AI Transparency
Version 1.0.0, effective from October 4, 2026
This page describes how Spyral uses artificial intelligence (AI): which features use it, which providers and models run it and where, what the features are for and what they cannot do, how the product keeps a person in control, and how AI output is identified. It is written for the firms that use Spyral and for the people in those firms who work with it.
It supports the transparency duties in Article 50 of the AI Act (Regulation (EU) 2024/1689) and the AI literacy duty in its Article 4, and it gives firms the information they need for their own obligations. The contractual terms on AI are in the Terms of Service. How personal data is processed is set out in the Privacy Policy and the Data Processing Agreement.
Summary
- AI in Spyral prepares proposals: it reads, classifies, extracts, drafts and answers. A person decides what is used, filed or sent.
- AI output is labelled in the product, and text that AI writes carries a machine-readable marker when it leaves the product.
- All AI processing is restricted to providers and data centres in the European Economic Area (EEA) or Switzerland. A built-in guard checks where each model runs before it is used and, where the provider reports it, where each call was served, and it stops a feature rather than route data anywhere else.
- Customer content is never used to train or fine-tune any AI model.
- Spyral's AI features are not high-risk AI systems under the AI Act, and Spyral uses no prohibited AI practice.
Spyral's role under the AI Act
Spyral builds its AI features on general-purpose AI models developed by others and offers them under its own name. Spyral is therefore the provider of the AI features described on this page. A firm whose staff use those features in their professional work is a deployer.
The underlying models are general-purpose AI models developed by third parties; the register below names each model family. Their developers carry the obligations that the AI Act places on providers of general-purpose AI models. The models are open-weight models that our inference providers run in their own data centres, and Spyral does not send content to the developers of the models.
Used for their intended purpose (described below), Spyral's AI features are not high-risk AI systems within the meaning of Article 6 and Annex III of the AI Act. Spyral does not use any practice prohibited by Article 5.
Which features use AI
- Reading documents. When you upload a document, AI reads the text of scanned pages, identifies the type of document, suggests labels, and recognises the companies, people and RCS numbers it mentions. If the vision model cannot read a page, open-source text recognition software running in Spyral's own hosting environment is used instead.
- Search. Documents are converted into numerical representations (embeddings) so that you can search them by meaning. The same technique suggests colleagues in your workspace who have worked on similar documents.
- Asking your documents. The chat answers questions using passages it retrieves from the documents in your workspace that you are allowed to see, with citations to its sources. It can suggest follow-up questions and draw mind maps. For complex questions, it first runs a short automated check and may decline a question it assesses as inappropriate.
- Spyral Assistant. The assistant panel answers questions and looks up documents, companies, ledgers and annual accounts on your behalf, within your own permissions. It can also make a limited set of changes, as described under "Human oversight" below.
- Document editing. AI can rewrite a passage you select, or edit a Word document following your instructions in a chat. The result is saved as a new version of the document.
- Bookkeeping. AI reads financial documents, such as invoices, contracts and statements, and proposes journal entries for a company's ledger, with accounts, amounts and tax codes.
- Annual accounts. AI extracts figures and company details from earlier accounts and from register extracts, and suggests shareholder and other relationships between companies and people.
- Approvals. When Spyral prepares an approval document from an earlier one, AI locates details such as the RCS number, share capital, registered office or manager names where fixed patterns cannot find them.
- Firm memory. When people in your firm correct AI output, for example a bookkeeping entry, Spyral remembers the correction for your firm, and later proposals for your firm take it into account. This is not model training: the correction is stored in your workspace and given to the model as context, for your firm only.
- What's new. The product update notes in the dashboard are drafted with AI from descriptions of Spyral's own product changes. They contain no customer content.
AI register
The table below is generated from the configuration that the service runs on, so it changes when that configuration changes. For each AI function it shows the providers and model families the function can use, in order of preference, and the countries where each of them runs.
| Feature | Human oversight | Models (in order of preference) |
|---|---|---|
| Assistant and chatAnswers questions from your documents, with sources, and carries out actions you confirm. | Shown as a suggestion, marked as AI generated, which a person can change. |
|
| Document editingProposes rewrites and edits inside a document. | A person reviews and approves the output before it takes effect. |
|
| Annual accountsExtracts figures and parties for annual accounts, relationships and approvals. | A person reviews and approves the output before it takes effect. |
|
| BookkeepingClassifies documents and proposes journal entries. | A person reviews and approves the output before it takes effect. |
|
| Document classificationLabels and sorts uploaded documents. | Shown as a suggestion, marked as AI generated, which a person can change. |
|
| Company and person extractionFinds companies, people and their roles in documents. | Shown as a suggestion, marked as AI generated, which a person can change. |
|
| Scanned documentsReads the text of scanned pages (OCR). | Runs automatically; the result is visible and correctable. |
|
| Register extractsReads company register extracts from page images. | A person reviews and approves the output before it takes effect. |
|
| SearchTurns document text into vectors for semantic search. | Runs automatically; the result is visible and correctable. |
|
If the first choice for a function is unavailable, or not yet enabled, Spyral uses the next model in its list. The register marks a provider that is not in use, for example because its data processing agreement has not been signed yet; such a provider receives no data. Every model in every list runs in the EEA or Switzerland. The model that produces embeddings for search has no fallback: replacing it would make the existing search data unusable, so if it becomes unavailable, search stops instead of switching.
Intended purpose
Spyral's AI features are intended to help qualified staff of professional firms, such as accounting, fiduciary and corporate-services firms in the European Union and mainly in Luxembourg and the Benelux, to organise, read, search and prepare work on business documents. Every result is a proposal or a draft for review by a person competent to judge it.
Uses the features are not designed for
The binding list of restricted uses is in the Terms of Service. In summary, do not use Spyral's AI features:
- as the sole basis for a decision that produces legal effects for a person or similarly significantly affects them;
- to evaluate the creditworthiness of individuals or establish their credit score, or to assess risks or set prices for individuals in life or health insurance;
- to recruit or select people, or to take or support decisions on promotion, termination, task allocation or the monitoring and evaluation of employees' performance or behaviour;
- to identify or categorise people using biometric data, or to recognise emotions;
- for any other use listed as high-risk in Annex III of the AI Act;
- to make customer due diligence, anti-money laundering or sanctions screening decisions. Spyral can help you prepare and organise the documents involved, but a competent person must take every decision;
- to give accounting, tax, legal or audit advice to a client without review by a qualified professional; or
- for any practice prohibited by Article 5 of the AI Act.
These uses are outside the features' intended purpose. A firm that uses them for a high-risk purpose listed in Annex III of the AI Act may itself become the provider of a high-risk AI system under Article 25 of the AI Act, with the obligations that go with it.
Limitations
- Errors. AI output can be incomplete, out of date or wrong, even when it reads fluently and with confidence. Models can invent figures, account or tax codes, names or citations that do not appear in the source.
- Answers from retrieved passages. Chat answers rely on the passages that search retrieves from your documents, not necessarily on every document. If search misses a relevant passage, the answer can be incomplete.
- Document quality. Poor scans, handwriting, stamps, unusual layouts and rotated or partial pages reduce the accuracy of text recognition and extraction.
- Knowledge. The models' general knowledge stops at the date their training ended, and it does not include current law, tax rates or filing rules unless your own documents contain them. Do not rely on AI for the state of the law.
- Languages. The features are designed for English, French, German, Dutch and Italian. Quality can vary between these languages, and it is lower for other languages and for documents that mix languages.
- Variability. Results are not deterministic. The same document or question can give different results at different times, in particular when a function moves to a fallback model.
- Confidence indicators are estimates. A high confidence score does not guarantee that a result is right. A low one tells you to check it first.
- Incomplete processing. Some steps have time limits. When a step runs out of time or no model is available, a field can stay empty. An empty field does not necessarily mean that the information is absent from the document.
- Firm memory repeats corrections. If a correction your firm made is wrong, later proposals can repeat the mistake until someone corrects it again.
Human oversight in the product
Spyral is built so that a person reviews AI output before it has consequences.
- Proposals, not decisions. AI output is presented as a proposal. Nothing that AI produces is filed, signed or sent outside Spyral unless a person does it.
- Confidence flags. Document classifications carry a confidence level, and low-confidence classifications are flagged "Needs review". The Library can be filtered to show only those documents. Bookkeeping entries show the model's confidence, and entries read with low certainty carry a warning to check the accounts and amounts.
- Review before filing. People review bookkeeping entries and mark them as reviewed. An eCDF filing file cannot be generated until every entry in the ledger has been marked as reviewed and the required identifiers are complete. Automatic bookkeeping can be switched off for each company.
- Document reviews. A version of a document can be sent to a colleague for review, who approves it or requests changes.
- Assistant confirmations. The Spyral Assistant looks up information on its own, within the permissions of the person using it. It makes only one change without asking first, an update to a company's notes, and it shows you that it has done so. Before it reclassifies a document, creates a bookkeeping entry or starts an annual accounts workflow, it shows a confirmation card describing the change, and nothing happens until you approve it. A document type that the Assistant changes is recorded as an AI proposal and flagged for review, not as a person's decision.
- Sources and versions. Chat answers cite the documents they draw on, so that each statement can be checked against its source. Every AI edit to a document is saved as a new version, and earlier versions can be restored. The document editor also offers a mode in which AI changes are held as a proposal until you accept them.
- Learning only from people. Firm memory learns only from corrections that people make to AI output. A correction is applied to later proposals once it has been confirmed in a review or has been repeated, and it is set aside if people later correct the same thing differently.
How AI output is identified
In the product
- The chat and the Spyral Assistant are presented as AI. The Assistant panel carries an AI badge and, from the first interaction, a notice that its answers can be wrong and should be checked. The chat shows a notice that AI responses may contain inaccuracies.
- An AI badge marks AI output where it appears next to content written by people: bookkeeping entries, document versions, and document types in the Library and in the document preview. Entries and document types that the Spyral Assistant set at a user's request are labelled as such.
- Relationships that AI infers, such as shareholdings, are labelled as AI suggestions.
When output leaves Spyral
Text that AI writes carries a machine-readable marker (Article 50(2) of the AI Act):
- Word documents. A document version written or edited by AI carries the custom document properties AIGenerated, AIGenerator, AIModel and AIGeneratedAt, and names "Spyral AI" as the author of the last change. The document's own properties and its original author are kept. Word and document management systems can read these properties.
- Exported conversations. An exported conversation contains a meta tag named ai-generated and a generator tag, marks each AI answer and the model that wrote it, and ends with a visible notice that the answers were generated by AI.
- Data sent to your browser. Chat answers, Assistant answers, mind maps and AI edits to documents are delivered with an indicator that they are AI-generated and, where it is known, the model that produced them.
The marking covers text that AI writes. Structured data that AI reads from your own documents, such as document types, company and person details, amounts and proposed bookkeeping entries, reproduces information from the source rather than creating new content. It is labelled in the product as described above but is not separately marked in the files you export from it, such as eCDF filings. Every bookkeeping entry must be reviewed by a person before a filing can be generated.
Markers are lost when AI-written text is copied into another document. If you pass AI-assisted content to a client or a third party, any disclosure that your own obligations require is yours to make. Do not remove or alter the markers in order to present AI output as written by a person to someone who is entitled to know otherwise.
Your data and AI
- No training. Spyral does not use customer content, prompts or AI output to train, fine-tune or otherwise improve any AI model. We send customer content to an AI provider only under terms that prohibit the provider from using it to train its models, and we ask each AI provider for zero data retention. The Sub-processors page shows, for each AI provider, whether these terms are confirmed in writing and whether zero data retention is in effect. Where it is not, the provider may keep requests and responses only for the limited period and purposes its data processing terms allow, such as abuse monitoring.
- Your workspace only. A request to a model contains only content from your own workspace that the requesting user is allowed to see. Content of different firms is never combined.
- EEA or Switzerland only. Spyral restricts AI processing to a list of allowed countries: the member states of the EEA, and Switzerland, which the European Commission recognises as providing adequate protection for personal data.
- Before a model is used, its location is checked against that list: for Nebius, from the provider's published information on where each model runs; for Mistral AI, from the location of its EU service.
- After every call to Nebius, Spyral checks which region actually served it. Nebius states in its terms that the location of its shared models can change without notice, so for Nebius this check, not the contract, is what keeps processing in the allowed countries. If a model was served from outside the list, Spyral blocks that model at once, sends the next request to the next model in an allowed location, logs the event as an error and informs the customers concerned, as the Data Processing Agreement provides. A request that reached the model before the block took effect will already have been processed at the reported location.
- If no model in an allowed location is available for a function, the function stops with an error. Spyral never falls back to a provider or a region outside the list.
- Spyral records which provider and model handled each AI call and, where the provider reports it, the region that served it, so that we can tell a customer where its documents were processed.
- Sub-processors. AI providers process customer data as our sub-processors under the Data Processing Agreement. They are listed, with their locations, on the Sub-processors page.
What we ask of firms using Spyral
- AI literacy (Article 4). Make sure the people who use Spyral's AI features understand what the features do, their limitations and the review steps described on this page. This page and the notices in the product support that, but they do not replace your own measures.
- Keep the review steps. Assign competent people to review AI output, use the review flags and the review steps before filing, and do not organise your work so that AI output reaches a filing, a client or an authority without review.
- Disclose where you must. If you publish AI-generated text to inform the public on matters of public interest, Article 50(4) of the AI Act may require you to disclose that it was generated by AI, unless a person has reviewed it and taken editorial responsibility for it. Data protection law, your engagement terms or your professional rules may require you to inform your clients about your use of AI.
- Stay within the intended purpose described on this page.
- Use this page for your records. Regulated firms can use this page and the Sub-processors page for their own AI inventory and for their register of ICT third-party service providers.
- Tell us about problems. Report serious or repeated errors, or output that could cause harm, to contact@spyral.lu, with an example if you can.
Changes to this page
The AI register updates automatically when the configuration changes, for example when a model is replaced by a newer one from the same provider. We publish a new version of this page when we add or remove an AI feature, or change how AI output is reviewed or marked. A new AI provider is a new sub-processor and is announced in advance, as the Sub-processors page describes.
Contact
- Questions about AI in Spyral: contact@spyral.lu
- Questions about personal data: privacy@spyral.lu
- Security issues, including ways to make the AI features misbehave or disclose data: security@spyral.lu
Version history
| Version | Effective from | Status |
|---|---|---|
| 1.0.0 | October 4, 2026 | In force |