Cette page n'est disponible pour l'instant qu'en anglais.

AI Act Article 50 — Transparency disclosure

Where NetSenX uses AI, and how we govern it.

Under Article 50 of the EU AI Act (Regulation 2024/1689), providers of AI systems must disclose to users when AI is involved in decisions that affect them. NetSenX provides this disclosure proactively — even for components where it is not strictly required.

Last reviewed: 2026-05-21 · Owner: Data Protection Officer · [email protected]

Section 1

Where AI is used in NetSenX

Three distinct components use AI. Each has a documented scope, a governance owner, and a customer-visible opt-out where applicable. We use the marketing names below; the internal model architectures are proprietary and not material to the user-facing transparency obligation.

Proprietary LGGT+ engine

Detection · governed by ISO 42001

Behavioral analysis using multi-valued logic. Used to classify network sessions on a continuous risk spectrum.

  • Internals are proprietary; the bounding method — split-conformal prediction at a stated confidence level — is published, so the construction can be checked independently. The bound in force for your tenant, and the calibration size behind it, are shown in-product.
  • Does not train on customer data by default. Bootstrapped on anonymised reference corpora.
  • Governed by an ISO 42001 AI Management System with quarterly risk-register review.
  • Outputs a calibrated risk score plus an evidence trail — not a black-box yes/no.

NetSenX AI Analyst Core

Explanation · opt-out available

Generates plain-language analyst notes for detected alerts. Operates only on metadata already classified by the detection engine.

  • Does NOT make autonomous response decisions. Auto-Response is a separate, rule-driven subsystem.
  • Reads only the metadata produced by the LGGT+ engine — never raw payloads.
  • Customer can disable AI Analyst Core in dashboard settings; detection continues without it.
  • All notes are logged into the immutable audit trail alongside the underlying alert.

NetSenX FastStart

Cold-start · federated · privacy-preserving

Privacy-preserving cold-start detection. Uses anonymised cross-customer patterns to bootstrap detection on day one without exposing customer data.

  • Federated by design — no raw customer data leaves the customer's tenant.
  • Cross-customer patterns are aggregated and anonymised before use.
  • Customer can opt out at provisioning time; detection runs on local baselines instead.
  • Reviewed by the AIMS Risk Committee at every model refresh.

Section 2

What NetSenX does NOT use AI for

The negative space matters as much as the positive. The following are explicit non-uses, documented here so customers can rely on them in their own risk assessments.

  • Automated blocking without human review

    The Auto-Response Tier executes pre-approved, customer-authored playbooks. It is not LLM-driven. An LLM never decides to block, isolate, or quarantine on its own.

  • Profiling of individual users

    NetSenX is a network detection product. We operate on flow metadata between machines. We do not build user-level behavioural profiles, and we do not produce employee-monitoring outputs.

  • Training on customer data without consent

    By default we do NOT train any model on customer data. Customers who explicitly opt in to a private fine-tune receive their own tenant-isolated model and a signed data-use addendum.

Section 3

Customer rights

Every right below is implemented in the product. Nothing on this list is a policy document with no engineering behind it.

Right to explanation

Every AI-influenced alert ships with a human-readable analyst note plus the underlying evidence trail. You can see exactly which signals contributed.

Right to opt out

Disable AI Analyst Core in dashboard settings. Detection continues without it. FastStart can be turned off at provisioning time.

Right to portability

Export all your alerts and analyst notes as JSON, at any time, with one API call. Standard GDPR Article 20 — implemented as a product feature, not a paperwork process.

Right to audit

Full immutable audit log of every AI-derived decision. Available via dashboard and API. 10-year retention on Enterprise.

Section 4

Risk classification under the AI Act

Our classification

NetSenX, considered as a whole, is a limited-risk AI system under the AI Act. It informs human decisions but does not make legally significant autonomous decisions. Transparency obligations under Article 50 apply.

What we voluntarily adopt

We voluntarily adopt high-risk-system practices for the AI Analyst Core (logging, monitoring, transparency, post-market surveillance). We expect those practices to become baseline EU procurement requirements by 2027.

Customers operating NetSenX in critical-infrastructure or public-administration contexts may, depending on their own deployment, be using it inside a higher-risk regulated workflow. We provide the documentation (model cards, evidence packs, AIMS records) needed for the customer's own conformity assessment.

Section 5

Governance and ISO 42001 AIMS

Every AI component is managed inside an ISO/IEC 42001-aligned AI Management System (AIMS). Certification audit scheduled for Q3 2026.

AI risk register

Reviewed quarterly by the AIMS Risk Committee. Risks are scored, owned, and tracked to closure with documented mitigations.

Data quality and bias monitoring

Training and reference data are profiled for representativeness, drift, and label quality at every refresh. Findings are recorded in the AIMS register.

Lifecycle management

Every AI component has an explicit lifecycle: introduction → operation → retirement. Retirement is triggered by performance degradation, drift, or regulatory change.

AI incident response

A documented runbook covers AI-specific incidents (data leak, prompt injection, model misbehaviour, supply-chain compromise). Tested in our annual tabletop exercise.

Section 6 — Contact

AI-related questions go straight to the DPO.

The Data Protection Officer is also the AI-accountability owner. One contact, one accountable person, one audit trail.

[email protected] · acknowledged within four EU business hours