EU AI Act & AI Compliance for Icon Map

Icon Map currently includes one optional AI-assisted feature. Tekantis governs it under a formal, risk-based framework aligned with the EU AI Act and the NIST AI Risk Management Framework, designed so that your data stays in your control.

This page explains where Icon Map uses AI, exactly what data is and is not sent to AI services, and how we govern these features. For our wider security architecture, see the Icon Map Pro security whitepaper (PDF).

Our approach to AI

Tekantis treats AI as something to be governed, not bolted on. Every AI feature in our products is assessed before release, recorded in an internal AI System Register, and classified against the EU AI Act's risk categories. Our current AI feature is assistive, helping a user find and rank information, and the person always remains in control of the outcome.

In short: AI in Icon Map is optional, limited in scope, and does not analyse your business data or make automated decisions about people. Customer data is never used to train AI models.

Where Icon Map uses AI

We believe in being explicit about where AI is involved. Icon Map currently uses AI in one feature:

AI-assisted catalogue search (Icon Map Catalog)

When a user types a natural-language request to find a dataset in the Icon Map catalogue, an AI model helps interpret the request and rank the most relevant datasets. Technically, the search prompt is converted into an embedding, a vector search is run against catalogue metadata, and a large language model ranks the candidate datasets by relevance. The models are hosted within Microsoft Azure AI Foundry.

The feature is limited to discovering and ranking catalogue datasets. It does not read, analyse or transmit the data inside your reports. It is optional and can be disabled.

Other Icon Map capabilities (rendering maps, layers, slicing, catalogue hosting) are not AI features and are covered by the security whitepaper.

What data is sent to AI, and what is not

This is the question customers most want answered, so we answer it plainly.

Sent to the AI service

Never sent to the AI service

No training on your data. Tekantis does not use customer data, datasets or prompts to train AI models. The AI processing runs in Microsoft Azure AI Foundry, and Microsoft states that business customer prompts, completions and embeddings are not used to train its foundation models without the customer's permission or instruction.

Our EU AI Act position

The EU AI Act (Regulation (EU) 2024/1689) is risk-based. It places the heaviest obligations on "prohibited" and "high-risk" AI, with lighter transparency duties for AI that interacts with people. Tekantis has carried out a formal internal assessment of its AI feature against these categories.

We describe our features as assessed against the EU AI Act rather than "certified", because the Act does not provide a product certification scheme for low-risk AI.

United States and the NIST AI Risk Management Framework

There is currently no single, comprehensive federal AI law in the United States equivalent to the EU AI Act. The recognised benchmark that US enterprise customers ask about is the NIST AI Risk Management Framework (AI RMF 1.0).

The NIST AI RMF is voluntary guidance, not a certification scheme; "conformance" means we follow its functions and practices.

Transparency and human oversight

Governance and accountability

Behind these features sits a defined governance process, so our position is repeatable and evidenced rather than ad-hoc:

Supporting your compliance reviews

Icon Map is designed to slot into your existing governance. We can support:

More information

More detailed governance documents are available to customers and prospective customers on request, including our:

For our wider security architecture, external resources, coding standards and assurance options, read the Icon Map Pro security whitepaper (PDF). You may also be interested in our Healthcare Compliance (HIPAA & NHS) page.

To request documentation or discuss an AI or security review, please get in touch.