Skip to main content

Pensero and the EU AI Act

What the AI in Pensero does, how it is classified under the EU AI Act, the position on each obligation, and what the deployer is responsible for.

Written by Wayne

Pensero informs, a human decides. That principle governs the design of the product and answers most questions about its position under Regulation (EU) 2024/1689, the EU AI Act. This article describes what the AI in Pensero does, how the system is classified, the position on each relevant provision, and the obligations that sit with the customer as deployer.

What the AI in Pensero does

Pensero measures engineering delivery: increasingly the work of AI agents, and alongside it the human work around them. AI models read work artifacts — a pull request, a ticket, a document, a review, an agent session — and describe them: the size of a change, its complexity against the organisation's own rubric, the category of work it belongs to, what a day of delivered work evidences about capability. Everything downstream of those descriptions (points, percentiles, rankings, trends, cost per delivery) is arithmetic that resolves to individual work items.

Where the subject of a measurement is a person, the output is evidence-grounded insight with full traceability, and any AI-produced input can be overridden by an authorised human. Override is always available; it is not a claim that every output is reviewed before it appears. Outputs are not individually human-supervised, and the result complements human criteria rather than substituting for it. How individual Impact is measured, evidenced, and overridden documents the evidence chain in detail.

What Pensero does not do

  • Pensero makes no decision about a person. No output is written back to an HR, payroll, performance or identity system, and no threshold labels a person as under-performing, high potential or at risk.

  • Pensero does not infer the emotions, mood or attitude of people at work.

  • Pensero does not use biometric data, facial analysis, emotion recognition from face or voice, keystroke logging or screen monitoring, and does not read private messages or meeting contents.

  • Pensero does not infer protected characteristics and does not predict resignation.

  • Pensero does not profile people. It measures the impact of the work they deliver, and every measurement resolves to the work items behind it.

Classification under the AI Act

Pensero is a provider of an AI system intended to be used for the evaluation of the work-related performance of people in a work relationship, assessed from delivered work outcomes. That places the system in the high-risk class under Annex III, point 4(b). The exception in Article 6(3) for systems performing a narrow procedural task, or improving the result of a previous human activity, is not claimed. Pensero does not profile people: it measures the impact of the work they deliver, item by item. The system stays in the high-risk class because those measurements may be used in the evaluation of people at work.

Under the Digital Omnibus (Regulation (EU) 2026/1744) the obligations attached to Annex III high-risk systems apply from 2 December 2027. The prohibitions in Article 5 apply already; none of them covers a capability in Pensero.

Article 25 makes a customer a provider if it rebrands the system or repurposes it. The Terms of Service permit neither: the licence is non-transferable, non-sublicensable and limited to the customer's internal business purposes, and modification, resale, sublicensing and distribution are prohibited (sections 4.9.2 and 4.9.3). Customers accordingly remain deployers; anything further requires Pensero's written consent and carries the provider role with it.

Pensero is a US company. The Act applies to providers outside the Union whose systems are used within it, and establishment in the Union is not required.

Position on each relevant provision

Provision

What it requires

Position

Art. 2 — territorial scope

Binds providers established outside the Union where the system, or its output, is used in the Union

Pensero is a US company and is caught on that basis; establishment in the Union is not required, and the obligations rest with Pensero, discharged in the Union through an authorised representative (Art. 22).

Art. 3 — roles

Provider and deployer are distinct roles with distinct duties

Pensero is the provider of the system; the customer is the deployer. In relation to the general-purpose models Pensero builds on, Pensero is a downstream provider rather than a GPAI provider; the Art. 53 and 55 duties sit with the model vendors.

Art. 4 — AI literacy

Provider and deployer ensure a sufficient level of AI literacy among staff operating the system

Applies to both roles. The Pensero team has been trained on AI literacy, on the system itself and on its AI Act obligations; Pensero publishes methodology and limitations for every metric, supplies training material for managers, and delivers customer training on demand. Ensuring that readers of the output are trained remains the deployer's part.

Art. 5(1)(f) — emotion inference at work

Prohibited, with narrow medical and safety exceptions

Not implicated. Pensero does not infer the emotions of a person in the workplace, and no score, ranking or threshold takes an affective input.

Art. 5 — other prohibitions

Subliminal manipulation, exploitation of vulnerability, social scoring, predictive policing, biometric categorisation, untargeted face scraping, real-time remote biometric identification

Not implicated. Pensero performs no biometric processing and produces no general-purpose social score used outside its context; scores are engineering delivery metrics used inside the employment relationship in which they were measured.

Art. 6(3) + Annex III 4(b)

High-risk unless the narrow-task exception applies; profiling never qualifies for the exception

Classified as high-risk; the exception is not claimed. Pensero measures the impact of delivered work rather than profiling the person.

Art. 9 — risk management

A documented, iterative risk management system across the lifecycle

Mandatory from 2 December 2027. In build. It covers foreseeable misuse — delivery metrics as the sole basis for a dismissal, cross-team ranking of non-comparable work — with mitigations and residual-risk statements reviewed on release.

Art. 10 — data governance

Relevant, representative and error-checked training and validation data; examination for bias

Pensero does not train models on customer data; general-purpose models are prompted and scoring is deterministic on top of their output. Governance therefore covers input quality (which repositories and tickets are connected, exclusions, boilerplate removal) and bias review of the rubric and of known measurement gaps such as part-time work, on-call and mentoring.

Art. 11 + Annex IV — technical documentation

Documentation sufficient to assess conformity

In build, on the same per-metric evidence already published.

Art. 12 — logging

Automatic recording of events over the lifetime of the system

Every AI-produced input and every human correction is stored with author and timestamp, and access is audited. Being extended to a retained, exportable per-system log.

Art. 13 — transparency and instructions for use

Deployers can interpret and use output appropriately; characteristics, capabilities, limitations, accuracy and oversight measures documented

Every number opens to the work items behind it, each metric has a published definition, and limitations are documented in the Help Center. Formal instructions for use are being assembled from that material.

Art. 14 — human oversight

Designed so that natural persons can oversee, interpret and override the output, and do not over-rely on it

AI outputs are proposals an authorised human can confirm or correct; every output can be overridden, though not every output is reviewed in advance; corrections are stored next to the original with author and reason; a score can be challenged and re-examined; no output is written back to an HR system. Automation bias is addressed by presenting evidence rather than verdicts.

Art. 15 — accuracy, robustness, cybersecurity

Declared accuracy metrics, resilience and security

Security is attested under SOC 2 Type II (see Security). A second model validates sensitive outputs. Declared accuracy metrics per assessment type are in build.

Art. 16-17 — provider obligations and quality management

A quality management system covering design, testing and post-market activity

In build on the existing engineering quality management system.

Art. 22 — authorised representative

A provider established outside the Union appoints an authorised representative in the Union

Applies to Pensero as a US-established provider; met by written mandate to an authorised representative in the Union, in place before the 2027 dates.

Art. 25 — responsibilities along the value chain

A deployer that rebrands the system or materially repurposes it becomes a provider

Does not arise: the Terms of Service (4.9.2, 4.9.3) bar rebranding, resale and repurposing, so customers remain deployers. Any use beyond them requires Pensero's written consent, and carries the provider role.

Art. 26 — deployer obligations

Use according to instructions, assign competent human oversight, monitor operation, keep logs, inform affected workers (26(7))

Obligations of the deployer. Pensero provides the instructions, the oversight surfaces, the logs, and worker-facing material that can be given to employees and their representatives.

Art. 27 — fundamental rights impact assessment

Required of certain deployers using Annex III systems

Where it applies to a deployer, Pensero supplies the system description, intended purpose, data categories and oversight measures the assessment requires.

Art. 43-49 — conformity assessment, declaration, CE marking, registration

Conformity assessment based on internal control, EU declaration of conformity, CE marking, registration in the EU database

Roadmap items ahead of 2 December 2027. Annex III 4(b) systems use internal control rather than a notified body.

Art. 50 — transparency obligations

Inform people that they are interacting with an AI system; mark AI-generated content

AI-generated summaries and assessments are labelled as such in the product. No part of Pensero presents itself as a human.

Art. 72 — post-market monitoring

Collect and review performance data from systems in use

Built on existing quality telemetry, correction rates and challenge outcomes.

Art. 73 — serious incident reporting

Report serious incidents to market surveillance authorities

Handled through the incident response process already used for security. Reports and enquiries: [email protected].

Art. 86 — right to explanation

A person affected by a decision taken on the basis of a high-risk system may request an explanation

Every person can see the work items and the arithmetic behind their own numbers.

GDPR Art. 22

Automated decisions with legal or similarly significant effects

Not applicable. Pensero produces no decision; a human decides on the evidence and the decision is recorded.

GDPR Art. 35 — DPIA

Impact assessment for systematic evaluation of employees

The deployer's assessment. Pensero supplies data flows, retention, sub-processors, model usage and oversight measures. Works council consultation, where the jurisdiction requires it, is also the deployer's, and precedes rollout.

Human oversight

Every AI-produced input to a score can be confirmed or corrected by an authorised human: work size, complexity per competency, defect attribution, category of work. The original value and the correction both stay on the record, with author and reason. A challenged score is re-examined and the outcome recorded. Repositories can be excluded from scoring, with a mandatory reason.

Controls available to the organisation

Anonymisation mode across the platform; per-section visibility settings for individual contributors; access based on role and reporting line; repository and file exclusions; per-integration control over what is connected.

Deployer responsibilities

The deployer decides how Pensero output may be used in its own processes. That includes internal guidelines for the role delivery data may play in a formal HR process, a named human accountable for every decision, treatment of Pensero as one input among several, AI literacy among the people who read the output (Art. 4), and informing affected employees and their representatives (Art. 26(7)).

Limitations

Output quality depends on what the connected systems contain. Work outside connected repositories, tickets and documents is invisible to Pensero, and invisible is not the same as absent. Assessments are made per work item, from the artifact alone, and can be wrong in an individual case; each one is reviewable for that reason.

Contact

AI Act questions, documentation requests and incident reports: [email protected].

Did this answer your question?