Last updated: September 2026
Steelter uses its own AI agents to write action plans, interpretations and recommendations from SPA (Steelter Professional Assessment) profile data. This page explains what AI does on the platform, what it does not do, and how we govern it under the European AI Regulation.
Our commitment"Steelter operates AI classified as high-risk under the EU AI Act (Annex III — employment and workers' management) and governs it accordingly. We meet the obligations of the Regulation already in force: no prohibited practices (Art. 5), transparency about AI-generated content (Art. 50), and EU-based infrastructure and providers under the GDPR. Every AI output is a decision-support guide: the data is computed deterministically from the SPA profile, the AI only writes its interpretation, and no decision about people is automated. We are running a full conformity programme as a high-risk provider — technical documentation, risk management, human oversight and registration in the EU database — with a target date ahead of the legal deadline of 2 December 2027."
Regulation (EU) 2024/1689 classifies as high-risk the AI systems used in employment and workers' management (Annex III): evaluating candidates in recruitment and supporting decisions on promotion, role assignment or evaluation within the employment relationship. Steelter's use cases fall within that scope, and we treat them accordingly.
High-risk does not mean dangerous: it means the European Union considers this area serious enough to require safeguards. We take on that classification explicitly and govern the platform accordingly, rather than looking for a more convenient category.
The Regulation applies in phases. These are the obligations already in force and how we meet them:
| Obligation | How we meet it |
|---|---|
| Prohibited practices (Art. 5) | None. The SPA profile is questionnaire-based psychometrics: no emotion recognition, no social scoring and no automatic rejection of people. |
| Transparency of AI-generated content (Art. 50) | All AI-generated content carries a visible notice and machine-readable marking, both in the platform's panels and in exported PDFs. |
| Data protection (GDPR) | EU-based infrastructure and providers, data processing agreements with our sub-processors and an appointed external Data Protection Officer. |
Steelter's architecture separates two layers:
No output of the platform decides anything about a person on its own. No hiring, promotion, termination or role-assignment decision is automated, and the platform does not reject candidates. The HR professional reviews, cross-checks and decides, in line with the right not to be subject to decisions based solely on automated processing (Art. 22 GDPR).
Every AI-generated analysis, whether of a person or a group, is accompanied by this notice, visible on screen and in the PDF:
AI-generated reference profiles carry their own notice: in that case the AI does propose the competencies and their target values, so the profile must be reviewed and validated by the HR professional before it is used in any analysis.
The full set of obligations for providers of high-risk systems (risk management, technical documentation, human oversight, conformity assessment and registration in the EU database) becomes enforceable on 2 December 2027. Steelter is running a full conformity programme with a target date ahead of that deadline.
Much of what that package will require is already part of the platform's architecture: deterministic data, validation of AI outputs, traceability of every generation and human oversight by design. The work between now and 2027 is to complete and document a system that already exists.
If your compliance or procurement team, or your Data Protection Officer, needs more detail (system classification, sub-processor chain, data processing, retention and deletion, or answers to due-diligence questionnaires), write to us at info@steelter.com.