Sovereignty:** All AI Model Hub services, including model inference endpoints, are hosted in <code class="expression">space.vars.ionos\_cloud</code>'s ISO 27001-certified data centers in Germany.
* **GDPR Compliance:** All data processing is fully compliant with the EU's General Data Protection Regulation (GDPR / DSGVO).
* **Data Processing:** Customer data, including API-sent prompts, inputs, and any files sent as part of a request, is processed exclusively for the provision of the service. In line with our Data Processing Agreement (DPA), this data is not used for training, fine-tuning, or otherwise improving any AI models. For a detailed breakdown of our data handling policies, see [<mark style="color:blue;">Data Handling</mark>](/cloud/ai/ai-model-hub/governance-and-compliance/data-handling.md).

## Roles and responsibilities under the EU AI Act

Under the AI Act, an entity's obligations depend on its role in the value chain. In the AI Model Hub, three parties each hold a role, and all three apply at the same time: the developers of the models, <code class="expression">space.vars.ionos\_cloud</code>, and you as our customer. The roles and responsibilities of the model developers and <code class="expression">space.vars.ionos\_cloud</code> are set out below; your own role as deployer follows in the next section.

### Role 1: The model developers are the providers of the AI models

The open-weight models available on the hub are developed and published by third parties. Those developers are the providers of the general-purpose AI model and hold the obligations attached to the model itself under Article 53 of the AI Act: the model's technical documentation, the information to be made available to downstream providers, a policy to comply with Union copyright law, and a publicly available summary of the content used for training.

These obligations rest with the developer; we do not verify or warrant the completeness of their Article 53 documentation. Our role is to make that information readily available, so you can assess it directly from the developer's own published sources. This includes:

1. **Providing Model Documentation:** Each model has a dedicated documentation page that provides a summary and specifications.
2. **Linking to Authoritative Sources:** These pages include direct links to the model's published model card and license. This allows you to access the authoritative technical information, including details on training data, capabilities, and limitations, as published by the original developer. Use this original documentation to inform your own compliance assessment.

### Role 2: IONOS CLOUD is the provider of the AI system

AI Model Hub constitutes an AI system within the meaning of Regulation (EU) 2024/1689. We deploy the models on infrastructure we operate and make the service available under our own name through our own API; on that basis <code class="expression">space.vars.ionos\_cloud</code> is the provider of the system within the meaning of Article 3(3). This applies to every model in the catalogue, irrespective of whether we modify it.

Where we modify a model, we document the modification:

1. **Traceability:** Our documentation clearly identifies the original base model and the nature of the modification we performed.
2. **Technical Documentation:** We publish our own technical documentation for the modified model. This includes the results of our internal performance and quality benchmarks, which serve to verify that our quantization process delivers performance efficiencies while maintaining the model's accuracy and robustness relative to the original.

### Article 50: transparency for AI-generated content

Article 50(2) places the obligation to mark synthetic output in a machine-readable format on the provider of the AI system. See the notice at the top of this page for the current status.

Other obligations under Article 50 fall on you as the deployer of your own application: disclosing to natural persons that they are interacting with an AI system (Article 50(1)); informing persons exposed to an emotion recognition or biometric categorization system (Article 50(3)); and labeling deep fakes and AI-generated text published to inform the public on matters of public interest (Article 50(4)).

## Enabling your compliance as a developer and Deployer

As a user of the AI Model Hub, you will be a **Deployer** or may become a **Provider** of your own AI system. You are responsible for conducting your own risk assessment to determine if your specific application qualifies as Limited-Risk or High-Risk under the Act's criteria.

Our platform provides the necessary technical infrastructure to help you implement the controls required for your specific classification.

{% tabs %}
{% tab title="For Limited-Risk Systems" %}
If your system, for example, a general-purpose chatbot, is deemed to be limited-risk, your primary obligation is transparency. Our standard REST APIs are designed to integrate seamlessly into your application, allowing you to build the necessary user notifications; for example, "You are interacting with an AI".
{% endtab %}

{% tab title="For High-Risk Systems" %}
If your application's use case falls into a high-risk category, such as employment, credit, or education, you have significant obligations. The AI Model Hub provides the flexible infrastructure to help you achieve the following:

* **Data Governance:** You retain full control over the data you send to the AI Model Hub, including any content you use for retrieval-augmented generation. You remain responsible for the quality, relevance, and bias-checking of your data; our platform ensures it is processed securely within our German data centers.
* **Logging and Traceability:** The AI Act requires that high-risk systems maintain event logs. While <code class="expression">space.vars.ionos\_cloud</code> does not provide a pre-configured AI Act logging template, our API-first platform allows you to log all API requests and responses using your own logging solutions to build a compliant audit trail.
* **Human Oversight:** High-risk systems must be designed for effective human oversight. Our APIs serve as flexible building blocks, allowing you to design and implement your own "human-in-the-loop" workflows, such as routing an AI-generated output for human approval within your application logic.
  {% endtab %}
  {% endtabs %}

## Summary of our compliance framework

The <code class="expression">space.vars.ionos\_cloud\_ai\_model\_hub</code> provides a secure, EU-based foundation for AI development that is compliant with the GDPR. We operate with transparency about how the roles are allocated: <code class="expression">space.vars.ionos\_cloud</code> is the provider of the AI system, the model developers are the providers of the AI models they publish, and you are the deployer and, depending on your application, the provider of your own AI system. This clear allocation, combined with our platform's technical capabilities, is designed to support you in meeting your own downstream compliance obligations.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ionos.com/cloud/ai/ai-model-hub/governance-and-compliance/eu-ai-act.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
