1. System description
Specky is a specification-driven project management platform for software teams. AI features, built on third-party general-purpose AI models (Anthropic Claude, OpenAI) accessed via API:
- extract requirements from uploaded project documents and classify their scope,
- propose tasks derived from those requirements,
- compute coverage between specifications and tasks (embeddings-based),
- answer user questions about project content (chat assistant).
Design principle: "AI proposes, human decides." All AI outputs are proposals requiring explicit human review and acceptance. The system contains no auto-apply mechanisms.
2. Role under the AI Act
| Question | Answer |
|---|---|
| Is Spark IT a GPAI model provider? | No. The general-purpose models are provided by Anthropic and OpenAI. Specky does not train, fine-tune, or substantially modify these models. |
| Is Spark IT an AI system provider (Art. 3(3))? | Yes. Specky develops an AI system (the platform integrating GPAI models for a specific purpose) and places it on the EU market under its own name. |
| Is Spark IT also a deployer? | Only of its own system in the course of providing it; customers using Specky in their organizations act as deployers of the system. |
3. Risk classification
3.1. Prohibited practices (Art. 5) — not applicable
Specky performs none of the prohibited practices (no subliminal manipulation, social scoring, emotion recognition in workplace, biometric categorization, etc.).
3.2. High-risk (Art. 6 + Annex III) — not applicable, with documented reasoning
Project management software is not listed in Annex III. The only category requiring careful analysis is Annex III point 4 (employment and worker management), which covers AI systems intended for, among others, work-related task allocation based on individual behaviour or personal traits, and for monitoring or evaluating the performance and behaviour of workers.
Specky falls outside this category because:
- Task generation derives from documents, not from people. Proposed tasks are extracted from project specifications and requirements. The system does not profile individuals, does not process behavioural or biometric signals, and does not base proposals on personal traits of workers.
- No automated task allocation. Specky proposes what needs to be done, not who should do it. Assignment of tasks to people is a manual decision of the customer's project manager. The system makes no recommendation tied to an individual's characteristics or past performance.
- No performance monitoring or evaluation of workers. Coverage metrics measure the relationship between specification and tasks, not the productivity, behaviour, or performance of any person. The system produces no individual-level performance analytics.
- Human-in-the-loop by design. Every AI output requires human acceptance before becoming part of project state.
Standing instruction (product guardrail): features that would introduce individual-level performance analytics, automated assignee recommendations based on personal characteristics or behaviour, or worker monitoring MUST trigger re-classification under Annex III point 4 before development. This document's review is a mandatory step in the design of any such feature.
3.3. Resulting classification: AI system subject to transparency obligations (Art. 50) — "limited risk"
4. Applicable obligations and implementation status
Article 50 transparency obligations apply from 2 August 2026. The Digital Omnibus (provisional political agreement of 7 May 2026, pending formal adoption) does not defer the core disclosure duties; it grants systems placed on the market before 2 August 2026 a grace period until 2 December 2026 for machine-readable marking of AI-generated content (Art. 50(2)).
| # | Obligation | Applies to Specky | Implementation |
|---|---|---|---|
| 1 | Art. 50(1) — inform natural persons they are interacting with an AI system, unless obvious from context | Yes — chat assistant | Persistent, clearly visible label in the chat UI: assistant identified as AI at the start of and throughout the conversation (not only in onboarding). Wording: "You are chatting with an AI assistant. Answers are AI-generated and may contain errors." |
| 2 | Art. 50(2) — machine-readable marking of synthetic (AI-generated) content | Yes — generated task proposals, requirement extractions, chat answers | (a) UI level: visible "AI-generated" badge on proposals until human acceptance; (b) data level: ai_generated: true + model + timestamp metadata persisted on AI-created records and included in exports (JSON/structured exports); (c) monitoring of Commission guidelines and the marking code of practice (draft published; consultation opened 8 May 2026), with format alignment once finalized. |
| 3 | Art. 50(4) — deepfake/public-interest text disclosure | No — Specky generates no image/audio/video content and its text outputs are internal work products, not publications to inform the public | n/a |
| 4 | Emotion recognition / biometric categorization disclosures | No — no such features | n/a; guarded by Section 3.2 standing instruction |
AI literacy (Art. 4, applicable since 2 February 2025): as a provider, Spark IT maintains adequate AI literacy for persons operating the system on its behalf (currently: the operator). Customer-facing measure: documentation explains capabilities and limitations of AI features (accuracy disclaimer in Terms of Service Section 2, in-product labeling).
5. Relationship to other documents
- Terms of Service Section 2 — contractual disclosure of AI-assisted nature, human review responsibility
- Privacy Policy Section 4 — factual description of AI processing flow and provider commitments
- DPA Annex 1–3 — processing of personal data within AI pipeline, sub-processor list
- This document — classification reasoning and Art. 50 implementation mapping
6. Monitoring and review triggers
This classification is reviewed: (a) every 6 months; (b) upon formal adoption of the Digital Omnibus and publication of Art. 50 Commission guidelines / marking code of practice; (c) upon adoption of the Polish implementing act (national supervisory authorities and penalty framework); (d) before development of any feature touching individual-level analytics, assignee recommendation, or worker monitoring (Section 3.2 standing instruction); (e) upon change of AI providers or addition of new modalities (image/audio generation).
Key dates:
- 2 Aug 2026 — Art. 50 disclosure obligations apply (item 1 in Section 4 must be live)
- 2 Dec 2026 — end of grace period for machine-readable marking for systems on the market before 2 Aug 2026 (item 2(b) must be complete)
- 2 Dec 2027 — deferred Annex III high-risk deadline (relevant only if classification changes)
Penalty context: non-compliance with transparency obligations carries administrative fines of up to the thresholds set in Art. 99 (for transparency breaches, up to EUR 15M or 3% of worldwide annual turnover, whichever is higher — proportionality for SMEs applies).