Transparency by design

Compliance & transparency.

MSAI is a sovereign, full-stack UK AI company - and we hold ourselves to the highest transparency bar. This page sets out, in full, how we meet the EU AI Act and UK GDPR across everything we build.

Last updated: 17 August 2026 · Media Stream AI Limited (trading as MSAI)

Our commitment

We believe sovereign AI must also be accountable AI. MSAI designs, owns, hosts and trains its models and infrastructure in the United Kingdom, and we publish the documentation, disclosures and safeguards required by law - and often more than is required - so that customers, regulators and the public can see exactly how our systems work.

  • Open-weight MOTHER models with published model cards and checkpoint lineage.
  • Human-in-the-loop by default; a signed Guardian layer governs any embodied action.
  • UK/EU data residency; on-prem and air-gapped deployment options.
  • Clear labelling of AI-generated and synthetic media.

EU AI Act

Reg. (EU) 2024/1689

Our role - provider of general-purpose AI models

MOTHER CORE V2 & V3 are open-weight general-purpose AI (GPAI) models. As their provider, we meet the obligations in Article 53 and make the following available:

  • Up-to-date technical documentation of the models and their training and testing (Art. 53(1)(a)–(b)).
  • A copyright-compliance policy respecting the Art. 4(3) text-and-data-mining reservation of rights (Art. 53(1)(c)).
  • A public summary of training content using the AI Office template (Art. 53(1)(d)).
  • Information enabling downstream providers to understand and comply with their own obligations.

Systemic risk (Art. 55)

Our models are 7B-parameter class and are not trained above the 10²⁵ FLOP threshold that presumes systemic risk, so the additional Article 55 obligations for systemic-risk GPAI do not currently apply. We nonetheless perform model evaluations, adversarial testing and incident tracking as good practice, and will adopt Article 55 measures if a future model crosses that threshold.

Prohibited practices (Art. 5)

We do not build or offer AI for any practice prohibited by the Act - including social scoring, subliminal or manipulative techniques, exploitation of vulnerabilities, untargeted facial-image scraping, emotion inference in the workplace or education, or real-time remote biometric identification in public spaces for law enforcement.

Transparency to people (Art. 50)

  • Where users interact with an AI system (e.g. a chatbot or copilot), that fact is disclosed.
  • AI-generated or manipulated image, audio and video (including deepfakes) is marked as artificially generated.
  • Synthetic-media outputs are, where technically feasible, machine-readable and detectable as AI-generated.

Human oversight & high-risk use

For embodied and safety-critical deployments (MOTHER EXO, MOTHER Defence), a signed Guardian action filter holds veto authority over every actuation, red-lines are enforced independently of the model, and every decision is logged to an auditable ledger. Where a customer deploys our technology in a high-risk context under Annex III, we support their conformity obligations with documentation, logging and human-oversight tooling.

UK GDPR & Data Protection Act 2018

Controller

Data controller: Media Stream AI Limited (trading as MSAI), Manchester, United Kingdom. For data-protection queries: [email protected].

Lawful bases (Art. 6)

  • Contract - to provide the service you sign up for.
  • Legitimate interests - to secure, improve and operate our platforms (balanced against your rights).
  • Consent - for optional analytics, marketing, and any special-category processing.
  • Legal obligation - where we must retain or disclose data by law.

Special-category data (Art. 9)

Any biometric personalisation is strictly opt-in and processed only on your explicit consent, which you can withdraw at any time. We do not use biometric data for identification of others.

Your rights

  • Access a copy of your data
  • Rectify inaccurate data
  • Erase your data (right to be forgotten)
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time
  • Not be subject to solely automated decisions with legal effect
  • Complain to the ICO (ico.org.uk)

Transfers, retention & security

Personal data is stored and processed on UK sovereign infrastructure. We do not transfer personal data outside the UK/EEA except under an adequacy decision or appropriate safeguards. We retain data only as long as necessary for the purposes above or as required by law, and protect it with encryption, access controls and on-prem / air-gap options. See the full Privacy Notice.

Data sovereignty & residency

Sovereignty is ownership across every layer - land, power, data centres, compute and models, in Britain. Weights and customer data never leave your control: default UK residency, sovereign GB10 / DGX serving, and on-prem or air-gapped deployment for regulated and defence customers, all on UK sovereign infrastructure.

AI-content transparency

Content generated or materially altered by our AI (image, audio, video, text) is disclosed as AI-generated in accordance with Article 50 of the EU AI Act. Where feasible we embed machine-readable provenance so downstream platforms can detect synthetic media. Human review is expected before reliance on any AI output.

Cookies & analytics

We use strictly necessary cookies to run the site, and optional analytics/marketing cookies only with your consent. You can change your choice at any time. Details of the cookies we set and their purposes are in our Privacy Notice.

Documents & downloads

White papers & dossiers

Register with your name and email to download our white papers and due-diligence dossier - this helps us keep you informed and route your interest to the right team.

Publicly available under EU AI Act Art. 53

The statutory copyright policy and training-content summary are also available without registration, as the Regulation requires:

Data protection: [email protected] · AI Act / model transparency: [email protected] · General: [email protected].