Imagicle AI transparency

(v2.4) EU AI Act - Classification Statement

1. Purpose and Scope

This document sets out Imagicle's classification of its AI-enabled products under Regulation (EU) 2024/1689 (the “AI Act”). It identifies, for each product, the applicable risk category and the resulting obligations, and it allocates those obligations between Imagicle (as provider) and the customer or partner (as deployer).

It is intended to be shared with customers and partners and to form part of Imagicle's contractual and compliance documentation. It provides a transparent, good-faith account of how Imagicle has classified each product and how responsibilities are shared across the AI value chain.

Products in scope. This statement covers the following Imagicle products and the AI functionality embedded in them: (i) Voice Analytics; (ii) AI Receptionist; (iii) Virtual Agent; and (iv) Advanced AI Analytics (together, the “Products”). Other Imagicle products and features that do not incorporate AI systems within the meaning of the AI Act are outside the scope of this statement.

Geographic and temporal scope. This statement applies where the Products are placed on the market or put into service in the European Union, or where their output is used in the Union. It reflects the AI Act and the related guidance available as of the date of last review and will be updated as implementation guidance, harmonised standards, codes of practice and the pending “AI Omnibus” amendments are finalised.

2. Imagicle's Role and Key Definitions

Imagicle as provider. Imagicle develops the Products and places them on the EU market under its own name and trademark. Imagicle is therefore a “provider” within the meaning of Article 3(3) of the AI Act with respect to the AI systems embedded in the Products.

Customer as deployer. A customer or partner that uses a Product under its own authority, in the course of its professional activity, is a “deployer” within the meaning of Article 3(4). Certain AI Act obligations – in particular some transparency duties under Article 50 – fall on the deployer rather than on Imagicle. Section 10 sets out this allocation in detail.

Key definitions used in this statement:

AI system – software that, for explicit or implicit objectives, infers from input how to generate outputs such as predictions, content, recommendations or decisions (Article 3(1)).

General-purpose AI (GPAI) model – an AI model that displays significant generality and can competently perform a wide range of distinct tasks, and that can be integrated into a variety of downstream systems (Article 3(63)). Chapter V regulates providers of such models.

GPAI system – an AI system based on a general-purpose AI model that has the capability to serve a variety of purposes (Article 3(66)).

Emotion recognition system – an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data (Article 3(39)).

3. Products in Scope

The following descriptions summarise the AI functionality of each Product for classification purposes.

3.1 Voice Analytics

Function. Voice Analytics processes recorded or live voice interactions to provide transcription (speech-to-text), keyword and topic detection, and conversation analytics (such as talk-time, silence and sentiment indicators) for quality-monitoring and business-insight purposes in contact-centre and unified-communications environments.

AI characterisation. Voice Analytics is an AI system. Its sentiment indicators are derived purely from lexical and statistical analysis of transcribed text; it does not infer a person's emotional state from biometric data (such as voice characteristics). Voice Analytics is therefore not an “emotion recognition system” within the meaning of Article 3(39). As a result, neither the Article 5(1)(f) prohibition nor the Article 50(3) disclosure obligation is engaged (see Sections 7 and 8). However, because Voice Analytics generates or manipulates synthetic audio and text output, it falls within the content-marking obligation in Article 50(2) (see Section 8.2).

3.2 AI Receptionist

Function. AI Receptionist is an AI-powered automated attendant that answers inbound calls, interprets caller intent using natural-language understanding, provides information, and routes or handles calls without a human operator.

AI characterisation. AI Receptionist is an AI system intended to interact directly with natural persons (callers). It therefore falls within the transparency obligation in Article 50(1) and, because it generates or manipulates synthetic audio and text output, also within the content-marking obligation in Article 50(2).

3.3 Virtual Agent

Function. Virtual Agent is a conversational AI agent (voice and/or chat) that interacts directly with end users to answer queries, provide information and complete tasks, and that may rely on generative AI to formulate responses.

AI characterisation. Virtual Agent is an AI system intended to interact directly with natural persons. It falls within Article 50(1) and, because it generates or manipulates synthetic audio and text output, also within the content-marking obligation in Article 50(2).

3.4 Advanced AI Analytics

Function. Advanced AI Analytics collects Call Detail Records (CDR) from the calling platform to produce dashboards and reports on call management, including the allocation of outgoing-call costs to a user, department or organisation. Users interact with it by describing, in natural language, the dashboard or report they require, which the system then generates.

AI characterisation. Advanced AI Analytics is an AI system: it infers from a natural-language request how to generate the corresponding dashboard or report. Its analytics are derived from call-detail metadata and do not infer any person's emotional state from biometric data; it is therefore not an “emotion recognition system” within the meaning of Article 3(39), and neither the Article 5(1)(f) prohibition nor the Article 50(3) disclosure obligation is engaged (see Sections 7 and 8). Its only interactive element is the prompt through which a customer's own users specify the outputs they want; it is not intended to interact with the public as a conversational agent, and it is obvious to those users that they are using an AI system, so the Article 50(1) interaction-disclosure obligation is not engaged. However, because Advanced AI Analytics uses generative AI to produce synthetic text output, it falls within the content-marking obligation in Article 50(2) (see Section 8.2).

4. Classification Framework

The AI Act applies a risk-based, layered approach. Imagicle has classified each Product against four cumulative regimes, plus the separate Chapter V regime for general-purpose AI models:

Tier 1 – Prohibited practices (Article 5). AI practices that are banned outright, applicable since 2 February 2025. See Section 7.

Tier 2 – High-risk AI systems (Article 6, Annexes I and III). Systems subject to the most extensive obligations (risk management, data governance, technical documentation, human oversight, conformity assessment). See Section 6.

Tier 3 – Transparency-risk systems (Article 50). Systems that interact with people, perform emotion recognition or biometric categorisation, or generate synthetic content, which carry specific disclosure and marking obligations. See Section 8.

Tier 4 – Minimal-risk systems. All other AI systems, which carry no mandatory obligations beyond the horizontal AI-literacy duty (Article 4) and voluntary codes of conduct.

Parallel regime – General-purpose AI models (Chapter V, Articles 51–56). A separate, model-level regime addressing providers of GPAI models. It is independent of the risk tier of any downstream system. See Section 9.

These regimes are cumulative: a single AI system may, for example, be minimal-risk for the purpose of Tiers 1–2 yet still carry Article 50 transparency obligations under Tier 3. Classification can also depend on the customer's specific deployment context; where a customer integrates a Product into a use case listed in Annex III (for example, recruitment or access to essential services), additional high-risk obligations may apply to that customer as deployer.

5. Risk Classification Summary

The table below summarises Imagicle's classification of each Product. Detailed analysis follows in Sections 6 to 9. Where an obligation falls on the deployer (customer) rather than on Imagicle, this is indicated.

Product

Art. 5 – Prohibited

Art. 6 – High-risk

Art. 50 – Transparency

Overall classification

Voice Analytics

Not prohibited

Not high-risk by design

Art. 50(2) – mark synthetic audio/text output (provider duty)

Limited (transparency) risk

AI Receptionist

Not prohibited

Not high-risk by design

Art. 50(1) inform callers; Art. 50(2) mark synthetic audio/text (provider duties)

Limited (transparency) risk

Virtual Agent

Not prohibited

Not high-risk by design

Art. 50(1) inform users; Art. 50(2) mark synthetic audio/text (provider duties)

Limited (transparency) risk

Advanced AI Analytics

Not prohibited

Not high-risk by design

Art. 50(2) – mark synthetic text output (provider duty)

Limited (transparency) risk

 

“Not high-risk by design” means the Product is not, in its standard configuration, a high-risk AI system under Article 6 and Annex III. A customer's particular deployment may bring the system within Annex III, in which case high-risk obligations apply to that customer as deployer (see Section 6).

6. High-Risk Classification (Article 6 and Annex III)

Under Article 6, an AI system is high-risk only if (a) it is a safety component of a product covered by the Union harmonisation legislation in Annex I and subject to third-party conformity assessment, or (b) it is intended for one of the use cases listed in Annex III (which include biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services, law enforcement, migration and asylum, and administration of justice).

Imagicle's assessment. In their standard configuration, the Products are general unified-communications and contact-centre tools. They are not safety components of Annex I products, and their standard purpose – call handling, conversation analytics and customer interaction – does not by itself fall within an Annex III use case. Accordingly, Imagicle classifies the Products as not high-risk by design.

Deployment-dependent reclassification. This classification can change with the customer's use case. In particular, where a customer deploys Voice Analytics or Advanced AI Analytics to monitor or evaluate the performance and behaviour of its own workers (for example, contact-centre agents), the system may fall within Annex III, point 4 (employment and worker management) and become high-risk in that customer's hands. Similarly, use in recruitment, in determining access to essential services, or in other Annex III contexts may trigger high-risk obligations.

Consequence for the customer. Where a deployment makes a Product high-risk, the customer (as deployer) assumes the deployer obligations in Article 26, and the obligations of a provider may also be triggered for any party that substantially modifies the system or puts it into service under its own name. Customers intending such deployments should contact Imagicle so that the parties can confirm the applicable obligations.

7. Prohibited Practices Screening (Article 5)

Article 5, applicable since 2 February 2025, bans certain AI practices outright, including: subliminal or purposefully manipulative techniques that cause significant harm; exploitation of vulnerabilities; social scoring; certain biometric categorisation of sensitive attributes; untargeted scraping of facial images; predictive policing of individuals; certain real-time remote biometric identification in public spaces; and emotion recognition in the areas of the workplace and education institutions (Article 5(1)(f)), except for medical or safety reasons.

Imagicle's assessment. The Products are not designed or marketed for any of the prohibited practices, and Imagicle classifies none of them as a prohibited practice.

Critical screening point – Voice Analytics in the workplace. The Article 5(1)(f) prohibition on emotion recognition in the workplace and education applies only to systems that infer emotions from biometric data. Voice Analytics derives its sentiment indicators purely from lexical and statistical analysis of transcribed text and does not infer emotional state from biometric data; it is therefore not an emotion recognition system, and the Article 5(1)(f) prohibition is not engaged, including where the Product is used in workplace or contact-centre settings. Should Imagicle introduce biometric-based emotion inference in the future, this assessment would need to be revisited.

8. Transparency Obligations (Article 50)

Article 50 imposes transparency obligations that apply independently of the risk tier and that are, for the Products, the principal AI Act obligations. These obligations become applicable on 2 August 2026. The obligations fall on different actors depending on the obligation, so the allocation between Imagicle (provider) and the customer (deployer) is set out below and consolidated in Section 10.

8.1 Interaction disclosure – Article 50(1) (provider obligation)

Obligation. Providers of AI systems intended to interact directly with natural persons must ensure those persons are informed that they are interacting with an AI system, unless this is obvious to a reasonably well-informed user. The disclosure must be made at the point of interaction; a statement buried in terms and conditions or product documentation is not sufficient, and vague labels such as “assistant” do not satisfy the obligation.

Application. This applies to AI Receptionist and Virtual Agent. As provider, Imagicle designs these Products so that, at the start of each interaction, the user is clearly informed they are interacting with an AI system (for example, an audible statement at the beginning of a voice interaction or a clear notice at the start of a chat). Customers must not disable or obscure this disclosure.

8.2 Synthetic-content marking – Article 50(2) (provider obligation)

Obligation. Providers of AI systems that generate synthetic audio, image, video or text content must mark the output, in a machine-readable format, as artificially generated or manipulated, and ensure it is detectable as such. An exception applies where the system performs a purely assistive function for standard editing or does not substantially alter the input.

Application. This applies to all four Products – Voice Analytics, AI Receptionist, Virtual Agent and Advanced AI Analytics – each of which generates or manipulates synthetic audio and/or text output. As provider, Imagicle marks that output as artificially generated or manipulated in a machine-readable format, in accordance with Article 50(2) and the AI Office's Code of Practice on Transparency of AI-Generated Content. Because no single technique satisfies the obligation, Imagicle applies a layered approach: (i) cryptographically signed, tamper-evident provenance metadata following the C2PA Content Credentials standard (ISO/IEC 21694), embedded wherever the output format supports it; (ii) an imperceptible watermark interwoven with the content and designed to remain detectable after common transformations such as compression, format conversion or cropping; and, where these prove insufficient, (iii) fingerprinting or logging as a supplementary fallback. The marking is applied in a manner appropriate to each modality (for example, a metadata-borne or audible marker for synthetic audio and an embedded marker for synthetic text) and is designed to be effective, interoperable, robust and reliable as far as is technically feasible, consistent with the qualitative criteria set out in the Code of Practice. Note: under the "AI Omnibus" amendments (approved by the European Parliament on 16 June 2026 and awaiting formal adoption by the Council and publication in the Official Journal), the Article 50(2) marking obligation is subject to a four-month grace period, to 2 December 2026, for AI systems already placed on the market before 2 August 2026; systems placed on the market on or after 2 August 2026 must comply from 2 August 2026. The remainder of Article 50 continues to apply from 2 August 2026. These dates remain subject to formal adoption.

8.3 Emotion recognition – Article 50(3) (deployer obligation)

Obligation. Deployers of an emotion recognition or biometric categorisation system must inform the natural persons exposed to it of the system's operation, no later than the time of first exposure, and must process any personal data in accordance with the GDPR.

Application. Voice Analytics is not an emotion recognition system, because its sentiment indicators are derived purely from lexical and statistical analysis of transcribed text rather than from biometric data (see Sections 3.1 and 7). Accordingly, the Article 50(3) disclosure obligation does not apply to Voice Analytics. Were any Product in future to infer emotions from biometric data, the deployer would have to inform exposed individuals, and emotion recognition in the workplace or education would remain prohibited under Article 5(1)(f) regardless of any disclosure.

8.4 Deepfakes and AI-generated text – Article 50(4) (deployer obligation)

Obligation. Deployers who use AI to generate or manipulate deepfake image, audio or video content, or AI-generated text published to inform the public on matters of public interest, must disclose the artificial origin of that content.

Application. The Products are not designed to create deepfake media resembling real persons, so Article 50(4) is not expected to apply. Where a customer uses a Product to publish AI-generated text on matters of public interest, the disclosure obligation falls on that customer as deployer.

8.5 Manner of disclosure – Article 50(5)

All disclosures under Article 50 must be provided in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and must comply with applicable accessibility requirements.

9. General-Purpose AI Models (Chapter V, Articles 51–56)

Chapter V establishes a separate, model-level regime for providers of general-purpose AI (GPAI) models. It is independent of the risk classification of any AI system and applies from 2 August 2025. Its obligations address the entity that develops and places a GPAI model on the market – not the downstream providers that integrate that model into systems.

Obligations under Chapter V. Providers of GPAI models must, under Article 53, maintain technical documentation (Annex XI), provide integration documentation to downstream providers (Annex XII), put in place a copyright policy, and publish a summary of the training content. Providers of GPAI models with systemic risk (broadly, models trained using more than 10^25 floating-point operations) have additional obligations under Article 55, including model evaluation, systemic-risk mitigation, incident reporting and cybersecurity. Compliance may be demonstrated through the General-Purpose AI Code of Practice pending harmonised standards.

Imagicle's position. Imagicle does not train or place general-purpose AI models on the EU market. Where the Products rely on large AI models, Imagicle integrates third-party GPAI models supplied by upstream model providers. Imagicle is therefore not a “provider of a general-purpose AI model” and has no obligations under Articles 53 or 55.

Downstream role. To the extent a Product is built on a third-party GPAI model, Imagicle acts as a downstream provider of an AI system (potentially a general-purpose AI system within the meaning of Article 3(66)). Imagicle's obligations in that capacity arise under the AI-system rules – principally the Article 50 transparency obligations addressed in Section 8, and the high-risk rules if and where Section 6 applies – and not under Chapter V.

Reliance on upstream providers. Imagicle relies on its upstream GPAI model providers to meet their Chapter V obligations and to supply the Annex XII integration information. Imagicle uses that information to support its own transparency compliance and will pass relevant model information through to customers where appropriate. Should Imagicle in future develop or place its own GPAI model on the market, this statement will be updated to reflect the resulting Chapter V obligations.

10. Allocation of Responsibilities (Provider and Deployer)

The AI Act allocates obligations across the value chain. The following summarises how responsibilities are shared between Imagicle (as provider) and the customer or partner (as deployer) for the Products.

Imagicle, as provider, is responsible for: designing the Products so that users are informed they are interacting with an AI system (Article 50(1)); implementing machine-readable marking of any synthetic output as artificially generated or manipulated, using signed provenance metadata (C2PA Content Credentials) backed by watermarking in line with the Code of Practice on Transparency of AI-Generated Content (Article 50(2)); providing customers with the information and configuration means needed for the customer's own disclosures; maintaining this classification and the related product information; and ensuring an adequate level of AI literacy among its relevant staff (Article 4).

The customer, as deployer, is responsible for: informing individuals exposed to any emotion recognition functionality (Article 50(3)) and to deepfake or public-interest AI text where applicable (Article 50(4)); not disabling or obscuring Imagicle's built-in AI disclosures; using the Products only for lawful, non-prohibited purposes (Article 5), in particular not deploying emotion recognition in workplace or education settings; assessing whether its specific deployment brings a Product within a high-risk Annex III use case and, if so, meeting the deployer obligations in Article 26; complying with the GDPR for any personal data processing; and ensuring an adequate level of AI literacy among its own staff (Article 4).

Shared and contextual matters. Where a customer substantially modifies a Product, or deploys it under its own name or trademark, or puts a high-risk system into service, that customer may itself assume provider obligations under Article 25. The parties should consult one another before any such deployment.

11. Implementation Timeline

The principal AI Act milestones relevant to the Products are set out below. Dates reflect the regulation as currently in force; the pending “AI Omnibus” may adjust certain transparency dates.

Date

Milestone

1 August 2024

AI Act enters into force.

2 February 2025

Prohibited practices (Article 5) and AI-literacy duty (Article 4) apply.

2 August 2025

Obligations for providers of GPAI models (Chapter V), governance and penalties apply.

2 August 2026

Transparency obligations (Article 50) and most high-risk obligations (Annex III) apply.

2 December 2026

Article 50(2) machine-readable marking obligation: four-month grace period (to this date) for AI systems placed on the market before 2 August 2026; systems placed on or after 2 August 2026 comply from 2 August 2026. Under the AI Omnibus (approved by the European Parliament on 16 June 2026; pending Council adoption and Official Journal publication).

2 August 2027

High-risk obligations for Annex I product-safety systems apply; GPAI models already on the market must be compliant.

This timeline is indicative and will be updated as the AI Omnibus and related implementing measures are adopted.

Good-faith self-classification. This statement reflects Imagicle's good-faith classification of the Products under the AI Act based on the regulation and the guidance available at the date of last review. It does not constitute legal advice and should not be relied upon as such.

Evolving framework. The AI Act is subject to ongoing implementation through Commission guidelines, codes of practice, harmonised standards and the pending AI Omnibus amendments. The classifications and dates in this statement may change, and Imagicle will update this statement as appropriate.

Deployment-dependent classification. The classification of a Product can depend on how a customer deploys it. Customers and partners remain responsible for assessing and meeting their own obligations as deployers, including any high-risk obligations arising from their specific use case.

Contractual status. Where this statement forms part of contractual documentation between Imagicle and a customer or partner, it is provided subject to, and does not expand, the representations, warranties and limitations set out in the applicable agreement. In the event of any conflict, the terms of Service Agreement prevail.

Contact. Questions regarding this statement or the AI Act classification of the Products may be directed to Imagicle Security & Trust Team (trust@imagicle.com)