EU ARTIFICIAL INTELLIGENCE ACT ADDENDUM
To the extent applicable, the following terms form part of the DPA and Services Agreement between the parties:
Artificial Intelligence Processing & EU AI Act Compliance
Scope and Definitions.
This Section applies solely to the extent that the Services provided by Egnyte involve the processing of personal data via artificial intelligence systems ("AI Systems"), as defined under Regulation (EU) 2024/1689 (the "EU AI Act").
For the purposes of this Section and the EU AI Act and as between Egnyte and Customer, Egnyte shall act as the "Provider" and Customer shall act as the "Deployer" of the AI Systems.
"Input Data" means any personal data, text, prompts, images, or instructions submitted by Customer or its authorized Users into the AI Systems.
"Output Data" means the predictions, content, recommendations, or decisions generated by the AI Systems based on Input Data.
Egnyte (Provider) Obligations. Egnyte agrees to implement and maintain technical and organizational measures to ensure compliance with its applicable obligations under the EU AI Act, including:
Instructions for Use: Providing Customer with clear, digital instructions for use and technical documentation outlining the intended purpose, operational boundaries, and known limitations of the AI Systems.
Logging Capabilities: Ensuring that the AI Systems automatically generate and retain logs of operational events to the extent necessary to monitor system performance and detect anomalies.
Security and Quality: Maintaining appropriate data governance, cybersecurity protections, and quality management systems, in line with industry standards.
System Transparency: Where required under applicable law, assisting Customer as reasonably necessary for Customer to fulfill its transparency and end-user notification obligations under Article 50 of the EU AI Act.
Customer (Deployer) Obligations. Customer represents, warrants, and covenants that it shall:
AI Literacy: Ensure that all staff, employees, or contractors operating or managing the AI Systems have a sufficient level of AI literacy, considering their technical knowledge and the context of use, in accordance with Article 4 of the EU AI Act.
Compliance with Instructions: Use and deploy the AI Systems strictly in accordance with the Agreement and implement appropriate human oversight mechanisms over the Output Data before it is acted upon or incorporated into critical business workflows.
Input Data Quality: Ensure that all Input Data provided to the AI Systems is legally sourced, relevant, and sufficiently representative for its intended use, and that Customer has obtained all necessary consents or lawful bases required under Data Protection Laws and Regulations.
User Notifications: Fulfill all end-user transparency mandates, including explicitly informing natural persons (such as Customer's employees or clients) when they are directly interacting with an AI System or when content has been artificially generated or manipulated, unless the context makes it completely obvious.
Prohibited AI Practices & Risk Classification.
Customer is strictly prohibited from using the AI Systems for any "Prohibited AI Practices" outlined in Article 5 of the EU AI Act (including but not limited to subliminal manipulation, social scoring, or unauthorized biometric categorization).
Customer shall not utilize the AI Systems within "High-Risk" use cases as defined in Annex III of the EU AI Act (such as employment evaluation, creditworthiness scoring, or critical infrastructure management).
Incident Reporting and Cooperation.
Customer shall immediately, and in no event later than forty-eight (48) hours, notify Egnyte if it becomes aware of any serious incident, anomaly, or malfunction of the AI Systems that risks causing harm to the health, safety, or fundamental rights of individuals.
The parties agree to cooperate in good faith, exchange necessary technical documentation, and assist each other where applicable in responding to inquiries, audits, or enforcement actions brought by the EU AI Office or other applicable data protection authorities.