Compliance

Case data requires more than a standard approach to AI.

AR3S is being designed to work with materials that may contain health data, information protected by professional secrecy and other confidential information. Data protection and regulatory compliance are therefore treated as product constraints from the outset, rather than as an add-on at the end.

AI supports the analysis. The decision remains with the lawyer.

Under its current intended use, AR3S is designed to support professional users acting for parties to proceedings. It is not designed as a tool for courts or as a system for automatically deciding cases.

01

AR3S as an AI system

To the extent that AR3S uses language models to analyse content, it falls within the scope of assessment under the AI Act. The system is designed with the resulting requirements concerning documentation, transparency and human oversight in mind.

02

Outside the high-risk category

Under its current intended use — as a tool supporting law firms and professional representatives — AR3S should not be classified as a high-risk AI system within the meaning of Article 6 of the AI Act.

03

The user remains in control

AR3S supports the analysis of case materials, but it does not make decisions for the user, decide the case or replace a lawyer’s professional judgement. System outputs should be reviewed before they are used.

04

Data protection from the outset

AR3S is designed to work with pseudonymised data. Data sent to AI models is not used to train them or retained permanently, and processing takes place within infrastructure located in the EU.

Client data is used only to perform the requested analysis. It does not train models.

The client remains the controller of case materials, while AR3S processes data only to the extent necessary to perform the requested analysis.

01

No secondary use

Materials submitted to AR3S are not used to train models, improve the system or for purposes unrelated to performing the requested analysis.

02

Defined processing roles

The client remains the data controller, while AR3S and its technology providers process data within an appropriately governed chain of processors and sub-processors.

03

Providers under control

We select AI models, OCR, hosting and other technical services with regard to data retention, processing location, access rules and the possibility of secondary use.

Pseudonymisation preserves the analytical value of the material

Fully anonymising case documentation at the analysis stage is not practically possible without removing information relevant to assessing the expert opinion. AR3S therefore relies on pseudonymisation — removing direct identifiers while preserving the content needed for a reliable analysis.

Pseudonymisation as the standard
Pseudonymised data remains personal data, but this approach is appropriate from a data-protection perspective and materially reduces risk without sacrificing the analytical value of the material.

Additional safeguards
Pseudonymisation is complemented by technical and organisational safeguards: need-to-know access, encryption, short retention periods, and requirements for providers regarding no training on client data and defined processing locations.

Short retention. Defined location. A controlled processing chain.

For pilots using real case materials, the intended direction is EU/EEA processing and the shortest practicable retention of source materials. Specific retention periods and infrastructure arrangements will depend on the deployment model and contractual documentation.

01EU/EEA as the default processing direction for pilots
02Limited or zero retention by external providers, depending on the service
03Data processing agreements and no training on client data as provider-selection requirements
04The shortest practicable retention of source materials after an analysis is completed

Professional secrecy requires control of the entire chain.

Law-firm materials may be protected by professional secrecy, while insurers are subject to insurance confidentiality obligations. The use of technology providers does not in itself negate confidentiality, but it requires a clearly limited processing purpose, restricted access and appropriate contractual safeguards.

01

Need-to-know

Access to real case materials should be limited to people for whom it is necessary to perform a specific task.

02

Sub-processor confidentiality

Entities with technical access to data should be subject to obligations reflecting the nature of the materials entrusted to them.

03

No profiling of people

The object of analysis should remain the document and its reasoning — not profiles of experts, witnesses, patients, doctors or other people appearing in case files.

04

Review before use

System output is assistive. Final assessment of the material and any decision on how to use it remain with the professional user.

External legal review

Compliance is part of product development, not a claim added at the bottom of a page.

In July 2026, the regulatory assumptions behind AR3S were subject to an external legal review covering, among other matters, the AI Act, GDPR, health data, professional secrecy, liability, the Data Act and product communications.

The findings are being used in the preparation of pilots.

Compliance documentation is intended to be updated as the product and deployment model change.

This page describes the design direction and regulatory assumptions; it is not a certificate of compliance.

Compliance · Pilots

Questions about data,
deployment or security?

Before a pilot begins, the scope of processing, deployment model and responsibilities of the parties should be reflected in documentation appropriate to the client and the intended use.

contact@ar3s.tech