Ashio whistleblowing software
AI compliance

A confidential reporting channel, built for AI companies.

AI uzņēmumi saskaras ar īpašu ES Trauksmes cēlēju aizsardzības direktīvas versiju: globālām pētniecības komandām, daudzvalodu personālam un reputācijas riskiem, kas ir lielāki nekā vairumā nozaru. Mēs piedāvājam kanālu, kas atbilst Direktīvai 2019/1937, atbilst AI komandu faktiskajam darbam un iztur reālu iepirkumu due diligence anketu.

5 min

No reģistrācijas līdz funkcionējošam ziņošanas kanālam.

17

Valodas globālām pētniecības komandām. Balss ievade, nav atsevišķas lapa katrai valodai.

0

Saglabātie audio ieraksti. Audio tiek transkribēts pārlūkprogrammā un izdzēsts. Mēs to nekad neredzam.

E2E

Pilnīga šifrēšana. Ziņotājam ir atslēga. Mēs nevaram lasīt saturu.

Overview

Why AI companies need this

The EU Whistleblower Directive 2019/1937 applies to any legal entity with 50+ employees that operates in the EU, regardless of industry. AI companies hit this threshold early — often at Series A — and once they sell to enterprise customers, the requirement is reinforced by procurement due-diligence questionnaires that ask for a documented internal reporting channel. The AI Act (Regulation (EU) 2024/1689) does not itself require a whistleblower channel, but it does require general-purpose AI providers to have internal grievance mechanisms for fundamental-rights issues. A single channel covers both obligations without operational overlap.

What applies to you

The regulations that touch AI companies

Most AI companies we work with are navigating two parallel compliance regimes at once. Here is what the law actually requires — and where our channel maps onto it.

EU Directive 2019/1937

Internal reporting channels for legal entities with 50+ employees. Seven-day acknowledgment, three-month feedback, no retaliation. Member-state law (e.g. HinSchG in Germany, Loi Sapin II in France) layers on local specifics.

AI Act 2024/1689 (Article 86)

General-purpose AI providers must enable fundamental-rights complaints. Our internal channel routes those to the right team without changing the data flow.

Procurement due diligence

Enterprise customers routinely include a "describe your internal reporting channel" question in their vendor security questionnaires. Saying "email us" is not a passing answer in 2026.

Whistleblower protection

Anti-retaliation duties apply to the AI company once a report is filed. Documented intake + case history is the employer's strongest defense in any subsequent dispute.

ISO 27001 / SOC 2 alignment

AI uzņēmumi, kas tiecas pie šiem sertifikātiem, vajadzīgs dokumentēts, auditējams uzņemšanas un lietu pārvaldības process. Mūsu lietu žurnāls ar laika zīmogiem un aktīviem lietotājiem ir auditācijas pēdas, kas atbalsta šīs prasības — tas nav viss audits, bet vislabāk pārbaudītā daļa.

Why Ashio for AI

A channel that fits how AI teams actually work

The reason most AI companies pick us over a generic ticketing tool or a Slack-channel workaround.

Voice intake for global research teams

AI researchers and safety leads often work in mixed-language teams. Reporters can dictate their report in any of 17 languages. The server only ever sees the text.

Per-case access URLs

Every case gets a unique URL the reporter can use to follow up anonymously. No login, no account, no friction. Same model as how Linear and Notion share issues.

End-to-end encryption

Ziņotājs šifrē ziņojumu pārlūkprogrammā ar atslēgu, kas ir tikai viņam. Drošības vadītājs atšifrē. Mēs nevaram lasīt saturu.

Mazāk par 50 darbiniekiem? Daudzi AI uzņēmumi tomēr sāk šeit.

Pat zem direktīvas 50 darbinieku sliekšņa, dokumentēts iekšējais ziņošanas kanāls palīdz nokārtot uzņēmumu iepirkumu due diligence anketas. Daudzi mūsu klienti, kuriem ir mazāk par 50 darbinieku, to ievieš pirms Series A, SOC 2 audita nolūkos, vai tāpēc, ka viņu pirmais uzņēmuma klients to pieprasīja piegādātāja drošības anketā.

Routes to the right team automatically

Reports can be auto-assigned to your safety lead, your DPO, or your compliance officer based on the report category. No manual triage required.

Filtrējiet paneli pēc kategorijas

Lietu sarakstu var filtrēt pēc kategorijas — modeļa aizspriedumiem, datu privātumam, novērtējuma integritātei un citam. Katrs ziņojums nes savu kategoriju no iesniegšanas brīža, lai jūsu drošības vadītājs varētu izvilkt tikai atbilstošos vienumus.

Compliance checklist

Set this up before your next enterprise deal

A pre-flight list for AI companies about to sign a contract that requires a documented reporting channel.

  • 1

    Document the channel exists and is operational

    Most procurement questionnaires ask for this as a hard requirement. A live URL with a unique access link per case is the standard answer.

  • 2

    Document the 7-day acknowledgment SLA

    The directive requires feedback to the reporter within seven days. We enforce this with a per-case deadline that is visible to every admin from day one.

  • 3

    Document the 3-month feedback window

    The directive also requires feedback on how the report was handled within three months. Our case status supports this out of the box.

  • 4

    Document the anti-retaliation posture

    The directive prohibits retaliation against the reporter. Your hiring, compensation, and assignment records need to be defensible. The case log is the source of truth for that.

  • 5

    Document the cross-border applicability

    If you have staff in multiple EU countries, the local transposition may add extra requirements. Our locales system maps each country to its specific law.

FAQ

Common questions from AI companies

Does the EU AI Act require a whistleblower channel?+

No, not directly. The AI Act (Regulation 2024/1689) requires general-purpose AI providers to enable fundamental-rights complaints under Article 86. A whistleblower channel is required by the separate Directive 2019/1937, which applies to legal entities with 50+ employees. Most AI companies we work with operate the single internal channel that satisfies both — the legal duties are complementary, not duplicative.

We are below 50 employees. Do we still need this?+

Not for EU Directive 2019/1937 compliance. But if you sell to enterprise customers, the SOC 2 / ISO 27001 questionnaires most large buyers use will ask "do you have an internal reporting channel?" Saying "no" is increasingly disqualifying. The cost of a 14-day free trial is much lower than losing a deal over that question.

We are a remote-first company. Does this work?+

Yes. The intake is a public URL — reporters can file from any browser, in any country, in any of 17 languages. The dashboard is a normal web app. There is nothing to install on the reporter's device or in your infrastructure.

How do you handle retaliation cases?+

Our role is the intake and the case log. The actual anti-retaliation protection (employment law, HR investigations) is your responsibility. What we do provide is a defensible record: every case has a full event log with timestamps and the acting user, so any subsequent retaliation claim can be cross-referenced against the case timeline.

Can reports go to our AI safety lead automatically?+

Yes. You can set a default assignee per case category, so reports about model bias, data privacy, or eval integrity go straight to the right person. Multi-stage review (initial triage, then escalation) is also supported.

Vai balss ievade ir atļauta ES ziņošanas kanālos?+

Jā. ES Trauksmes cēlēju aizsardzības direktīva (10. panta 2. punkta b) apakšpunkts skaidri uzskaita "balss teksta pārveides rīkus" kā atbilstošu kanālu. Mūsu balss ievade tiek transkribēta ziņotāja pārlūkprogrammā un pēc tam izdzēsta. Serveris redz tik iegūto tekstu.

Cik atri AI uznemumiem japstiprina zinojums saskana ar ES tiesibam?+

7 dienu laikā pēc saņemšanas. ES Direktīva 2019/1937 (7. pants) prasa apstiprinājumu 7 dienu laikā un atgriezenisko saiti par rezultātu 3 mēnešu laikā. Mūsu platforma izpilda abus termiņus kā redzamus taimerus katram gadījumam.

Ko meklē SOC 2 auditors zinosanas kanālā?+

Lielākā daļa SOC 2 auditu meklē trīs lietas: (1) dokumentētu uzņemšanu ar pieejamu URL, (2) apstiprinājuma SLA ar laika zīmogiem, un (3) neviltojamu žurnālu par to, kurš izskatīja lietu. Visi trīs ir standarta produkta daļa.

Kādi ir ES Trauksmes cēlēju aizsardzības direktīvas 50 darbinieku sliekšņi?+

Privātajā sektorā direktīva attiecas uz juridiskām personām, kurās ir vismaz 50 darbinieki. Publiskajā sektorā tā attiecas uz visām iestādēm, kurās ir vismaz 10 pašvaldības darbinieku, un uz visām valsts iestādēm neatkarīgi no lieluma.

Related reading

Where to go next

Stay compliant by default.

Start a 14-day free trial. The compliance is included, the audit log is included, the encryption is included.