Trust Center

Compliance & Regulatory Engineering

AI in employment is regulated activity. GattAI is engineered to the strictest global and regional frameworks—EU AI Act, GCC data protection laws (KSA & UAE PDPL), and native statutory payroll standards—with immutable records that prove compliance on demand.

Designed to the EU AI Act (High-Risk Baseline)

Under the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689), AI systems utilized in employment, recruitment, performance evaluation, and workforce management are classified as High-Risk (Annex III, Point 4). GattAI implements these rigorous compliance requirements as the global architectural baseline across all operating regions.

No Emotion or Sentiment Inference (Article 5)
GattAI strictly bans biometric emotion analysis, sentiment classification from facial/voice cues, and psychological profiling. The capability is fundamentally absent in our models and codebase, not merely switched off in configuration.
Enforced Human Oversight (Article 14)
No consequential HR outcome—whether candidate disqualification, performance score finalization, disciplinary action, or compensation change—can be executed autonomously. The system enforces an unskippable human approval gate with self-approval prohibited.
Transparency & Provenance (Article 13)
Every AI-generated draft or assessment carries indelibly linked provenance metadata (model identifier, confidence interval, input baseline, and known constraints). This provenance persists even after human reviewers edit the text.
High-Quality Data Governance (Article 10)
AI pipelines operate strictly on curated organizational competency rubrics, approved job specifications, and verifiable performance KPI cards, preventing statistical noise or irrelevant demographic variables from entering the decision path.

GCC & Regional Regulatory Compliance (KSA, UAE, Egypt)

GattAI is purpose-built for organizations operating across the Gulf Cooperation Council (GCC) and the wider Middle East and North Africa (MENA) region. Regional data protection statutes operate alongside complex, legally mandated payroll calculation engines, both integrated directly into our core.

Kingdom of Saudi Arabia (KSA PDPL & Labor Law)
Engineered in full alignment with the Saudi Personal Data Protection Law (PDPL) and SDAIA regulatory guidelines. Core payroll engines natively compute General Organization for Social Insurance (GOSI) employee and employer contributions (including occupational hazards), generate compliant Wages Protection System (WPS / Mudad) SIF files, and map job structures to Qiwa standards.
United Arab Emirates (UAE PDPL & MOHRE)
Compliant with UAE Federal Decree-Law No. 45/2021 on Personal Data Protection, as well as DIFC and ADGM data frameworks. The payroll core calculates statutory End-of-Service Benefits (EOSB / Gratuity) per UAE Federal Decree-Law No. 33/2021, and formats compliant Central Bank WPS payroll files for commercial bank disbursement.
Arab Republic of Egypt (Data Protection & Labor Statutes)
Aligned with Egyptian Data Protection Law No. 151/2020. The statutory calculation engine supports Social Insurance Law No. 148/2019, progressive income tax brackets under Law No. 91/2005, and Unified Tax Procedures Law No. 206/2020.
DPIA as an Enforced Go-Live Gate
Conducting a formal Data Protection Impact Assessment (DPIA) is a mandatory architectural milestone in customer onboarding. An enterprise tenant cannot transition to production without an executed DPIA reviewing data flows and retention schedules.

Algorithmic Bias Monitoring & NYC LL144 Methodology

Where artificial intelligence assists in candidate selection or talent mobility, GattAI continuously computes the exact statistical distribution ratios that employment regulators and labor auditors evaluate—built directly into the analytics engine rather than performed as an afterthought.

Impact-Ratio & Selection Analytics
Candidate screening and shortlisting pipelines continuously calculate selection rates and adverse impact ratios using the Four-Fifths (80%) Rule, aligning with NYC Local Law 144 (LL144) AEDT audit standards and US EEOC guidelines.
Demographic Blind Screening
Candidate CV parsing systematically suppresses protected characteristics—including gender, age, nationality, marital status, and photographs—during initial algorithmic evaluation, scoring applicants exclusively on validated competencies and relevant experience.
Exportable Auditor Package
All underlying distribution data, selection frequencies, scoring rubrics, and demographic impact ratios export on demand as a cryptographically signed Auditor Pack, enabling independent third-party bias auditors to inspect live empirical data.

Automated impact-ratio reporting empowers organizations with continuous visibility. Where specific jurisdictions mandate an annual independent bias audit by a licensed auditor, our exportable auditor pack is formatted specifically for immediate third-party review.

The Structured, Exportable AI Decision Log

Every AI inference invocation across all 8 modules generates a structured, immutable decision record. Retained for a minimum of 12 months (and configurable up to statutory 7-year audit requirements), this log enables immediate reconstruction of any historical HR action.

Complete Lineage Capture
Each log entry preserves the model name, exact prompt template version, tokenized input snapshot, raw generated output, token expense, timestamp, authenticated human approver, and any reviewer edits or override reasons.
Immediate Regulatory Audit Readiness
When labor regulators, internal audit teams, or employee representatives inquire into how an interview was evaluated or how a review was synthesized, compliance teams export a self-contained, tamper-evident audit report with a single click.
Structured fields captured in every immutable AI decision record
event_id: "evt_ai_8f3d1b9" · tenant_id: "ten_mena_042" · timestamp: ISO 8601pipeline: "recruitment_screen" · model: "claude-3-5-sonnet@v2" · prompt_ver: "v4.2.1"input_hash: "sha256:7c8a..." · output_tokens: 1420 · cost_usd: 0.0084approver: "usr_hr_lead_01" · approval_status: "APPROVED_WITH_EDIT"override_reason: "Added regional field experience weighting"hash_chain: "sha256:e3b0c442... -> current: sha256:91f2a4..."

Flexible Data Residency & Provider Controls

Enterprises manage diverse multi-jurisdictional compliance requirements. GattAI provides flexible deployment configurations to ensure data remains strictly within approved borders.

GCC Regional Cloud Tiers
Dedicated hosting options in cloud data centers located in Saudi Arabia (KSA) and the UAE for enterprise and public-sector organizations requiring complete domestic residency.
EU Zero-Retention Routing
For multinational entities with European employees, inference traffic routes through EU-domiciled endpoints under binding Zero Data Retention (ZDR) guarantees.
Custom Model Provider Allowlists
Enterprises maintain complete administrative control over approved model providers. Any LLM provider not approved by customer security and legal policy is strictly blocked from the execution pipeline.