Status — read first
AI-assisted best-effort draft · not legal advice · not lawyer-reviewed.
This document was drafted with AI assistance as a best-effort starting point. No licensed attorney has reviewed, approved, or certified it, and it is not safe to rely on as a binding or compliant document. A qualified attorney in each operating jurisdiction must review and finish it before it is published or enforced. Nothing here claims an audit, certification, corporate registration, or executed contract that has actually happened.
No conformity assessment, CE marking, or EU registration exists. This page deliberately reports the honest, unfinished status. Earlier public copy asserted the opposite — that Vettika already maintained the Annex IV technical file, ran a documented Art. 9 risk-management system, provided Art. 13 instructions, and met Art. 12/19 record-keeping. Those claims are not true yet. Publishing conformity you cannot evidence is both a misrepresentation and, because these are mandatory provider obligations, a direct AI Act violation risk with penalties up to 7% of global turnover.
Timing — this is now, not later
The EU AI Act (Reg. 2024/1689) applies its high-risk obligations for Annex III systems from 2 August 2026. That date has arrived, so this is not a future planning exercise. As of now, either the conformity work exists, or EU/EEA candidate traffic should be gated off until it does. Continuing to serve EU/EEA candidates while a public page claims conformity that this status says is unbuilt is the specific thing to stop doing. Get urgent counsel.
Classification
The Service — provided by Vettika, a service operated by Nexprove across vettika.com and airecruiter.nexprove.com — is an AI system under Art. 3(1). Annex III §4(a) treats AI used for the recruitment or evaluation of candidates as high-risk. Working classification: high-risk under Annex III §4(a), to be confirmed by counsel.
Provider vs. deployer
- Provider (Art. 3(3)): Vettika, a service operated by Nexprove develops the system and places it on the market. The heavy obligations fall here.
- Deployer (Art. 3(4)): the recruiter, who uses the system under their own authority.
This split is correct, and so is the human-oversight framing: the recruiter must have a qualified human review every AI output, and Vettika builds toward making that reviewable. What has to stop is implying the heavy provider obligations are already satisfied.
Provider obligations — honest status
| Obligation | Article | Actual status |
|---|---|---|
| Risk-management system | Art. 9 | Not formalized |
| Data governance | Art. 10 | Vettika orchestrates third-party models it did not train; counsel confirms how Art. 10 applies |
| Technical documentation (Annex IV) | Art. 11 | Stub. Not the "technical file required by Annex IV" that earlier copy claimed |
| Record-keeping / logs | Art. 12 | Partial — audit and security logs exist; AI-output log retention (≥6 months) needs to be confirmed |
| Transparency to deployers | Art. 13 | Stub — a model card and intended-use instructions need to be written |
| Human oversight | Art. 14 | In place — recruiter must review every output (the one obligation genuinely met) |
| Accuracy, robustness, cybersecurity | Art. 15 | Partial — security baseline shipped; no formal accuracy testing |
| Quality-management system | Art. 17 | Not started |
| Automatic-log retention (≥6 months) | Art. 19 | See Art. 12 |
| Corrective action and duty to inform | Art. 20 | Process not defined |
| Conformity assessment / CE marking | Art. 43 | Not done — cannot be self-declared credibly for a high-risk system |
| EU database registration | Art. 49 | Not done |
| Post-market monitoring | Art. 72 | Not done |
Only the Art. 14 row is genuinely satisfied. Everything else is in progress or not started. This page matches this table — it does not contradict it.
Emotion recognition
Art. 5(1)(f) prohibits emotion-recognition in the workplace and education, with narrow exceptions. Positioning Vettika as never inferring emotion is good, but it has to be provably enforced in the agent configuration, not merely stated on a page. We confirm in the agent code that no emotion-inference runs, and keep that as evidence. We do not claim it as a global setting unless the config actually enforces it.
Deployer obligations (recruiter)
Under Art. 26, recruiters use the system per the instructions, assign competent humans to oversight, tell candidates they are subject to an AI system, run a Fundamental Rights Impact Assessment where Art. 27 requires one, and keep AI-output logs at least six months. These pass through to recruiters in the DPA and Terms — but only once the Art. 13 instructions actually exist to hand them.
What requires a human, not this document
- The Annex IV technical file, the Art. 9 risk-management system, the Art. 17 quality-management system, and the Art. 13 instructions for use all have to be genuinely built and maintained. AI drafting can start them; it cannot make them true.
- The conformity assessment and CE marking (Art. 43) and EU database registration (Art. 49) cannot be credibly self-declared for a high-risk system. This needs qualified counsel plus, for the conformity route, an external assessment. It is not represented as done.