How Basewise approaches the EU AI Act: what we had assessed, and what it means for our clients
As a founder, I have been asked the same question by clients again and again over the past year: "Will your tools need an AI label or a watermark, and what does that mean for us?" It is exactly the kind of question a vendor should not answer on gut feeling. So Basewise had it properly assessed, before clients needed to ask. This article starts with what the AI Act is, when it takes effect and why it affects every company that works with AI. Then we go deeper: what the assessment found for the Basewise tools, and what that means for you.
01 | What is the EU AI Act?
The AI Act, formally Regulation (EU) 2024/1689, is the first comprehensive law in the world to regulate artificial intelligence as such. It entered into force in August 2024 and applies directly in all EU member states, without the need for national legislation. Its purpose is twofold: to protect people from the risks of AI, and to create a level playing field for companies that develop or use AI in Europe.
At the heart of the law is a risk-based approach. Not every AI system is treated the same: the greater the risk to safety, health or fundamental rights, the stricter the requirements. The law distinguishes four levels.

The Basewise tools are decision-support applications intended for professionals who assess the output themselves. For that type of application, the law is mostly about the transparency rules in Article 50. That is what the rest of this article is about.
02 | When does what take effect?
The AI Act does not take effect all at once, but in phases over a period of four years. In July 2026 an amendment was adopted, the so-called Digital Omnibus, which postponed the heaviest requirements for high-risk systems. The transparency rules were not moved.
03 | Why this affects every company that works with AI
A common misconception is that the AI Act only applies to companies that build AI. That is not the case. The law addresses two groups: providers, who develop an AI system and place it on the market, and deployers, the organisations that use an AI system under their own responsibility. Anyone who uses an AI tool in their own work therefore also falls under the law, although the obligations are lighter than those of the maker.
For most companies working with AI, it comes down to a few concrete things. Staff who work with AI systems need a sufficient understanding of what those systems can and cannot do. AI must not quietly make decisions that affect people; human oversight must remain in place. And anyone who procures AI tools is entitled to expect the supplier to explain how the system works, what the risks are and how data is handled.
The necessity is not only legal. Fines can be substantial, but in practice the greatest pressure is commercial: clients, contracting authorities and regulators increasingly ask for demonstrable diligence. Having to say that it has not been looked into yet puts you at a disadvantage. That is why Basewise did not wait for someone to ask.
04 | What Article 50 is about
For users of tools such as those of Basewise, the AI Act is mostly about Article 50, on transparency. That article regulates three things that matter in practice.
First: people must know when they are dealing with an AI system rather than a human. Second: content generated by AI, such as text, images or audio, must in many cases be made recognisable, for example with a digital watermark or metadata. Third: separate rules apply to matters such as emotion recognition, biometric categorisation and deepfakes.
05 | What Basewise had assessed
The assessment focused on the three requirements applications: DRE, which extracts requirements from specification documents and, on request, rewrites them in formal INCOSE style; RQA, which checks requirement texts against quality rules and proposes improved wording; and REF, which compares evidence documents against a specification and assesses whether each requirement has been demonstrated.
The approach was deliberately thorough. For each application, we mapped exactly where AI is called, what each call produces, whether a person sees that result, and whether it can leave the application, for instance through an export. Only on the basis of that inventory was it determined, per type of output, what the law says about it.
06 | The outcome: no watermarking obligation, and why
DRE, RQA and REF do not need a digital watermark or signed metadata today. This is down to two independent reasons.

The first: a large share of what these tools produce, such as a score, a verdict or a structured result, is not "generated content" in the sense of the law at all, according to the European Commission. The same goes for text that is copied verbatim from your own document and arranged.
The second: the text the tools do formulate themselves, such as a rewritten requirement or a quality finding, falls under an exemption the law makes for business-to-business, technical applications. It applies when the work is technical in nature, used by a limited group of professionals within an organisation, and when the output is an intermediate product that is reviewed by a person before it goes anywhere. That is exactly how the Basewise tools are set up.
07 | Why that is no coincidence
Basewise designed its tools from the outset as an aid to the engineer, not a replacement. A score or a proposed rewording is an indication, not a ruling. The review step is not in the tools because the law demands it, but because that is simply how requirements work should be done: a specification that leaves the building is the work of a person who takes responsibility for it.
That design principle now also turns out to be the right choice legally. If an AI tool were to produce text intended directly for an external audience, or converse independently with end users, a very different regime would often apply and marking would be mandatory. The difference lies not in the technology, but in what is produced and for whom.
08 | Transparency that is already live
Aside from the watermarking question, the first transparency requirement, knowing that you are working with AI, has already been met. Since the end of August 2026, all five Basewise applications, DRE, RQA, REF, AI Assistant Chat and Knowledge Chat, show a clear notice on first use with a link to the full AI Transparency & Disclaimer Notice. AI-generated content is also visibly labelled as such.
That notice also states explicitly what Basewise's AI is not used for. Should that ever change, the notice will be updated before such a feature becomes available.

09 | What happens to your data
For the documents, requirements and messages you process in the platform, Basewise acts as a processor: your organisation remains the owner and decides what happens to them. Basewise processes that content only to deliver the feature you are using. No data is sold, and the data is not used to train or fine-tune AI models, not by the infrastructure providers Basewise works with either. Processing by AI models is transient: no copy of your input is retained after generating a response.
| Type of data | Retention period |
|---|---|
| Account data | Until cancellation or deletion of the account |
| Usage and security logs | 184 days |
| Documents, requirements and AI output | 365 days, or sooner if you delete them yourself |
Hosting and processing take place within the EU/EEA, with the sole exception of Basewise's technical implementation partner, which is established in the United Kingdom. That transfer is covered by the EU adequacy decision for the UK. A current overview of all subprocessors is available on request.
10 | What this means for you as a client
In summary, it comes down to four things you can count on.

11 | What you can do yourself
The AI Act also places a number of expectations on organisations that use AI: make sure that staff working with the tools sufficiently understand what AI can and cannot do, and keep human review in place. Basewise's transparency notice and documentation are intended to help you with that. If you have questions or complaints about the AI systems, you can contact contact@basewise.ai. Within the EU you also have the right to lodge a complaint with the market surveillance authority of your member state, and for privacy matters with the Dutch Data Protection Authority or your own national supervisory authority.
12 | What happens next
A compliance position is not a one-off outcome but a commitment that has to be maintained. With every new feature, Basewise reassesses whether the conclusion still holds. A feature that, for example, produces summaries for an external audience may well fall under the marking obligation, and will then be set up accordingly before it goes live. Basewise also follows the development of European standards for machine-readable marking, so that these can be applied the moment it becomes useful and mandatory.
Finally, a personal note
I understand that the AI Act still feels abstract to many of you, another rule, another thing to keep an eye on. What I want is for compliance at Basewise not to be something we improvise once a regulator asks, but something that is simply in order the moment you open our product.
To me, taking this off your plate does not mean promising that nothing will ever change. It means that we have already looked into it properly, that we keep doing so with every new feature, and that you can always come to us with questions.
Feel free to email contact@basewise.ai, I read along.
Christian van Eken
Founder & CEO, Basewise
contact@basewise.ai
You May Also Like
These Related Stories

When AI reads what isn’t there

The symbiotic Systems Engineer: AI that signals, humans who decide
.png)
