Voice intake for global research teams
AI researchers and safety leads often work in mixed-language teams. Reporters can dictate their report in any of 17 languages. The server only ever sees the text.

AI-ettevõtted seisavad silmitsi ELi rikkumisest teavitavate isikute kaitse direktiivi eriversiooniga: globaalsed uurimisrühmad, mitmekeelne personal ja mainerisk, mis on suurem kui enamikul tööstusharudestest. Pakume kanalit, mis vastab direktiivile 2019/1937, sobib AI-tiimide tegelikule tööviisile ja läbib reaalse hanke due diligence küsimustiku.
5 min
Registreerimisest toimiva teavituskanalini.
17
Keeled globaalsetele uurimisrühmadele. Häälsisend, eraldi leht keele kohta puudub.
0
Salvestatud helisalvestised. Heli transkribeeritakse brauseris ja kustutatakse. Me ei näe seda kunagi.
E2E
Lõpust lõpuni krüpteerimine. Teatajal on võti. Sisu me ei saa lugeda.
Overview
The EU Whistleblower Directive 2019/1937 applies to any legal entity with 50+ employees that operates in the EU, regardless of industry. AI companies hit this threshold early — often at Series A — and once they sell to enterprise customers, the requirement is reinforced by procurement due-diligence questionnaires that ask for a documented internal reporting channel. The AI Act (Regulation (EU) 2024/1689) does not itself require a whistleblower channel, but it does require general-purpose AI providers to have internal grievance mechanisms for fundamental-rights issues. A single channel covers both obligations without operational overlap.
What applies to you
Most AI companies we work with are navigating two parallel compliance regimes at once. Here is what the law actually requires — and where our channel maps onto it.
Internal reporting channels for legal entities with 50+ employees. Seven-day acknowledgment, three-month feedback, no retaliation. Member-state law (e.g. HinSchG in Germany, Loi Sapin II in France) layers on local specifics.
General-purpose AI providers must enable fundamental-rights complaints. Our internal channel routes those to the right team without changing the data flow.
Enterprise customers routinely include a "describe your internal reporting channel" question in their vendor security questionnaires. Saying "email us" is not a passing answer in 2026.
Anti-retaliation duties apply to the AI company once a report is filed. Documented intake + case history is the employer's strongest defense in any subsequent dispute.
Sertifikaatide poole püüdlevad AI-ettevõtted vajavad dokumenteeritud, auditeeritavat sissevõtu- ja juhtumihaldusprotsessi. Meie juhtumipõhine sündmuste logi ajatemplite ja tegutsejatega on auditijälg, mis toetab neid nõudeid — see ei ole kogu audit, vaid kõige paremini testitud osa.
Why Ashio for AI
The reason most AI companies pick us over a generic ticketing tool or a Slack-channel workaround.
AI researchers and safety leads often work in mixed-language teams. Reporters can dictate their report in any of 17 languages. The server only ever sees the text.
Every case gets a unique URL the reporter can use to follow up anonymously. No login, no account, no friction. Same model as how Linear and Notion share issues.
Teataja krüpteerib teavituse brauseris võtmega, mis on ainult temal. Turvajuht dekrüpteerib. Sisu me ei saa lugeda.
Isegi alla direktiivi 50 töötaja künnise, dokumenteeritud sisemine teavituskanal aitab läbida ettevõtete ostu due diligence küsimustikud. Paljud meie kliendid, kellel on alla 50 töötajat, võtavad selle kasutusele enne Series A-d SOC 2 auditi jaoks või seetõttu, et nende esimene ettevõtte klient küsis seda tarnija turvaküsimustikus.
Reports can be auto-assigned to your safety lead, your DPO, or your compliance officer based on the report category. No manual triage required.
Juhtumite loendit saab filtreerida kategooria järgi — mudeli eelarvamus, andmekaitse, hindamise terviklikkus jm. Iga teavitus kannab oma kategooriat esitamisest alates, nii et teie turvajuht saab tuua ainult asjakohased üksused.
Compliance checklist
A pre-flight list for AI companies about to sign a contract that requires a documented reporting channel.
Most procurement questionnaires ask for this as a hard requirement. A live URL with a unique access link per case is the standard answer.
The directive requires feedback to the reporter within seven days. We enforce this with a per-case deadline that is visible to every admin from day one.
The directive also requires feedback on how the report was handled within three months. Our case status supports this out of the box.
The directive prohibits retaliation against the reporter. Your hiring, compensation, and assignment records need to be defensible. The case log is the source of truth for that.
If you have staff in multiple EU countries, the local transposition may add extra requirements. Our locales system maps each country to its specific law.
FAQ
No, not directly. The AI Act (Regulation 2024/1689) requires general-purpose AI providers to enable fundamental-rights complaints under Article 86. A whistleblower channel is required by the separate Directive 2019/1937, which applies to legal entities with 50+ employees. Most AI companies we work with operate the single internal channel that satisfies both — the legal duties are complementary, not duplicative.
Not for EU Directive 2019/1937 compliance. But if you sell to enterprise customers, the SOC 2 / ISO 27001 questionnaires most large buyers use will ask "do you have an internal reporting channel?" Saying "no" is increasingly disqualifying. The cost of a 14-day free trial is much lower than losing a deal over that question.
Yes. The intake is a public URL — reporters can file from any browser, in any country, in any of 17 languages. The dashboard is a normal web app. There is nothing to install on the reporter's device or in your infrastructure.
Our role is the intake and the case log. The actual anti-retaliation protection (employment law, HR investigations) is your responsibility. What we do provide is a defensible record: every case has a full event log with timestamps and the acting user, so any subsequent retaliation claim can be cross-referenced against the case timeline.
Yes. You can set a default assignee per case category, so reports about model bias, data privacy, or eval integrity go straight to the right person. Multi-stage review (initial triage, then escalation) is also supported.
Jah. ELi rikkumisest teavitavate isikute kaitse direktiiv (artikkel 10 lõige 2 punkt b) loetleb selgesõnaliselt "häälsisendi vahendid" kui vastavuskõlbuliku kanali. Meie häälsisend transkribeeritakse teataja brauseris ja seejärel kustutatakse heli. Server näeb ainult saadud teksti.
7 päeva jooksul vastuvõtmisest. ELi direktiiv 2019/1937 (artikkel 7) nõuab kinnitust 7 päeva jooksul ja tagasisidet tulemuse kohta 3 kuu jooksul. Meie platvorm jõustab mõlemad tähtajad juhtumipõhiste nähtavate taimeritena.
Enamik SOC 2 auditeid otsivad kolme asja: (1) dokumenteeritud sissevõtt juurdepääsetava URL-iga, (2) kinnitus SLA ajatemplitega, ja (3) võltsimiskindel logi selle kohta, kes juhtumit käsitles. Meil on kõik kolm standardtoote osana.
Privaatses sektoris kehtib direktiiv juriidilistele isikutele, kus on vähemalt 50 töötajat. Avalikus sektoris kehtib see kõikidele asutustele, kus on vähemalt 10 kohalikku omavalitsuse töötajat, ja kõikidele valitsusasutustele, olenemata suurusest.
Related reading
Start a 14-day free trial. The compliance is included, the audit log is included, the encryption is included.