Information Relating to the EU AI Act
Information on our AI-based solutions
With DuPa Recovery, zapliance GmbH offers an AI-based software solution for detecting duplicate payments and unclaimed VAT.
This article provides an overview of the use of AI in our software and relevant information regarding the EU Artificial Intelligence Act (‘EU AI Act’). It specifically applies to the Content Bundle DuPa Recovery.
What is DuPa Recovery?
DuPa Recovery (Duplicate Payment Recovery) uses artificial intelligence (machine learning) to identify multiple entries of liabilities (‘duplicate payments’) and unclaimed, deductible input tax (‘lost VAT’) within an SAP client. This allows duplicate payments and lost VAT within a group to be analysed, identified and recovered across company boundaries.
With the help of DuPa Recovery, the user checks whether there has been a dupplicate payment or lost VAT and evaluates the results of the check (‘professional judgement’). The final responsibility for the use of the results lies with the user.
More information on the functionality can be found in this article.
Optionally, a customer-owned LLM (e.g. Azure OpenAI) can be integrated to perform document analysis (OCR).
Separation of Data Extraction and AI-Supported Processing
The zapliance solution architecture separates deterministic SAP data extraction from AI-supported processing. SAP data is extracted through RFC according to the scope defined and approved by the customer and stored as copies in a separate project database.
DuPa Recovery operates exclusively on these extracted data copies. The AI does not access SAP, use RFC, determine which SAP data is extracted, or initiate additional data extractions. All data extractions are initiated by the customer.
For more information, see SAP Governance Data Extraction with zapliance.
Classification According to the EU AI Act
Applicability of the EU AI Act:
DuPa Recovery falls under the provisions of the EU AI Act. The software is an automated system that independently generates relevant results based on input data.
Type of AI system:
zapliance does not offer a general-purpose AI model (GPAI) as defined in Article 3 of the EU AI Act, but rather a specialised AI system for detecting duplicate payments and lost VAT. If customer-owned LLMs are integrated, the customer retains full control and responsibility for the integrated AI solutions.
Training the AI model:
zapliance uses the transmitted data to improve its proprietary model for detecting duplicate payments and lost VAT. The transmitted data does not contain any personal data or data that could be used to identify business partners.
Role of zapliance:
Within the framework of the EU AI Act, zapliance assumes the role of the provider, while the customer acts as the deployer. zapliance develops the AI solution and places it on the market. The customer operates the solution on-premise in their own IT environment.
When integrating customer-owned LLMs, the customer retains complete control and responsibility for the integrated AI solutions. In this case, zapliance merely acts as an integrator of customer-owned AI.
Prohibited or high-risk application:
The solution does not fall under the prohibited or high-risk AI systems classified in Articles 5 and 6 of the EU AI Act. No sensitive or personal data is processed, and no decisions are made about people that could be classified as critical.
Transparency:
The zapliance AI model utilized for DuPa Recovery does not interact directly with the user, but performs data analyses in the background to detect duplicate payments and lost VAT. This is communicated during the sales process and onboarding.
Risk Control Measures
Local data processing:
The analyses are not performed at zapliance or in a cloud, but in the customer's IT environment. The data is stored there in a locally secured database that is completely under the customer's control.
Access restriction:
By default, zapliance does not have access to the customer's database or software. Data leaves the customer environment exclusively for specific purposes, controlled and initiated by the customer. If customer-approved access is required in a specific situation (e.g. support), it remains temporary, purpose-limited, and time-bound. The customer determines the granted permissions and when access is removed.
Data protection:
The AI data actively transmitted to zapliance by the customer within the scope of the purpose-specific provision does not contain any personal data or data that could be used to identify customers or business partners.
Data minimization:
Only the data required for a specific analysis is extracted from SAP. The extraction scope is approved by the customer.
Human control:
The customer's users initiate and control all data extractions. The results produced by the AI are reviewed by the users.
Error handling:
If anomalies are detected, the customer reports these to zapliance, whereupon zapliance handles the error resolution.
Conclusion
zapliance and DuPa Recovery meet the requirements of the EU AI Act for specialised low-risk AI systems. No personal data is processed and comprehensive risk control measures are in place.
Any questions?
Feel free to email us at support@zapliance.com.