Skip to main content
Iron Gorilla

Top use cases

Show all solutions
  • GovernmentZero-trust autonomy with cryptographic chain-of-custody.
  • Banking & FinanceEnforce compliance on trading, lending, and transaction flows.
  • HealthcareHIPAA-aligned AI agents with PHI protection and audit trails.
  • InsuranceAutomated claims triage with PII redaction and policy control.

More industries

  • Construction
  • Energy
  • Aerospace
  • Transportation

By team

  • Enterprise IT
  • Teams & SMBs

Resources

  • Platform overviewSee how Iron Gorilla builds, manages, and deploys AI employees.
  • Help CenterGet straightforward answers and product guidance.
  • Trust CenterReview security, privacy, and compliance information.
  • Developer docsFind implementation guidance and technical references.

Learn

  • Insights
  • Compare

About

  • Company
  • Partners
LoginGet started for free

Legal

Policies & Agreements

Legal documents covering your use of the Iron Gorilla platform, how we handle data, and related notices and policies.

Documents

Terms of ServicePrivacy PolicyData Processing AddendumAcceptable Use PolicyEU AI Act Transparency AddendumCookie NoticeSubprocessor ListCopyright and DMCA PolicyAI Transparency NoticeConsumer Health Data Privacy NoticeBiometric Information Privacy PolicyNCII Notice and Removal PolicyCA GenAI Training Data Disclosure

Team Clarity, Inc. DBA Iron Gorilla EU AI Act Transparency Addendum

Last updated: July 29, 2026

Effective date: August 2, 2026 for new Customers and otherwise as provided in the Terms of Service, applicable Order Form, and legally required notice

This EU AI Act Transparency Addendum (the "Addendum") supplements and forms part of the Agreement between Team Clarity, Inc. DBA Iron Gorilla ("Team Clarity," "Iron Gorilla," "we," "us," or "our") and Customer. It addresses transparency, marking, detection, labelling, disclosure, and related responsibilities for AI systems and AI-generated or manipulated content. Capitalized terms not defined here have the meanings given in the Agreement.

1. Purpose, Scope, and Priority

This Addendum applies where the Services, Customer's configuration or deployment, or outputs processed through the Services are subject to Applicable AI Law or include AI Transparency Features. It applies to hosted, private, on-premise, API, SDK, agent, workflow, integration, and professional-services deployments to the extent relevant.

If this Addendum conflicts with the Terms of Service on AI transparency, marking, detection, or labelling, this Addendum controls. A signed Order Form may expressly allocate operational responsibilities differently for a specific deployment, but no agreement relieves either party of a non-waivable legal obligation. The DPA controls for processing of Customer Personal Data.

This Addendum allocates contractual responsibilities and provides operating requirements. It does not determine a party's statutory role, constitute legal advice, certify a use case, replace a conformity assessment, or create a presumption that a deployment complies with law.

2. Definitions

"Applicable AI Law" means Regulation (EU) 2024/1689 (the "EU AI Act"), as amended, including by Regulation (EU) 2026/1744, and other laws, binding rules, or regulatory requirements applicable to the development, provision, deployment, distribution, or use of AI systems, models, or outputs.

"Article 50 Code" or "Code" means the EU Code of Practice on Transparency of AI-Generated Content, as assessed or updated by the European Commission and the European Artificial Intelligence Board.

"AI-Generated or Manipulated Content" means synthetic audio, image, video, or text content generated or materially manipulated by an AI system and within the scope of Applicable AI Law, taking account of applicable exclusions, special regimes, and official guidance.

"AI Transparency Feature" means any machine-readable mark, watermark, content credential, cryptographic signature, provenance record, timestamp, content hash or fingerprint, detection signpost, interaction notice, label, icon, detection mechanism, disclosure event, or related technical or user-interface control.

"Deep Fake" has the meaning assigned by the EU AI Act and generally means AI-generated or manipulated image, audio, or video content that resembles an existing person, object, place, entity, or event and would falsely appear authentic or truthful to a person.

"Detection Means" means a method, specification, tool, service, interface, API, or other mechanism used to determine whether content carries a mark indicating that it was artificially generated or manipulated.

"Public-Interest Text" means AI-generated or manipulated text published for the purpose of informing the public on a matter of public interest within the meaning of Applicable AI Law.

Statutory terms, including "provider," "deployer," "importer," "distributor," "product manufacturer," "AI system," "general-purpose AI model," "emotion recognition system," "biometric categorisation system," and "high-risk AI system," have the meanings assigned by Applicable AI Law when that law applies.

3. Iron Gorilla's Code Adherence and Role

Iron Gorilla has signed and submitted adherence to Section 1 (Providers) of the Article 50 Code as a provider of generative AI systems. Section 1 addresses machine-readable marking and detection of AI-generated or manipulated audio, image, video, and text content. Iron Gorilla maintains a compliance program designed to implement the applicable commitments of the section to which it has adhered.

The Article 50 Code is voluntary. Article 50 obligations are legal obligations where they apply. Signing the Code is not an EU certification, approval, safe harbour, or conclusive proof of compliance. It does not by itself address every obligation under Article 50, including all obligations for directly interactive AI systems, emotion recognition, or biometric categorisation.

For a given deployment, Iron Gorilla may be a provider of an AI system, a provider of technical infrastructure or a transparency solution, a processor or subprocessor, or another operator. Customer may be a deployer and may also become a provider or other operator depending on its branding, modifications, intended purpose, integration, distribution, and control. Each party must determine and comply with its own statutory role.

4. Iron Gorilla Provider Measures

4.1 Direct Interaction Notices

For an in-scope AI system for which Iron Gorilla is the provider and which is intended to interact directly with natural persons, Iron Gorilla will design the relevant Services so that the natural person can be informed that the interaction is with an AI system, unless a statutory exception applies. For interfaces controlled by Iron Gorilla, the notice will be presented no later than the start of the first interaction in a clear, distinguishable, and accessible manner. For Customer-controlled interfaces, Iron Gorilla may provide a notice, flag, component, configuration option, API field, documentation, or other means that Customer must implement and must not disable or suppress.

The "obvious" exception must be assessed narrowly in context and must not be assumed merely because the product uses the word "AI" in documentation, because the user is technically sophisticated, or because the notice appears only in terms, a manual, or a hidden settings menu.

4.2 Machine-Readable Marking

For in-scope generative functionality for which Iron Gorilla is the provider, Iron Gorilla will use one or more technical measures designed to mark AI-Generated or Manipulated Content in a machine-readable format. Depending on the modality and deployment, measures may include digitally signed metadata or content credentials, imperceptible watermarking, cryptographic provenance methods, content hashes or fingerprints, logging methods, detection signposts, or other techniques. Iron Gorilla may rely on upstream model-provider marks, add Services-level marks, or use a combination.

Technical measures will be selected and maintained with the objective of being effective, interoperable, robust, and reliable as far as technically feasible, taking into account the specificities and limitations of the content modality, cost of implementation, open or recognised standards, available model-provider capabilities, deployment architecture, and the generally acknowledged state of the art.

Marking may not apply to content or functions outside the legal scope, including where a narrow statutory exclusion or special regime applies, such as standard assistive editing that does not substantially alter the input or its semantics, certain short or technical outputs, machine-to-machine outputs with no human exposure, or non-final outputs in closed development workflows. Iron Gorilla may document modality-specific scope and limitations.

4.3 Preservation of Existing Marks

Where content used as input contains recognised machine-readable markings and the content is transformed into an output through the Services, Iron Gorilla will, to the extent technically feasible and recognisable through relevant standards or interfaces, retain those markings or avoid intentionally altering or removing them. Iron Gorilla may add new provenance information to reflect the transformation. Preservation cannot be guaranteed where a format, provider, integration, transformation, or Customer configuration does not expose or retain the signal.

4.4 Detection Means

For in-scope outputs marked by Iron Gorilla under the Article 50 Code, Iron Gorilla will make available Detection Means as required by the Code and Applicable AI Law. Detection Means may be provided through a public specification, software, API, cloud service, verification interface, content credential validator, or another mechanism. Availability, supported formats, rate limits, authentication, and documentation may vary by feature and deployment.

Iron Gorilla may work toward or implement interoperability through public standards, routing mechanisms, signposts, registries, or other approaches recognised by the Code, official guidance, or generally acknowledged state of the art.

4.5 Documentation, Monitoring, and Improvement

Iron Gorilla may document supported modalities, marking methods, detection methods, known limitations, transformations that may degrade signals, and Customer configuration requirements. Iron Gorilla may test, monitor, evaluate, update, replace, or retire technical measures as standards and technology evolve, provided that it maintains a compliance approach consistent with Applicable AI Law and its applicable Code commitments.

5. Customer and Deployer Responsibilities

5.1 Role and Use-Case Assessment

Before placing a deployment into production or publishing content, Customer must assess its intended purpose, users, affected persons, geography, model and system architecture, branding, modifications, integrations, output modalities, publication channels, and downstream recipients to determine Customer's statutory role and applicable obligations. Customer must repeat the assessment after a material change.

5.2 Preservation and Non-Interference

(a) retain and not intentionally alter, strip, remove, disable, obscure, or circumvent recognised AI Transparency Features, including when content is uploaded, transformed, exported, downloaded, transmitted, republished, or redistributed;

(b) use available formats, export settings, APIs, or workflows that preserve AI Transparency Features and avoid choosing a transformation for the purpose of defeating those features;

(c) not forge, spoof, falsify, transplant, or misapply a mark, content credential, label, icon, detection result, provenance assertion, or disclosure;

(d) not attempt to reverse engineer, probe, attack, or use Detection Means for the purpose of defeating marking, detection, or abuse-prevention controls, except under a written authorised-testing agreement;

(e) promptly stop dissemination of content known to carry a forged, misleading, or unlawfully removed transparency signal and investigate the cause; and

(f) require Customer's Users, contractors, distributors, publishers, and other downstream recipients to comply with equivalent preservation and non-interference duties where appropriate.

5.3 Directly Interactive AI Systems

Where Customer controls an interface through which natural persons interact directly with an AI system, Customer must enable and display a clear and distinguishable notice that they are interacting with AI no later than the start of the first interaction, unless Customer has documented that a narrow statutory exception applies. The notice must be accessible and presented in an appropriate language. It must not be hidden solely in terms, documentation, a privacy policy, a settings menu, or a tooltip that a person is unlikely to encounter.

Customer must not disable, remove, or obscure an Iron Gorilla-provided interaction notice, API flag, disclosure component, or equivalent control. If Customer replaces it with an equivalent notice, Customer is responsible for ensuring that the replacement satisfies applicable timing, clarity, distinguishability, language, and accessibility requirements.

5.4 Deep Fake Disclosure

When Customer deploys an AI system to generate or manipulate image, audio, or video content constituting a Deep Fake, Customer must disclose that the content has been artificially generated or manipulated. The disclosure must be directly perceivable, such as through a visible or audible label, and must occur no later than first exposure. Customer may not rely solely on a machine-readable mark to satisfy this human-facing disclosure obligation.

For evidently artistic, creative, satirical, fictional, or analogous works or programmes, Customer may use an appropriately contextual disclosure that does not unnecessarily hamper the display or enjoyment of the work, where permitted by law. Customer remains responsible for assessing whether the content and deployment context qualify for that special regime.

5.5 Public-Interest Text

When Customer publishes AI-generated or manipulated text for the purpose of informing the public on a matter of public interest, Customer must disclose that the text was artificially generated or manipulated unless a statutory exception applies. The disclosure must be clear, distinguishable, accessible, and provided no later than first exposure.

If Customer relies on the exception for human review or editorial control, the review must involve deliberate substantive examination by a natural person with relevant knowledge and professional judgment, or meaningful editorial authority to approve, change, or reject the substance of the text. Spelling, grammar, formatting, or other superficial checks are not sufficient. A natural or legal person must hold ultimate editorial responsibility for the publication. Customer must retain reasonable evidence of the review, editorial control, and responsibility.

5.6 Emotion Recognition and Biometric Categorisation

Customer may not use emotion-recognition or biometric-categorisation functionality through the Services unless expressly authorised in a signed Order Form or other written agreement. Where authorised, Customer must inform natural persons exposed to the system of its operation, whether the system operates in real time or after the event, and must satisfy all applicable privacy, data-protection, employment, equality, consumer, sectoral, and fundamental-rights requirements.

5.7 Clear, Distinguishable, Accessible, and Timely Information

Any required interaction notice, content label, or disclosure must be noticeable, understandable, perceivable, and accessible to the reasonably foreseeable audience, including persons with disabilities and, where relevant, children. It must be visually, audibly, or otherwise clearly separate from surrounding information and must not be easy to overlook. Customer must provide it no later than the first interaction or exposure and repeat, maintain, or reposition it where necessary for persons who encounter the system or content later.

Customer may use an EU AI-content icon or another appropriate indicator, but an icon does not replace understandable text or audible information where such information is necessary for clarity and accessibility.

5.8 U.S. Transparency and Automated-Decision Disclosures

Where the same interaction or output is subject to United States law, Customer must also provide any required chatbot, bot, synthetic-media, artificial-voice, employment-tool, consequential-decision, patient-communication, or consumer-protection disclosure. The AI Transparency and Automated Decision Systems Notice and any U.S. AI Addendum supplement, rather than replace, this Addendum.

6. Detection and Verification Limitations

Customer acknowledges that marking and detection technology has technical limitations. Marks may be lost or degraded through editing, compression, re-encoding, cropping, screenshots, transcription, translation, format conversion, re-recording, printing and scanning, model behaviour, unsupported integrations, third-party platforms, or deliberate interference. Detection may produce false positives, false negatives, inconclusive results, or incomplete provenance.

A mark or detection result indicates only what the relevant technical system is designed to indicate. It does not prove the identity of an author, the truth or accuracy of content, the existence of consent, the legality of a publication, the absence of manipulation, or compliance with any law. Customer must apply appropriate human judgment and may not use a detection result as the sole basis for an adverse legal or similarly significant decision about a person.

Content submitted to a detection or verification feature may contain Personal Data or confidential information. Customer must have the right and lawful basis to submit it, must minimise sensitive information, and must comply with the Privacy Policy, DPA, and data restrictions in the Agreement.

7. AI Literacy and Personnel Controls

Each party will take proportionate measures to support the development of AI literacy among staff and other persons operating or using AI systems on its behalf, taking into account their technical knowledge, experience, education, training, the context of use, and the persons or groups affected. Neither party is required by this Addendum to guarantee any specific level of AI literacy for an individual.

Customer must ensure that personnel responsible for publication, disclosure, human review, editorial control, high-risk decisions, biometric or emotion-related uses, and transparency configuration understand the relevant requirements and receive role-appropriate instructions. Training should be refreshed when the use case, law, model, system, or transparency controls materially change.

8. Prohibited and High-Risk Uses

Customer must not use the Services for any prohibited AI practice identified in Applicable AI Law or the AUP. Customer must assess whether a deployment is a high-risk AI system or is integrated into a regulated product. When high-risk obligations apply, Customer is responsible for the obligations assigned to Customer, which may include risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, fundamental-rights assessment, registration, conformity assessment, post-market monitoring, corrective action, and incident reporting.

Iron Gorilla's general platform features, documentation, or Code adherence do not constitute a conformity assessment, CE marking, high-risk certification, fundamental-rights impact assessment, or approval of Customer's intended purpose. Any support for a high-risk deployment must be described in a signed Order Form or statement of work.

9. Records, Monitoring, and Cooperation

(a) maintain records reasonably necessary to demonstrate its compliance, including role and use-case assessments, relevant model and system versions, configuration, disclosure text and placement, accessibility measures, publication channels, and downstream instructions;

(b) retain reasonable evidence of substantive human review, editorial control, and editorial responsibility when relying on an exception for Public-Interest Text;

(c) preserve relevant logs, output or content identifiers, provenance records, marking status, detection results, incidents, complaints, and remediation for the period required by law or reasonably necessary to demonstrate compliance;

(d) promptly notify Iron Gorilla of a missing, defective, forged, removed, or compromised AI Transparency Feature affecting the Services; a material misuse; a complaint or claim involving Iron Gorilla's transparency features; or a regulatory inquiry relevant to the Services;

(e) provide information reasonably requested by Iron Gorilla to investigate a suspected violation, remediate a transparency failure, respond to a competent authority, or demonstrate adherence to the Article 50 Code; and

(f) cooperate in good faith on corrective actions, content withdrawal, configuration changes, user notice, preservation, or other measures reasonably necessary to address a material compliance or integrity issue.

Iron Gorilla may review relevant logs, telemetry, configurations, output identifiers, and transparency records to the extent permitted by the Agreement and applicable law. Iron Gorilla may request an attestation or evidence of Customer's compliance where it reasonably believes that a violation or material risk has occurred. Any audit right is subject to reasonable confidentiality, security, scope, and non-disruption requirements.

10. Third-Party Models, Integrations, and the AI Value Chain

The Services may rely on third-party model providers, content-authenticity services, detection providers, open standards, cloud providers, or Customer-authorised integrations. Their marks, metadata, detection capabilities, availability, data handling, and legal roles may differ. Iron Gorilla may preserve or supplement third-party signals but does not control all downstream transformations, platforms, or recipients.

Customer must review and comply with the terms and transparency requirements of each connected provider. Customer must not instruct a connected system to remove or defeat an AI Transparency Feature. Where Customer places a combined, rebranded, substantially modified, or differently purposed AI system on the market or into service, Customer is responsible for assessing whether it assumes provider or other value-chain obligations.

11. Privacy, Confidentiality, and Security

Processing of Personal Data in connection with AI Transparency Features is governed by the Privacy Policy and, where applicable, the DPA. Customer must not place unnecessary personal, sensitive, or confidential information in public-facing marks or labels. Customer must protect signing keys, API keys, detection credentials, and administrative permissions and must promptly revoke or rotate compromised credentials.

Iron Gorilla may suspend or restrict a marking, detection, publication, or integration path if it reasonably believes that the path presents a legal, security, privacy, fraud, abuse, integrity, or regulatory risk. Where practicable and consistent with law and security, Iron Gorilla will provide notice and an opportunity to remediate a non-emergency issue.

12. Remedies and Enforcement

A violation of this Addendum is a violation of the Agreement and AUP. Without limiting other rights, Iron Gorilla may require remediation, preserve evidence, disable an output or feature, suspend or restrict access, revoke credentials, remove an integration, notify an affected customer or competent authority where required or permitted, or terminate the Agreement. Customer remains responsible for its publications, notices, labels, and downstream conduct.

13. Changes to this Addendum

Iron Gorilla may update this Addendum to reflect changes in Applicable AI Law, the Article 50 Code, Commission or AI Board assessments, official guidelines, technical standards, generally acknowledged state of the art, Services, or risk. Changes reasonably necessary to meet a legal or regulatory requirement or protect the integrity of transparency features may take effect on shorter notice where reasonably necessary. Other material adverse changes will be communicated as described in the Terms of Service.

13A. Current Application Timeline

Article 50 transparency obligations generally apply from August 2, 2026. The transition applicable to certain Article 50(2) marking obligations for qualifying systems placed on the market before that date runs until December 2, 2026. Following the 2026 AI Omnibus, the application dates for specified Annex III high-risk systems and high-risk systems embedded in regulated products are December 2, 2027 and August 2, 2028, respectively. The parties will apply later amendments, implementing measures, codes, and guidance to the extent legally binding or expressly incorporated into the Agreement.

14. Contact

Questions, compliance notices, transparency-feature incidents, complaints, or regulatory correspondence concerning this Addendum should be sent to:

Team Clarity, Inc. DBA Iron Gorilla
1111B S Governors Ave #41605
Dover, Delaware 19904
United States
legal@teamclarity.ai

Schedule 1. Recommended Disclosure Language

The following examples are starting points only. Customer must adapt language, modality, placement, repetition, accessibility, and local-language presentation to the use case and law.

Direct AI interaction: "You are interacting with an AI system."

General AI-generated content: "AI-generated content."

General AI-manipulated content: "AI-manipulated content."

Deep fake: "This image, audio, or video was artificially generated or manipulated using AI and may not depict an authentic event."

Artistic, creative, satirical, or fictional work: "This work contains AI-generated or AI-manipulated content."

Public-interest text without qualifying human review: "This text was generated or materially manipulated using AI and has not undergone substantive human review or editorial control."

Emotion recognition: "An AI-based emotion recognition system is operating and may analyse facial expressions, voice, or other relevant signals or content."

Biometric categorisation: "An AI-based biometric categorisation system is operating and may analyse biometric signals or content to assign characteristics or categories."

Schedule 2. Minimum Customer Evidence

(a) documented provider/deployer and use-case assessment;

(b) system, model, and material configuration versions;

(c) interaction notice or content disclosure text, placement, timing, language, and accessibility evidence;

(d) marking and detection configuration and known limitations;

(e) records of substantive human review or editorial control when an exception is relied upon;

(f) data-protection basis and exposed-person notice for any authorised emotion-recognition or biometric-categorisation use;

(g) downstream instructions requiring preservation of marks and labels; and

(h) incident, complaint, investigation, remediation, and regulator-communication records.

Iron Gorilla

The platform for building and governing AI employees, with policy-backed controls and clear human oversight.

  • SBA Certified Small Business

Product

  • Trust Profiles
  • Agent Builder
  • Command Center
  • Policy Builder
  • Reporting
  • Compliance Hub

Solutions

  • Government
  • Banking
  • Insurance
  • Healthcare
  • Energy
  • Aerospace

Resources

  • Trust Center
  • Help Center
  • Developer Docs
  • Insights
  • Compare
  • Pricing

Company

  • Company
  • Partners
  • Press Kit
  • Accessibility
  • Legal

© 2026 Team Clarity, Inc. DBA Iron Gorilla. All rights reserved.

Capabilities Statement