EU AI Act (Regulation 2024/1689)
How 20X approaches its obligations as a provider of an AI system under Regulation (EU) 2024/1689, and how customers acting as deployers can meet theirs.
Our role - provider
Setoo Solutions Pvt Ltd is the provider of the 20X AI system: we develop it and place it on the market and into service in the EU under the 20X name. Customers who use 20X to run AI agents inside their own operations act as deployers (Art. 3). This distinction determines who is responsible for which obligations under the Act.
Risk classification
20X is a general-purpose orchestration platform for AI agents and workflows. As shipped, it is not designed for, or marketed for, uses that the Act classifies as prohibited (Art. 5) or as high-risk under Annex III (for example biometric categorisation, critical infrastructure control, education scoring, employment decisions, essential-services eligibility, law enforcement, migration, or the administration of justice and democratic processes).
A deployer can configure any general-purpose platform for a high-risk purpose. Customers are responsible for assessing whether their intended use falls in Annex III or Art. 5, and for meeting the additional obligations that apply if it does. 20X's acceptable use policy prohibits configuring the platform for uses banned by Art. 5.
Transparency to end users (Art. 50)
- Systems that interact directly with natural persons must disclose that the person is interacting with an AI system, unless it is obvious from the context. 20X provides configurable disclosure surfaces for chat, voice, and form workflows. Replies sent via a connected Facebook Page or Instagram account may be AI-generated; deployers are responsible for disclosing that where required.
- AI-generated or manipulated content (text, image, audio, video) that could be mistaken for authentic must be marked in a machine-readable format where technically feasible. Deployers configuring generative flows are responsible for enabling and preserving these markings.
- Emotion-recognition and biometric-categorisation systems (where permitted at all) must inform the natural persons exposed to them.
Human oversight and controls
20X ships with human-in-the-loop approval gates, role-based access control, audit logs of agent actions, and the ability to pause, override, or roll back workflows. These are the mechanisms deployers use to meet Art. 14 human-oversight requirements when their use case is high-risk.
General-purpose AI models we use
20X integrates third-party general-purpose AI models (for example large language models) to power agent reasoning. Providers of those models carry the general-purpose AI provider obligations in Chapter V of the Act, including technical documentation, downstream information, copyright compliance, and - for models with systemic risk - additional evaluation and incident-reporting duties. 20X selects model providers that publish this documentation and passes relevant information to customers on request.
Data, logging and record-keeping
20X maintains logs of agent runs, tool calls, human approvals, and configuration changes so that deployers can trace how a decision was reached. Customers can export these logs and configure retention to meet their own governance and audit needs.
Deployer duties customers should note (Art. 26)
- Use the system in line with its instructions for use.
- Assign competent human oversight for high-risk use cases.
- Ensure input data is relevant and sufficiently representative for the intended purpose.
- Monitor operation and report serious incidents to the provider and, where applicable, to the relevant authority.
- Inform workers and their representatives before deploying a high-risk AI system in the workplace, and inform natural persons subject to decisions produced or assisted by a high-risk AI system.
- Complete a fundamental-rights impact assessment where required by Art. 27.
Serious-incident reporting (Art. 73)
Deployers who become aware of a serious incident involving a high-risk AI system must report it to the provider and to the market-surveillance authority of the Member State where the incident occurred. Reports to 20X can be sent to privacy@20x.business; we will cooperate with any resulting investigation.
AI literacy (Art. 4)
Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and other persons operating and using AI systems on their behalf. 20X publishes product documentation, in-product guidance, and consulting-led training to support customer AI-literacy programmes.
Contact
Questions about 20X and the EU AI Act: privacy@20x.business.