AI Regulation – Use of Artificial Intelligence (AI)
AI Regulation – Use of Artificial Intelligence (AI)
1. General Information
2. Use of AI Systems at ULTIDO
3. AI-Generated Content & Transparency
4. Classification as a Limited Risk AI System
5. Technical and Organizational Measures
6. Ethical Principles in AI Use
7. Internal Compliance and Training
8. Amendments to this AI Regulation
1. General Information
We, ULTIDO GmbH, attach great importance to the responsible and transparent use of Artificial Intelligence. With this AI Regulation, we inform you about how we use AI systems on our website and in our products, and what measures we take to meet the requirements of the European AI Act.
This AI Regulation applies to:
our website www.ultido.com, and
all ULTIDO products and services that use AI technologies (e.g., the ULTIDO AI filter in our photo booths and WebApps).
Below you will learn which of our content is AI-generated, how we ensure transparency, and why our offering is classified as a "limited risk AI system" under the EU AI Act. We also describe the technical precautions and ethical principles we follow when using AI, as well as our internal processes for ensuring compliance.
2. Use of AI Systems at ULTIDO
ULTIDO uses AI technology to provide you with creative photo and video experiences. Specifically, modern AI models – including diffusion models such as Stable Diffusion – are used to generate new image or video content based on uploaded photos and your dynamic inputs (e.g., text inputs for image descriptions or the selection of thematic styles). With the help of AI, your photo can, for example, be placed in a fantasy scenario or enhanced with special artistic effects.
The use of these AI functions always takes place on your initiative – you decide whether a photo is processed with an AI filter. The underlying AI system analyzes the provided image purely technically, without collecting any additional personal information. No personal data beyond the uploaded photo is processed. In particular, we do not identify any depicted persons or systematically analyze sensitive features from the photo.
We make the results generated by the AI (images and, if applicable, videos) available to you or authorized persons – such as event participants – for example, via a QR code or download link. We use the captured photos exclusively to perform the requested AI generation and to provide the result. No further use of your images, such as for training our models, takes place. After processing is complete, we store recordings only as long as necessary (details can be found in our Privacy Policy).
3. AI-Generated Content & Transparency
Transparency is important to us: We clearly indicate when content has been generated by AI and when you are interacting with an AI. You will be explicitly informed in the appropriate place that an AI system is in use – for example, directly in the WebApp or on the display of our photo booth when you use the AI filter. This way, you always know that the following result is created with the help of AI and is not handmade by a human.
All images and videos generated by our AI are also technically labeled. We integrate metadata (according to the IPTC/XMP standard) into every file generated by the AI, which records in a machine-readable format that the content was artificially generated or manipulated. This ensures that the AI origin of the image material remains verifiable even during subsequent use. Where technically possible, we additionally use visible notices or watermarks as labeling, without affecting the user experience.
These measures ensure that AI content is recognizable as such at all times. They fulfill the transparency obligations of the EU AI Act: Users must know when they are dealing with an AI or consuming AI-generated content. Furthermore, our system is designed in such a way that it does not possess any misleading or manipulative functions. It clearly serves the purpose of creating creatively edited images without deceiving you.
4. Classification as a Limited Risk AI System
Our AI systems used at ULTIDO are classified as "limited risk AI systems" in accordance with the EU AI Act. This means that our offer does not belong to either the prohibited or high-risk categories. We use AI exclusively for creative photo and video applications in entertainment and marketing contexts – not for safety-critical decisions, scoring, surveillance, or similar purposes with high risk to user rights. Accordingly, we are primarily subject to certain transparency requirements, but not to strict certification or reporting obligations as they apply to high-risk AI.
As a provider of a limited risk AI system, we fulfill our obligations in particular by ensuring transparency (see Section 3) and strengthening the AI literacy of our employees (see Section 7). We have internally reviewed and documented that our use cases fall into this risk class. Should the legal framework change or our system acquire a higher risk profile, we will immediately take measures to continue to ensure full compliance. Currently, our AI features are permitted and – subject to compliance with the prescribed due diligence and transparency obligations – are deemed harmless within the meaning of the AI Regulation. We ensure this through the measures described.
5. Technical and Organizational Measures
In connection with our AI systems, we implement various technical and organizational measures to ensure secure, reliable, and data-protection-compliant operation:
Content filters and usage limits: Our AI models are equipped with filter mechanisms designed to prevent the generation of inappropriate or harmful content (e.g., glorification of violence or pornographic depictions). We define clear usage guidelines for the AI filters so that they are only used within the intended framework – namely for creative, theme-specific image generation.
Quality assurance: Before we release a new AI feature, it is thoroughly tested. We check the generated results for quality, correctness, and any undesirable effects (such as bias or prejudice). We also monitor the performance of the AI during ongoing operations and make adjustments if necessary to immediately correct errors or deviations.
Data security: The processing of images by the AI takes place on secure, controlled servers in Germany. We protect the transmitted data using encryption and restrict access to authorized persons. Your photos are not forwarded to external AI services or third parties, but are processed within our own infrastructure. In this way, we guarantee the highest level of data privacy and control over the data flows.
Data minimization: We only collect the data that is necessary for the AI service (usually only the photo and your entered prompt texts or selection criteria, if applicable). In accordance with the principle of purpose limitation, this data is used exclusively for image/video generation. Storage only takes place as long as necessary; for example, uploaded recordings are automatically deleted after a defined period (details can be found in our Privacy Policy).
Robustness and reliability: Our developers ensure that the AI systems function stably and reliably. We keep the AI models used up to date with the latest technology and install necessary updates or improvements to guarantee security and stability. In the event of new findings about potential risks or vulnerabilities, we react promptly with corresponding countermeasures so that the use of AI remains safe at all times.
6. Ethical Principles in AI Use
For us, trustworthy and human-centered handling of AI is paramount. We are guided by the following ethical principles:
Fairness and non-discrimination: Our AI should work equally well for all users. We make sure that no one is disadvantaged or stereotyped by the generated content based on characteristics such as skin color, gender, or origin. If we notice any bias or unfairness in the results, we actively take action against it.
Transparency: Openness about the use of AI is central (see Section 3 above). We communicate clearly and understandably where and how AI is used. There are no hidden AI functions. As a user, you always know when a result comes from an AI and not from a human.
Safety and protection: The safety of our users is a priority. We ensure that our AI applications do not pose any physical or psychological danger. Through content controls and testing, we prevent the AI from generating potentially harmful or offensive content. In addition, we ensure that the use of our AI offerings takes place within a controlled framework (e.g., always supervised by our team at events).
Data privacy: We respect your privacy. Personal data is only used to the extent absolutely necessary for the AI service (see data minimization above) and is never used for other purposes without a legal basis or your consent. We comply with all relevant data privacy principles (especially GDPR) such as purpose limitation, data security, and deletion periods. Your data belongs to you – without your consent, it will not be used in any other way.
Accountability: We take responsibility for the use of our AI. ULTIDO has defined internal responsibilities to monitor compliance with all regulations and principles when using AI (see Section 7). For questions or problems in connection with our AI, we are at your disposal and look for transparent solutions. In addition, we subject our AI systems to continuous review in order to guarantee the high ethical standard permanently.
7. Internal Compliance and Training
Behind the scenes, we also ensure that the use of AI meets our own standards and legal requirements:
Training and literacy: Our employees are regularly trained in handling AI systems. We promote AI literacy within the team so that everyone involved knows exactly how our models work, the legal requirements (e.g., EU AI Act, GDPR), and our ethical guidelines. New employees and partners are also briefed on our AI policies and processes.
Internal guidelines & processes: We have defined clear internal guidelines for the development and operation of AI functions. This includes a company-wide AI policy or code of conduct that everyone must adhere to. Compliance with these guidelines is monitored by management and our data privacy/compliance team.
Documentation (record of processing activities): We maintain an internal record of all AI applications and the associated processing activities. This documents the purpose for which the AI is used, how it works, what data it processes, and what protective measures are implemented. This record of processing activities helps us keep track at all times and supply information to supervisory authorities if necessary.
Review and further development: We review our AI systems and their use at regular intervals. If new risks or potentials for improvement are identified, we adapt our processes and technical measures. We also stay informed about developments in AI law and technology in order to be able to react early. Our AI Regulation itself is also evaluated at defined intervals and updated as necessary.
Contacts and reporting: We have designated contact persons for questions regarding the use of AI (including our Data Protection Officer, reachable at datenschutz@ultido.de). Users and customers can contact us at any time in the event of queries or feedback. Should incidents or complaints arise in connection with our AI systems, we have established procedures for handling these internally and – if necessary – informing the responsible authorities.
8. Amendments to this AI Regulation
We reserve the right to adapt this AI Regulation as necessary to account for new legal requirements or technical developments. For example, if updates arise from the further implementation of the EU AI Act or changes to our offerings, we will update this policy accordingly. The current version of this AI Regulation will be published on our website.
Status: July 26, 2026