Policy 05
EU AI Act Compliance Policy
Purpose & scope
This policy sets out how WinguSuite ensures any use of artificial intelligence in, or alongside, the services is responsible and consistent with Regulation (EU) 2024/1689 (the EU AI Act). It applies to AI functionality we provide or operate and to AI tools used by our ICT team.
Risk-based approach
- Unacceptable risk — practices prohibited by the Act are not used.
- High risk — enhanced controls: risk assessment, human oversight, logging and documentation.
- Limited risk — transparency, so people know when they are dealing with AI.
- Minimal risk — standard security and acceptable-use controls.
Governance & human oversight
A human remains responsible for decisions supported by AI; AI does not make final decisions with legal or similarly significant effects without human review.
Monitoring of AI activity
AI-related activity is monitored using the Acronis GenAI Protection module together with Acronis EDR and MDR, giving visibility of generative-AI and AI-driven activity, detection of misuse, and response as part of wider security operations.
Transparency & data protection
Where people interact with an AI system or AI-generated content, we provide appropriate information. AI use is subject to our GDPR and Information Security policies.