FOTOhub is compliance-ready. Here's what that actually means.
With the EU AI Act enforced and Poland adopting its own AI systems law, we explain point by point why FOTOhub is fully compliant - and why we built it that way from day one.
On March 31, 2026, Poland's Council of Ministers adopted the draft Act on Artificial Intelligence Systems - the country's implementation of the EU AI Act. For many companies across Europe, this triggered a familiar question: does this affect us, what do we need to do, and are we safe?
At FOTOhub, we asked ourselves that question much earlier. And we have a concrete answer.
We are ready. Both for EU regulations under the AI Act and for the Polish law that has just entered parliamentary proceedings. Below, we explain point by point why - because in the AI industry, transparency is not a PR strategy. It is a standard.
Where FOTOhub sits under the AI Act risk framework
The EU AI Act classifies AI systems into four risk tiers: prohibited practices, high-risk systems, limited-risk systems, and minimal-risk systems. This is not our interpretation - it comes directly from Article 6 and Annex III of Regulation (EU) 2024/1689.
FOTOhub is a creative AI platform for generating images, video, voice, and audio. Our platform does not make decisions that affect people's lives. It does not assess creditworthiness. It does not recruit, diagnose, classify people by emotional sensitivity, monitor employees, or manage critical infrastructure. None of the high-risk categories in Annex III apply to us.
We qualify as a limited-risk system with elements of minimal risk. In practice, this means:
- No formal certification requirement
- No registration in the EU AI database
- No conformity assessment by an external notified body
- Specific obligations around transparency and labeling of AI-generated content - which we fulfill
FOTOcore AI: our engine, our responsibility
FOTOhub is not just an integration layer on top of third-party APIs. We develop our own AI models that operate within FOTOcore - our internal model orchestrator and the AI engine powering the entire platform.
We train on our own datasets, anchored by a library of over 12 million files accumulated within the FOTOhub ecosystem. User data is excluded from training by default. Your photos, videos, and audio uploaded to the platform do not enter training without your explicit, active consent. This is opt-in, not opt-out. The default state is privacy. This is a deliberate architectural decision, not an accident.
For users who choose to support model development and grant consent, data is used strictly within the scope of that consent and in full compliance with GDPR. Every operation on consented data is documented and auditable. This is the standard the AI Act requires from providers operating in the European Union.
We also use APIs from external AI model providers such as OpenAI, Google, Stability AI, and Runway. All our API partners have undergone their own compliance processes and operate in accordance with EU and US law. More importantly, FOTOcore is not just a pass-through to these models. We apply our own layers: content filtering, safety checks, and moderation mechanisms - before any output reaches the end user.
How FOTOcore controls every generated asset
This is the element that sets us apart from most platforms in this category.
Every asset generated through FOTOhub - whether it comes from our own model or an external API - passes through the FOTOcore control pipeline before delivery to the user. This mechanism verifies content for safety, platform policy compliance, and regulatory requirements. This is not post-hoc moderation on a "generate first, check later" basis. It is verification built into the generation pipeline architecture.
AI-generated content disclosure
Article 50 of the AI Act requires that systems generating synthetic content inform users that the content was generated by AI, where it could mislead regarding authenticity. Disclosure is part of FOTOhub's standard output. AI-generated materials are labeled as AI-generated both in the user interface and in file metadata where technically feasible.
This is not something we added at the last minute before a deadline. It has been part of the system design from the beginning.
What the Polish AI law means for FOTOhub
On March 31, 2026, Poland's Council of Ministers adopted the draft Act on Artificial Intelligence Systems, establishing the Commission for the Development and Safety of Artificial Intelligence (KRiBSI) as the central AI oversight body in Poland. Poland is one of the few EU countries that chose to create a new, dedicated institution rather than distributing competencies among existing regulators.
For FOTOhub, the Polish law does not materially change our compliance picture. We are not a high-risk system, so we are not subject to the regime of mandatory permits, audits, or registration. KRiBSI can handle user complaints, but our content control and transparency mechanisms exist precisely to minimize the risk of justified complaints.
The law also introduces a regulatory sandbox - a testing environment for AI innovation without the risk of penalties for potential violations during the testing phase. It is free for SMEs. As a Polish startup embedded in this ecosystem, we have full access to it.
Our data handling architecture in detail
Because compliance is not just about regulation labels - it is about how data actually flows through the system:
- Storage: All user data is stored on European infrastructure (GCP europe-central2, europe-west4). No data leaves the EU unless the user explicitly requests integration with a US-based provider.
- Processing: Generation requests are processed through FOTOcore's pipeline. Inputs are validated, outputs are filtered. Prompts and generated content are logged for safety auditing, not for training.
- Retention: Users have full control over their data. Account deletion triggers a complete data wipe within 30 days, including generated content, metadata, and any training opt-in records.
- Third-party APIs: When external providers are used (OpenAI, Google, Stability AI), data is transmitted via encrypted channels. We use API agreements that prohibit providers from using FOTOhub user data for their own training.
- Audit trail: Every generation event, credit deduction, and content moderation action is logged with timestamps, user context, and model metadata.
Why we are talking about this
Transparency in AI is not optional. It is the direction the entire industry, regulators, and the market are heading. Investors ask about AI governance. Enterprise customers ask about compliance. Integration partners ask about data handling.
We believe the best approach is to say it directly: we know where we stand in the regulatory hierarchy, we know what our obligations are, and we know how we fulfill them. We do not hide behind a generic "we comply with all legal requirements." We explain specifically what that means and why.
FOTOhub was founded in September 2025 as an AI-first platform for creators. We built it with the assumption that AI regulations are inevitable and that it is better to design for compliance from the first commit than to retrofit it after the fact. FOTOcore as a model orchestrator was designed with content control mechanisms built into its core architecture - not bolted on as an afterthought.
Compliance summary
For investors, partners, and users who want to know where FOTOhub stands on AI regulation:
| Requirement | Applies to FOTOhub? | Status |
|---|---|---|
| EU AI database registration | No (high-risk only) | N/A |
| Conformity assessment by notified body | No (high-risk only) | N/A |
| AI-generated content disclosure (Art. 50) | Yes | Implemented |
| GDPR compliance for training data | Yes | Implemented, opt-in disabled by default |
| Human oversight mechanism | Yes (best practice) | FOTOcore control pipeline |
| User transparency | Yes | Implemented |
| Regulatory sandbox (Polish law) | Optional | Available as SME |
| Data residency (EU) | Yes | All data on EU infrastructure |
| Right to erasure (GDPR Art. 17) | Yes | Full account deletion within 30 days |
FOTOhub is ready for AI regulations - and will be ready for the ones yet to come. We track EU and Polish legislation continuously and adapt our system architecture as the rules evolve.
Questions about our approach to AI governance and compliance can be directed to the FOTOhub team at [email protected].