Looking for a Shorter Overview?
AI Summary
Key Moments
Transparency requirements in the EU AI Regulation
Since August 2026, some AI systems are required to indicate when AI is involved, which should increase user understanding.The difference between visibility and mandate
VORTIQ-X points out that labels show the AI's presence but not who approved the action or decision behind it.VORTIQ-X's decision architecture
Proposes a separate decision point before execution to verify that an AI action complies with a valid mandate.Five key questions for AI procurement
Organizations should ensure, among other things, that the decision point is precise and that verifiable evidence is available even in the event of rejection.Article 50 of the EU AI Regulation applies since August 2, 2026 and contains new transparency requirements for, among other things, certain interactive AI systems, deepfakes and AI-generated or manipulated content.
This is part 2 of 7 in IT-Branschen's article series about VORTIQ-X and Authorized Demand. Read part 1: Authorized Demand – a new metric for the AI market.
Since August 2, 2026, the EU has applied new transparency requirements for, among other things, certain interactive AI systems, deepfakes, and AI-generated or manipulated content.
The aim is for people to be able to understand when they are communicating with an AI system and when content has been created or changed by AI. However, transparency requirements do not answer all the questions that arise when AI is allowed to influence data, money or business systems.
It is here VORTIQ-X places its offering. The company's thesis is that visibility and mandate are two different control problems.
A label can show that AI has participated in a process. It does not automatically show who approved an agent to read a patient record, copy customer data to a search index, send data to another country, call a payment tool, or make a permanent change in a business system.
”A label shows that AI was involved. A verifiable decision shows why the action had to become real,” says Raymond Steen, founder and CTO of VORTIQ-X.
From post-mortem log to pre-execution decision
In many AI environments, control is distributed across identity services, model protection, security tools, agent platforms, destination systems, and logging. Each component may be necessary.
VORTIQ-X believes that a gap can still arise if the same technical environment both proposes, communicates and implements an action and then produces the documentation that explains what happened.
The company's proposed architecture therefore places a separate decision point before the actual consequence. A model or agent may propose an action, but it may not itself create the authority that allows the action to be executed.
It is a narrower task than determining whether processing is lawful. The organization, its lawyers, data protection officers and responsible decision-makers still have to determine the purpose, legal basis, data needs, recipients, retention period and other conditions.
According to VORTIQ-X, the task of the technical system is to be able to show two things:
RESPONSIBLE ASSESSMENT EXISTS AND IS CURRENT
THE DECLARED LIMIT WAS FOLLOWED
However, it should not issue a general statement that an action is ”legal”.
Data protection decisions show why actual processing matters
Two major decisions by Ireland's Data Protection Authority, the DPC, illustrate the difference between documented arrangements and the processing that actually takes place.
In 2023, the DPC decided on an administrative penalty fee of EUR 1.2 billion against Meta Platforms Ireland in a case concerning transfers of personal data from the EU and EEA to the US. The DPC assessed that the standard contractual clauses and supplementary measures used did not address the risks identified by the CJEU.
In a separate decision in 2025, TikTok was fined a total of €530 million following an investigation into transfers of EEA users' data to China and the information provided about those transfers.
The decisions apply to GDPR, not Article 50 of the AI Regulation, and they do not demonstrate that VORTIQ-X or any other single technology had solved the legal issues. However, they illustrate why an organization must be able to reconcile its documented assessment with what the systems actually did.
A condition tied to a precise action
VORTIQ-X describes an AI permit as a one-way ticket: right traveler, right trip, right destination and right time. If any of these conditions change, a new decision is required.
For an individual data flow or an individual AI action, the decision can be tied to, among other things:
- identified person, service, model or agent
- exact working torque, target and payload
- the records and fields needed
- purpose and current performance assessment
- recipient and jurisdiction
- validity period and storage rule
- security, identity and recovery conditions
- maximum number of permitted uses
- the right of the receiving system to apply a stricter local rule
This is especially relevant in AI environments where the same task may appear in model context, RAG index, agent memory, tool calls, telemetry, logs, and stored responses.
The company's registered VXBound qualification
VORTIQ-X has tested the principle in a proprietary technical qualification of VXBound, the company's warehouse for controlled data intake and release.
The run was conducted on HPE bare-metal infrastructure and included 64 local model calls using DeepSeek and Qwen across eight AI-related data surfaces. These included model context, RAG indexing and search, agent memory, tool payloads, telemetry, and stored responses.
According to the frozen results:
- completed 16 out of 16 registered legitimate data flows
- all 48 restricted data flows were not given release authorization
- 16 out of 16 attempts to reuse an expired authorization were rejected
- none of the registered prohibited consequences were implemented
- the legitimate data set was reduced from 5,056 to 624 bytes through a minimum-necessary transformation
- a standalone, VORTIQ-X-built verifier rejected all 14 recorded changes to the evidence
The result shows what the recorded technical configuration did. It does not show that software can determine what is legal, that all data transfers outside the test limit are prevented, or that the solution has been customer or government certified.
HPE provided the infrastructure for the run. The qualification was powered and verified by VORTIQ-X and should not be described as an HPE certification or independent third-party validation.
From transparency to operational mandate
The European Commission's Article 50 guidelines focus on people being informed when they interact with certain AI systems and on certain AI-generated or manipulated content being identifiable.
VORTIQ-X seeks to address a related but different layer: whether an organization can tie a precise AI-driven action to a current business mandate before execution and subsequently produce verifiable proof of execution, limitation, or refusal.
It could be relevant for banks, healthcare providers, governments, energy companies, defense organizations, and industrial companies that want to move AI from analysis and drafting to production documents.
The commercial question is not just how much AI capacity an organization has purchased, but how many economically significant workflows it is actually prepared to approve for production.
Five questions for purchasing and supervision
According to the proposed model, organizations that procure AI with the right to influence data or operations can ask five questions:
- Where does the final decision point before execution take place?
- Is the authorization tied to a precise action, data set, recipient, and validity period?
- Can the receiving system apply a stricter local rule?
- Is there verifiable evidence even when an action is refused or restricted?
- Can the data be verified without an active service from the model or verification provider?
Article 50 makes certain AI systems and AI results more visible. VORTIQ-X wants to make the mandate behind the subsequent action operational and verifiable. Whether the company can demonstrate the same characteristics in customer operations remains to be tested in each concrete integration.
Sources and editorial notes
- European Commission, Guidelines on transparency obligations under Article 50:
https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations - European Commission, Questions and Answers on Article 50:
https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act - Irish Data Protection Commission, Meta Ireland and transfers to the USA:
https://dataprotection.ie/en/dpc-guidance/decisions/inquiry-concerning-data-transfers-eueea-us-meta-platforms-ireland-limited-its-facebook-service - Irish Data Protection Commission, TikTok and transfers to China:
https://www.dataprotection.ie/en/news-media/latest-news/irish-data-protection-commission-fines-tiktok-eu530-million-and-orders-corrective-measures-following - VORTIQ-X, benchmark and qualification materials:
https://vortiqxconsilium.com/benchmark
Transitional rule: Article 50 applies from 2 August 2026. A limited transition to 2 December 2026 applies only to systems placed on the market before 2 August 2026 and only to the obligation in Article 50(2) on machine-readable marking and detectability.
Source delimitation: VXBound performance data comes from VORTIQ-X's own controlled technical documentation. The external sources verify the regulatory framework and DPC decisions, not the performance of the VORTIQ-X product.
Editorial transparency: Raymond Steen has provided the product's technical thesis and commentary. IT-Branschen is responsible for fact-checking, headlines, selection and the final editorial assessment.
