Last updated: October 2, 2026
Over the past several years, governments and regulators around the world have increasingly focused their attention on artificial intelligence. From the EU to the U.S., India and beyond, there has been and will continue to be regulation in this space, and for good reason. The pace of innovation around AI and the novelty of its current and future applications is unprecedented. Not surprisingly, this has caught the attention of lawmakers, who have the difficult task of balancing how to foster AI innovation while promoting transparency, fairness, safety, security, and the protection of individuals' rights.
Thrifty AI builds artificial humans: lifelike, real-time AI avatars that hold face-to-face voice and video conversations. Because an artificial human looks and sounds like a person, can see the user's camera frame, and can produce synthetic audio and video, several areas of AI and data protection regulation are directly relevant to how we design and operate our services. These include transparency about AI interactions, labelling of synthetic media, restrictions on emotion recognition, and the rules that apply to biometric and facial data.
Given the volume of new regulation, we want to describe the measures Thrifty AI has taken and will continue to take in light of global AI and data protection laws, beginning with the EU AI Act. This page describes our approach and commitments. It is not legal advice, and it does not describe the obligations of our customers, who remain responsible for assessing how the laws that apply to them affect their own deployments.
In 2024, the EU adopted the first comprehensive law regulating the use of artificial intelligence: Regulation 2024/1689, otherwise known as the AI Act. At a high level, the AI Act governs the development and use of artificial intelligence while also seeking to promote innovation in the AI space. It comes into effect in stages based on how the AI Act classifies risk.
The AI Act sets out specific requirements for different types of AI systems according to their risk, distinguishing between AI practices that are prohibited, AI systems that are high risk, and AI systems that present transparency risks (often described as "limited risk" AI systems), with different rules applicable to each category. These rules cover a variety of areas including data governance, risk management, quality management, human oversight, and transparency.
Thrifty AI's approach to the AI Act began by identifying the AI systems we make available to customers and assessing how they are likely to be classified. Our services, including Thrifty Studio, the Thrifty AI APIs and SDKs, managed deployments and Thrifty Agent, are used to build and run artificial humans that interact directly with people and generate synthetic audio and video. We consider that, in their general-purpose configuration, they fall within the AI Act's transparency rules for AI systems that interact with people and generate synthetic content. Our services are not designed or permitted to be used for any of the prohibited practices set out in Article 5 of the AI Act.
The classification of a particular deployment can change depending on how a customer uses it. For example, an artificial human used to conduct recruitment interviews, evaluate candidates, or assess learners in education or vocational training may fall within the high-risk use cases listed in Annex III of the AI Act. Where a customer intends to use our services in such a context, the customer must tell us in advance and take the additional steps described in our Acceptable Use Policy, and we will work with the customer on the information and controls it needs.
We also analyzed whether we should be treated as a provider (i.e. a developer) or a deployer (i.e. a user) of AI systems. In the context of providing services to our customers, we generally act as a provider of the artificial human systems we design and build. Our customers who place an artificial human in front of their own users will typically act as deployers, and in some cases a customer that substantially modifies or rebrands a system may take on provider obligations of its own.
Article 50 of the AI Act sets out transparency obligations that are central to artificial humans. We address them as follows.
Article 50(1) requires providers to design AI systems that interact directly with people so that those people are informed they are interacting with an AI system, unless this is obvious from the context. Because an artificial human is designed to look and sound lifelike, we do not rely on it being obvious. Our services are designed so that end users are informed that they are speaking with an AI at or before the start of each conversation, and our default configurations include such a disclosure. Customers may adjust the wording and presentation of the disclosure, but our Acceptable Use Policy does not permit customers to remove it or to configure an artificial human to claim that it is a human being.
Article 50(2) requires providers of AI systems that generate synthetic audio, image, video or text content to ensure that outputs are marked in a machine-readable format and detectable as artificially generated, to the extent technically feasible. Article 50(4) requires deployers of AI systems that generate or manipulate image, audio or video content constituting a deep fake to disclose that the content has been artificially generated or manipulated. We are working towards machine-readable marking of the synthetic audio and video produced by our services, including recordings and exported media, and we provide visible labelling options that customers can use to meet their own disclosure obligations.
Article 5 of the AI Act prohibits the use of AI systems to infer the emotions of a natural person in the areas of workplace and education institutions, except where the system is intended for medical or safety reasons. Article 50(3) requires deployers of permitted emotion recognition or biometric categorisation systems to inform the people exposed to them. An artificial human can see the user's camera frame and adapt its responses, and some of our customers operate in workplaces and in education. Accordingly:
First, we are committed to providing regulators and our customers with the information they need to understand and trust our AI services. This includes, but is not limited to:
Second, we maintain internal AI governance processes covering risk assessment, testing, human review and incident handling for the artificial human systems we develop and deploy. We review and improve these processes as our services and the applicable rules evolve.
Third, our Acceptable Use Policy specifies overarching principles that apply to customers who use our services, prohibits use of our services for, or to facilitate, any prohibited AI practices under the AI Act, prohibits impersonating real people without their consent, and sets out the additional steps our customers must take if they intend to use our services in any AI system that is designated as high risk under the AI Act.
Finally, we recognize that compliance remains an ongoing exercise, and we expect further guidance, codes of practice and standards to be published by the European Commission and national AI regulators, including on transparency and the marking of synthetic content. We will engage with this guidance as and when it is published.
Artificial humans can process voice audio, camera video frames and facial imagery. Under the EU and UK General Data Protection Regulation, biometric data processed for the purpose of uniquely identifying a person is a special category of personal data, and a number of other jurisdictions, including several U.S. states, have specific laws on the collection and use of biometric identifiers. Our approach is as follows:
We remain particularly focused on how regulation has and will continue to develop in the United States, both at the state level, where a number of AI, biometric privacy and synthetic media laws have already been passed, and at the federal level, whether through executive orders and other administrative guidance or as part of a comprehensive federal AI bill. Laws addressing automated decision-making in employment, the disclosure of AI chatbots and synthetic media, and the use of a person's voice and likeness are especially relevant to artificial humans, and we monitor these developments closely.
On January 1, 2026, California's AB 2013 came into effect, which aims to promote further transparency into how generative artificial intelligence systems are developed. To the extent Thrifty AI develops or substantially modifies generative AI systems made available to Californians, we will publish the high-level information about training data that AB 2013 requires. As described in our Privacy Policy, customer data, including conversation recordings, transcripts, voice audio and camera video, is not used to train shared models without the customer's permission.
Thrifty AI's services are used across India, including in Indian languages, for education, banking and financial services, healthcare intake, HR and public-sector help desks. India's Digital Personal Data Protection Act, 2023 (DPDP Act), together with the rules made under it, establishes obligations for data fiduciaries and data processors handling digital personal data. Our approach includes:
We also follow developments under India's Information Technology Act and related rules and advisories, including those concerning synthetically generated information and deepfakes, and will adapt our labelling and disclosure features as needed.
While approaches to regulation may differ across the EU, the United Kingdom, the United States, India and other countries, we take a global, unified approach so that our customers can build and use artificial humans productively, safely, and responsibly in line with our Acceptable Use Policy. Above all else, our approach remains grounded in trust. This means designing artificial humans that are honest about being AI, and labelling the synthetic media they produce. This means building, evaluating, and monitoring our services to protect against unlawful bias, misuse, impersonation and harm. This means providing transparency and control over the data you share with us, including our commitment not to use your recordings, transcripts, voice or video data to train shared models without your permission. This means protecting and securing your data and complying with the privacy and data protection laws already in place. And this means remaining committed to meeting our obligations under global AI laws as they evolve, and evolving our approach as needed. You can learn more about how we earn that trust in our Trust Center.
If you have questions about Thrifty AI's approach to AI regulation, please contact legal@thriftyai.com. Questions about personal data can be sent to privacy@thriftyai.com.