AI Use and Compliance
Exactly what the AI-assisted features do, what they are prevented from doing, and how to evidence that to a supervisor.
Last updated 2026-07-28
Why this notice exists
Treica's customers are regulated financial entities. Many of them must be able to tell a supervisor precisely whether, where and how AI is involved in a regulatory process, and many must be able to refuse AI processing outright. This notice is written so that it can be handed to a reviewer as it stands.
It describes behaviour that is enforced in the product, not intentions.
AI is off unless two independent conditions are both met
- The workspace must be on the Premium plan (an entitlement).
- An owner must have switched AI on for that workspace (a kill-switch, default off).
- If either is absent, no model request is made at all - the feature is not merely hidden.
- Removing the entitlement stops AI immediately, without anyone having to remember to change the switch.
- Switching AI on or off is an owner-level action and is recorded in the immutable audit log with the actor and timestamp.
AI suggests; a person decides
No AI feature writes a record, sets a compliance status, approves anything, closes a finding, or produces a filing. Output is presented as a suggestion beside the relevant form. A person then enters or confirms the value, and the audit trail attributes that entry to that person, because they made it.
It follows that every clause status, register value, assessment outcome, risk acceptance and remediation decision in a Treica workspace was made by a named human being.
The four features, and what each one receives
| Feature | What is sent | What comes back | What it cannot do |
|---|---|---|---|
| Contract clause coverage | The contract PDF or text you supply, plus the obligation texts | A suggested status per obligation with the supporting quotation and a reason | Set a clause status or raise a finding |
| Register field proposals | The same contract you supply | Proposed field values, validated against the product's own coded lists and formats; unstated fields returned empty | Create or amend an arrangement |
| Supplier response review | The questions and answers of that one assessment | Answers worth challenging, with severity, the concern and a suggested follow-up question | Score, approve or reject an assessment |
| Validation explanation | One validation result: its code, severity, record type and message | Plain-language meaning, supervisory relevance and remediation steps | Acknowledge, clear or alter a finding or any record |
What is never sent
- Your register as a whole, or any record you did not submit for that specific action.
- Evidence files other than the document you explicitly uploaded for that action.
- User credentials, API keys, or audit records.
- Data from any other workspace - isolation applies to AI actions exactly as it does to every other read.
Provider, location and training
Model access is provided through Vercel's AI Gateway to Anthropic models. Content submitted through the gateway is not used to train models.
Requests are authenticated by the deployment's own short-lived credential; no long-lived model provider key is stored by us for this purpose.
The applicable provider terms and data processing terms are those of Vercel Inc. and Anthropic PBC, referenced in our sub-processor list at [SUB-PROCESSOR LIST URL].
Accuracy, and the limits you should assume
Language models can be wrong, including confidently. Treica reduces the consequences structurally rather than promising accuracy: suggestions are never applied automatically, the clause reader must quote the supporting sentence so you can check it, proposed coded values are discarded unless they match the product's own permitted values, dates and amounts must parse before they are shown, and a field the document does not state is returned empty rather than guessed.
The supplier-response reviewer states explicitly when it finds nothing, and that a clean pass is not an assurance. The validation explainer marks its output as AI-generated guidance to be checked against the record.
You should treat every suggestion as an unverified draft prepared by an assistant.
Relationship to the EU AI Act
The features described here assist a human with drafting and reading. They do not make decisions about individuals, do not perform biometric or emotion inference, and do not determine access to a service, employment or credit. On that basis we consider them limited-risk assistive systems rather than high-risk systems under the AI Act, and we meet the associated transparency expectation through this notice and the in-product labelling of every suggestion.
This is our assessment of the product as built; your own classification of your use of it remains yours to make. Treica includes an AI systems register in which you can record any AI system your entity uses or provides - including this one - with its risk classification, provider, oversight arrangements and owner.
We do not present this notice as legal advice on your AI Act obligations.
Refusing AI entirely
A customer may remain on the Free plan, or keep the switch off on Premium, and lose no regulatory capability whatsoever. Building the register, validating it, generating and filing the submission package, evidence, assessments, reviews, monitoring, reporting and the audit trail are all available without AI.
That is a deliberate design constraint: your ability to meet a legal obligation must not depend on accepting AI processing.
What to tell a supervisor
- Whether AI is enabled is recorded, and every change to that setting is audited with actor and timestamp.
- No compliance determination is made by a model; every determination in the record is attributable to a named user.
- Only the specific document or answers submitted for an action are processed; the register is never transmitted.
- The firm can disable AI permanently and retain full regulatory capability.
- The AI system itself can be entered in the firm's own AI systems register with its classification and oversight.