GARMTECH is AI Act compliant and meets the requirements of the European Union Artificial Intelligence Act that apply to the roles and services described on this page.
For a solution developed or implemented for a specific customer, compliance depends on the intended purpose, configuration, use and allocation of responsibilities agreed in the contract. GARMTECH reviews its compliance assessment when the solution, its intended purpose or the applicable requirements change.
GARMTECH helps organisations introduce artificial intelligence into business processes responsibly. We provide consulting, design, development, configuration and integration of AI solutions and workflow automation, along with hosted AI agents, hosting and technical support.
Hosted AI agents and OpenClaw
GARMTECH provides infrastructure, deployment, security configuration and technical support for hosted AI agents, including OpenClaw VPS. The customer defines the system's intended purpose and selects the connected AI models, communication channels, data sources and authorised users. GARMTECH operates the components included in the agreed service scope and helps configure the solution with appropriate security, data protection and transparency measures.
The customer remains responsible for the use of the agent, the instructions and data supplied to it, and actions performed through connected third-party services. The parties document responsibilities for a managed service or customer project in the applicable order, service description or agreement.
How GARMTECH uses AI
GARMTECH uses AI to assist authorised specialists with infrastructure alert analysis, technical diagnostics and documentation. AI also helps classify and summarise customer requests and prepare draft responses.
GARMTECH personnel remain responsible for decisions and customer-facing actions. When AI supports an automated action, GARMTECH defines its permissions and operating procedure, keeps an operational record where needed and escalates the task to a specialist. When a customer interacts directly with an AI assistant, GARMTECH identifies it as an AI system and provides access to human support.
We limit the data available to an AI system to what the task requires and apply access, security and retention controls appropriate to the service and risk.
Our role in AI delivery
GARMTECH's role depends on the service and allocation of responsibility for each project:
- we act as an AI system provider when we develop a system and place it on the market or put it into service under the GARMTECH name;
- we act as an integrator or distributor when we configure and implement a third-party AI system;
- we act as a technical supplier when we develop a solution for an intended purpose and requirements defined by the customer;
- we act as a deployer when GARMTECH uses an AI system under its authority.
The customer usually acts as the deployer of a solution used under its authority. The customer determines the intended purpose, authorised users, data sources, human oversight and the processes that use the system's output. Providers of general-purpose AI models remain responsible for their models and services.
How we manage compliance
GARMTECH applies a risk-based approach to AI consulting, development, integration and hosting. Within the scope of each project, we define the solution's intended purpose and operating environment, record the parties' roles and material data flows, assess prohibited practices and potential high-risk use, and establish access controls, human oversight and escalation arrangements. We reassess the solution after material changes.
Methodological basis
GARMTECH applies a documented approach to artificial intelligence risk management and security. We consider and apply the provisions of the EU AI Act that relate to our systems, together with the NIST AI Risk Management Framework and NIST Generative AI Profile, the Google DeepMind AI Control Roadmap and TRAIT&R, OWASP GenAI Security guidance, and TC260-PG-20266A guidance on the secure deployment and use of AI agents. As our AI management system develops, GARMTECH also takes account of the principles of ISO/IEC 42001 and ISO/IEC 23894.
For privileged AI agent systems, GARMTECH applies R2 control principles. The specific measures depend on the system's intended purpose, the data and privileges available to it, and the potential consequences of its actions. Where necessary, GARMTECH applies additional measures beyond those described in these methodologies.
Transparency and human oversight
People should know when they interact with an AI system. For interactive systems, including AI agents and chat services, GARMTECH provides or configures appropriate notices within the agreed scope of work. Customers must keep these notices in place when employees, customers or members of the public use the system.
Where the type of system and our role require it, we also implement or preserve technical marks and labels that help identify AI-generated or manipulated content.
The customer determines which actions require human approval. Decisions that may affect a person's rights, employment, finances, health, safety or access to services require proportionate human control and review.
Customer data, input and AI output
Customers retain their rights to instructions, data and other content submitted for processing and to AI-generated output to the extent permitted by applicable law and the terms of the relevant service.
AI-generated output may contain errors, be incomplete or resemble content generated for another user. Before using or publishing output, customers must review its accuracy, confidentiality, intellectual property implications and legal requirements.
GARMTECH does not use customer data to train general-purpose AI models unless the parties enter into a separate written agreement and establish a lawful basis.
Privacy, security and external services
An AI solution may send information to model providers, communication platforms, search services or other integrations selected by the customer. Within the agreed project scope, GARMTECH identifies material data flows and applies data minimisation, access control and secure credential storage to the components we operate.
Depending on the service, security measures may include isolated hosting environments, encrypted connections, restricted administrative access, operational logging, sensitive-data redaction, backups and software updates.
Reliability and change management
AI systems produce output using probabilistic models. Results may be incomplete, inaccurate or unsuitable for the intended purpose. Customers must apply a level of review appropriate to the purpose and potential effect of using the output.
AI models, platforms, application programming interfaces and other external services may change their features, limits or availability. GARMTECH assesses material changes that may affect security, data flows, transparency, intended purpose or risk classification.
Customer responsibilities
Customers must provide accurate information about the intended purpose, ensure that submitted data is processed lawfully, manage authorised users and review AI output. Customers also provide required AI and privacy notices, maintain human oversight and monitor the solution after deployment.
Customers must inform GARMTECH before materially changing the intended purpose or using the solution in biometrics, employment, education, creditworthiness, insurance, healthcare, critical infrastructure, law enforcement, migration or another regulated field.
Prohibited and restricted use
GARMTECH does not knowingly develop, host or support AI solutions for uses prohibited by the AI Act or other applicable law. GARMTECH may decline a project, restrict support or suspend a service if a customer uses a system unlawfully or outside the agreed intended purpose.
AI literacy
GARMTECH supports the development of AI literacy among employees and specialists who develop, operate or support AI systems. Training reflects the person's responsibilities, technical knowledge and the environment in which the system is used. We also explain the solution's capabilities, limitations, security and responsible operation to customers.
Questions and concerns
If you want to understand how an AI solution provided by GARMTECH works or report harmful output, misuse, a security concern or a privacy issue, please contact us. We assess reports according to their legal, security and operational impact.
Related documents
Last reviewed: 3 September 2026