Why Reactor Is Not a High-Risk AI System
The EU AI Act sorts AI by the risk of its use, not by its technology. Reactor sits outside the high-risk tier because of three deliberate design choices: AI never administers a test or computes a result, insights describe populations rather than individuals, and where AI does contribute the output is marked as such — visibly for a reader, and machine-readably for whatever consumes it next......AI Compliance Is an Architecture Decision, Not a Legal Opinion
The question every AI buyer now opens with

Procurement conversations about research platforms have changed. A year ago the questions were about methodology, panel quality, and turnaround. Now, somewhere in the first meeting, someone asks the tier question: under the EU AI Act, is this a high-risk AI system?
It is a fair question and it deserves a precise answer rather than a reassuring one. “No” is easy to say. What matters is whether the vendor can show you the reasoning — because the answer does not come from a marketing decision. It comes from what the system is actually used for and what it actually does to the people whose data passes through it. If those things change, the answer changes with them.
So here is our answer, with the working shown. Reactor is not a high-risk AI system under the Act. That is not an accident of category, and it is not a claim we intend to defend by argument if the product drifts. It is a consequence of three decisions in the architecture — decisions we published in our AI Policy before anyone asked us to.
The Act regulates uses, not technologies
The most common misreading of the AI Act is that it grades models by capability, as though a more powerful model automatically attracts heavier obligations. It does not work that way. The Act is a product-safety regulation, and like every product-safety regulation it asks what the thing is for.
It sorts AI systems into tiers by the risk their intended purpose creates for health, safety, and fundamental rights. A small, unremarkable model deciding who gets a mortgage sits in a heavier tier than a far more sophisticated one suggesting chart titles. The question is never “how advanced is it?” — it is “what does it decide, and about whom?”
That framing is what makes the answer for a research platform tractable. Reactor does not decide anything about the people it measures. It measures consenting participants, computes results from published cognitive-association methods, and reports what a population did. Nobody is admitted, refused, priced, hired, graded, or flagged as a consequence of a Reactor study.
The high-risk list, and why market research is not on it
High-risk is not a vibe or a severity judgement — it is, in the main, a list. Annex III of the Act enumerates the use cases: biometric identification and categorisation; safety components in critical infrastructure; education and vocational training; employment, worker management, and access to self-employment; access to essential private and public services, including creditworthiness and life and health insurance pricing; law enforcement; migration, asylum, and border control; and the administration of justice and democratic processes.
Consumer and market research appears nowhere on that list, and the omission is not an oversight the regulator will patch later. The list is organised around decisions taken about an identified individual that determine their access to something — a job, a loan, a school place, a border, a courtroom outcome. Research that describes what a population of consenting participants associates with a brand does not have that shape. There is no individual determination for the Act to protect anyone from.
It is worth being precise about the adjacent cases, because they are where a research company would land if it were careless. An AI system used to screen job applicants is high-risk. An AI system used to evaluate students is high-risk. An AI system that categorises people biometrically is high-risk. A study that asks two thousand consenting shoppers to react to six packaging designs, and reports which design produced faster and stronger associations across the sample, is none of those things.
Three design decisions that keep us out of the tier
The tier question has a stable answer only if the architecture makes the answer stable. Three decisions do that work, and each of them costs us something — which is how you can tell they are real.
First: AI does not administer tests or compute results. This is the one that surprises people, because the obvious way to build a modern research platform is to let a model do as much as possible. We do not. Measurement and scoring use published cognitive-association methods — deterministic, inspectable, and the same today as yesterday. AI enters only afterwards, to synthesise meaning and summaries from results that were already computed without it. A model cannot bias a score it never touched.
Second: aggregate insight, never individual inference. Our AI Policy states it plainly: “Insights describe significant trends in populations; Reactor never uses its data to infer the emotions or likely behavior of any individual participant.” That sentence is a design constraint, not a comfort. Profiling natural persons is precisely what pulls a system toward the high-risk tier and keeps it there even where an exemption might otherwise apply. We do not do it, so the question does not arise.
Third: where AI does contribute, the output says so — to the reader and to the next machine. We use AI to summarise findings and to help present the work, and we are not going to pretend otherwise: a claim that every sentence passes under a human eye before publication is the kind of assurance that is easy to write and impossible to audit. What we do instead is mark provenance, in two layers. A report shows a human which findings have been reviewed and which have not. It also carries invisible machine-readable marks, so an agent or downstream system consuming the report can tell what was AI-generated without a person having to vouch for it.
The second layer is the one that matters most as research outputs start flowing between systems rather than only being read. A visible label protects a human reader; it does nothing for an automated pipeline that ingests the report, and stripping a visible label is trivial. Marking the output itself means the provenance travels with the content instead of depending on the honesty of whoever forwards it. Disclosure that survives inspection — and survives being passed on — is worth more than a blanket promise that does not.
That matters for the tier question because of what AI is doing at that point. It is summarising and presenting results that were already computed without it — it is not deciding anything, and there is no outcome for a person for it to influence. The only consumer of the output is a researcher forming a view about a population. The Act treats meaningful human oversight as central to whether a system materially influences an outcome; in Reactor the more relevant fact is that there is no such outcome to influence in the first place.
The emotion-recognition question, answered precisely
Any company working in behavioural science should expect this one, and it deserves a definitional answer rather than a rhetorical one. The Act defines an emotion recognition system narrowly: a system that identifies or infers the emotions or intentions of natural persons on the basis of their biometric data. Two elements have to be present — an inference about a person’s emotional or intentional state, and biometric data as the basis for it.
Reactor’s methods measure how quickly and how consistently a participant responds to stimuli. Response latency is behavioural data about a moment of interaction; it is not data processed for the purpose of uniquely identifying anyone, which is what makes data biometric in the first place. And the inference we draw from it is a statement about a sample, not a reading of a person: this population associated this brand with this attribute more strongly and more automatically than that one.
So the definition fails on both elements, independently. Even if you disagreed with us about the first, the second would still hold — and it is the one we have committed to publicly and enforce in the product. We think a vendor should be able to lose an argument about the legal characterisation of its inputs and still be outside the tier on the strength of what it refuses to do with them.
Not high-risk is not the same as no obligations
The tier answer is sometimes treated as a finish line, which is a mistake we would rather not make in public. Several obligations under the Act apply regardless of tier, and some of what the Act reserves for high-risk systems is simply good practice that we would want in place whatever the law required.
AI literacy applies to everyone. The obligation to ensure that staff dealing with AI systems have a sufficient level of AI literacy attaches to providers and deployers of any AI system, at any tier, and has been in force since February 2025. We maintain a literacy register that records completion rather than mere exposure, and it is readable by the people who would have to answer for it.
Transparency is a standing commitment, not a disclosure event. Our policy’s first principle is that there is no hidden AI: each feature is documented with its purpose and its data usage, and users are aware when AI processes their data.
The marking obligation we meet directly. The Act requires that AI-generated content be marked in a machine-readable format and be detectable as artificially generated — an obligation that attaches to the generation of synthetic content, not to the risk tier of the system doing it. AI-assisted summaries in Reactor carry both a human-visible indication and invisible machine-readable marks, so the disclosure is legible to a reader and to a system alike. We would want it that way regardless of the Act: a research output whose provenance is only readable by a human stops being trustworthy the moment it is consumed by something that is not one.
Traceability we keep as though we were in the tier. The Act’s record-keeping regime for high-risk systems exists so that a supervisory authority can reconstruct what a system did. We log AI feature usage as audit records — which user used which feature, and when — and organisations can export their own logs for audit purposes. We built the reader for that log on the customer side and again on the staff side, because “we have the data somewhere” is not an answer during an audit.
And confidentiality is enforced before the model, not after. The Sanity Agent Privacy Wall replaces confidential values — names, email addresses, customer and project identities — with pseudonymous tokens before text reaches an external model, with the token registry held encrypted and never exposed to the model. Deliverables are produced with real values restored as the final step. It is on by default.
Where the analysis could change — and whose job that is
An honest compliance statement has to say what would break it, so here is ours. The Act places obligations on providers and on deployers, and a deployer who takes a general-purpose research instrument and points it at a regulated decision has changed the analysis for themselves, whatever the provider intended.
If a customer were to use behavioural measurement to screen job applicants, to evaluate students, or to infer the emotional state of employees or learners, they would not be doing market research any more. The first two are squarely on the high-risk list. The last is not merely high-risk — inferring emotions in the workplace and in education is among the practices the Act prohibits outright, with narrow exceptions for safety and medical purposes.
Reactor’s intended purpose is consumer and market research with informed, consenting participants. That is what it is designed for, documented for, and sold for. Our terms make the customer responsible for ensuring their use complies with their own policies and their obligations to research participants, and we would rather state the boundary in an article like this one than discover a customer had assumed it did not exist.
The same discipline applies to us. New capability gets assessed against this reasoning before it ships, not after. If a feature could not be described honestly in a document like this one, that is information about the feature.
Why we are publishing the reasoning and not just the conclusion
Every vendor in this market will tell you they are not high-risk. Most will be right. The claim is nearly free to make and, as a buyer, nearly impossible to check — which is exactly why it is worth asking for the reasoning instead.
The reasoning is checkable in a way the conclusion is not. Ask what the AI actually touches, and whether it computes any score. Ask whether the system ever makes a statement about an individual participant, and where that boundary is enforced. Ask whether anything at all is decided about a person as a result of a study. Ask to see the audit log and the literacy register rather than the policy that promises them. The answers to those questions are properties of a system, and a vendor either has them or does not.
We have set out ours. If your assessment reaches a different conclusion, we would genuinely like to hear the argument — a compliance position that cannot survive contact with a well-briefed customer is not a position, it is a hope.
| Tier | What it covers | Reactor |
|---|---|---|
| Prohibited | Practices banned outright, including social scoring, manipulative techniques causing significant harm, and inferring emotions in the workplace or in education | Out of scope. Reactor's intended purpose is consumer and market research with consenting participants; it makes no statement about any individual participant |
| High-risk | The Annex III use cases — biometrics, critical infrastructure, education, employment, essential services and creditworthiness, law enforcement, migration, justice | Not on the list. No individual determination is made, and AI performs no measurement or scoring |
| Transparency obligations | Systems people interact with directly, and synthetic or AI-generated content, which must be marked machine-readably and be detectable as artificially generated | Met directly. AI-assisted summaries carry a human-visible indication and invisible machine-readable marks; no hidden AI, every feature documented with its purpose and data usage |
| Minimal risk | Everything else — no mandatory obligations beyond the cross-cutting ones such as AI literacy | Where Reactor's AI features sit. We maintain literacy, traceability logging, and human review regardless |