EU AI Act Compliance

Trialcraft BV (trading as Studia)
Last Updated: 07/08/2026

Introduction

This statement explains how Studia addresses Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (the "AI Act"). It describes the role we take under the Regulation, how we classify the risk of our AI features, and the transparency, human-oversight and governance measures we apply.

Studia is a medical writing platform. Its AI features draft, review and check clinical documents such as protocols, informed consent forms and investigator brochures. Every AI output is a proposal to a qualified professional, never a decision.


1. Our Role Under the AI Act

The AI Act allocates obligations by role. Ours are as follows:

PartyRoleWhat it means
Trialcraft BVProvider of an AI system (Art. 3(3))We develop and place the Studia platform on the EU market under our own name.
Trialcraft BVDeployer of third-party GPAI modelsStudia is built on general-purpose AI models supplied by third parties. We do not train or fine-tune foundation models ourselves.
Our CustomersDeployer of the Studia AI system (Art. 3(4))Customers use Studia under their own authority and remain responsible for the documents they produce and submit. See Section 8.

2. Risk Classification

2.1. Prohibited Practices (Art. 5)

Studia implements none of the practices prohibited under Article 5. The Platform performs no social scoring, no emotion recognition, no biometric categorisation, no predictive profiling of individuals, and no subliminal or manipulative techniques.

2.2. High-Risk Classification (Art. 6 and Annex III)

Based on our intended purpose, Studia is not a high-risk AI system:

  • It is not a safety component of a product covered by the Union harmonisation legislation listed in Annex I. Studia is a document authoring tool: it is not a medical device, not an in-vitro diagnostic device, and it neither drives nor controls one.
  • It does not fall under any use case in Annex III. Studia performs no biometrics, no critical-infrastructure management, no evaluation of access to education, employment, essential services, credit or insurance, no law-enforcement, migration or justice functions, and it makes no decisions about natural persons.
  • Its output is document text proposed to a human author, who accepts, edits or rejects it before the document has any effect.

Studia is therefore an AI system subject principally to the transparency obligations of Article 50 and the AI literacy duty of Article 4. We nevertheless apply a number of high-risk-grade controls voluntarily — human oversight, logging, traceability and continuous quality evaluation — because our customers operate under GxP and clinical trial regulations that demand them.

2.3. Re-Classification by Customer Use

A deployer who puts Studia to a use outside our documented intended purpose may bring the system into a high-risk category and, under Article 25, may assume provider obligations for that use. Studia must not be used to make or materially inform decisions about individual patients, subjects, employees or applicants.

3. Transparency (Art. 50)

Users always know when they are interacting with AI and which content an AI produced:

  • AI features are labelled as such in the interface. AI assistance is invoked deliberately by the user; it never runs silently in the background of an authoring session.
  • AI-generated content is marked. Every edit an AI feature proposes to a document is created as a tracked change attributed to the AI. It stays visually distinct from human writing until a person accepts it, and the attribution survives export to Word.
  • Findings are evidence-linked. Where the Platform raises a compliance or consistency finding, it cites the source text or reference document the finding is based on, so a reviewer can verify it rather than trust it.
  • Limitations are disclosed. AI output is probabilistic and can be incomplete or wrong. This is stated in our Terms of Service (Section 8) and in the Platform documentation.

4. Human Oversight

Studia is designed so that a qualified professional stays in control of the document at every step:

  • Nothing is applied automatically. AI proposals require an explicit accept or reject by a user with authoring rights. Rejecting a proposal leaves the document untouched.
  • Every change is reversible. Documents are versioned, and revisions can be inspected and restored.
  • Roles limit who can act. Access control separates readers, reviewers, authors and administrators, so the ability to accept AI-proposed content is granted deliberately.
  • The Platform never signs off. Studia produces no approvals, no regulatory determinations and no medical judgements.

5. Data Governance

  • No training on customer data. Documents and content processed in the Platform are not used to train, fine-tune or improve our models or those of our model providers. This is a contractual warranty — see Terms of Service, Section 3.3.
  • Customer data stays the customer's. Customers retain full ownership of uploaded content, and we process it strictly as a Data Processor on their instructions.
  • EU hosting. Platform data is hosted in the European Union (Google Cloud, Belgium/europe-west). Details of processing, transfers and sub-processors are set out in our Privacy Policy and our Data Processing Agreement.
  • Data minimisation. Customers are asked to avoid uploading unnecessary identifiable patient data; Studia's purpose is document authoring, not the processing of individual health records.

6. Underlying AI Models

Studia does not train foundation models. It calls general-purpose AI models operated by third-party providers under commercial agreements that exclude the use of our customers' content for model training. The models are selected and configured by us, and the choice may change as the state of the art evolves.

The current list of AI model providers acting as sub-processors is maintained in the sub-processor annex to our Data Processing Agreement and is available to customers and prospective customers on request at contact@studia.health. Customers under a DPA are notified of changes to that list.

7. Quality, Logging and Traceability

Although not mandatory for a system of this risk class, we operate controls that make AI behaviour auditable:

  • Version history. Document revisions and tracked changes record what was proposed, by whom or by what, and who accepted it.
  • Audit logging. Identity and access events are recorded for administrators.
  • Continuous evaluation. AI features are measured against curated datasets for factual grounding, adherence to guidelines and formatting discipline before prompt or model changes are rolled out.
  • Monitoring. Production AI runs are traced and monitored so that quality regressions and failures are detected and investigated.

8. Obligations of Our Customers as Deployers

Under Article 4 and Article 26 of the AI Act, deployers carry obligations of their own. When using Studia, you should:

  • Ensure that staff using the Platform have a sufficient level of AI literacy — they must understand that outputs are probabilistic and must be verified.
  • Use the Platform in accordance with its intended purpose as described in this statement and in our Terms of Service.
  • Assign human oversight to competent people — qualified medical writers or reviewers with the authority and training to reject AI proposals.
  • Keep your own records as required by your quality system and by the clinical trial or device regulations that apply to your submissions.
  • Inform affected staff and, where relevant, your own clients that AI assistance is used in document preparation.

9. AI Literacy Within Studia (Art. 4)

Our team is trained on the capabilities and limitations of the models we deploy, on the failure modes of generative AI in a regulated writing context, and on our obligations under the AI Act and GDPR. In-product documentation explains to users what each AI feature does, what evidence it uses, and what it cannot be relied on to do.

10. Applicability Timeline

DateMilestone
1 August 2024AI Act enters into force.
2 February 2025Prohibited practices (Art. 5) and AI literacy (Art. 4) apply.
2 August 2025Obligations for general-purpose AI model providers apply.
2 August 2026General application, including the transparency obligations of Art. 50.

We track guidance from the European Commission and the AI Office, including harmonised standards and codes of practice, and update our controls and this statement accordingly.

11. Reporting a Concern

If you believe an AI feature in Studia has behaved unsafely, produced seriously misleading output, or has been used outside its intended purpose, contact us at contact@studia.health. We investigate reports of AI malfunction, correct the underlying prompt, model configuration or guardrail where warranted, and inform affected customers.

12. Changes to This Statement

We update this statement as the Regulation, its implementing guidance, and our Platform evolve. The latest version is always published on this page.

Trialcraft BV
Baron Opsomerdreef 32, 3090 Overijse, Belgium
CBE/KBO: BE1010925090
Email: contact@studia.health