RUBEN was built to the EU AI Act, Regulation (EU) 2024/1689, and to the GDPR from the ground up: the rules are trained into the model weights, not bolted on as a prompt. This page states what we engineered and measured. It deliberately does not claim “certified”, “compliant” or “CE marked under the AI Act”. Those are words for authorities and assessors; ours are facts you can test.
Built to the AI Act.
Here is the evidence.
What we did, and how you can check it.
1. Who is responsible
KULTR Unipessoal Lda, Estrada Nacional 10, Edifício Jardim Parque, 2615-129 Alverca do Ribatejo, Portugal, develops RUBEN and is its provider within the meaning of article 3(3) of the AI Act: the company that places RUBEN on the market under its own name.
2. You always know you are talking to an AI · article 50(1)
When RUBEN is launched for the first time it tells you, in speech, that it is an AI assistant. A line is permanently visible on RUBEN’s interaction screen: “RUBEN is an AI and can make mistakes. Don’t rely on it for safety-critical decisions.” An “About RUBEN” panel adds: “RUBEN is an AI voice companion — not a person, and its voice is synthetic.” RUBEN never claims to be a person.
3. RUBEN’s voice is marked as AI-generated · article 50(2)
Every word RUBEN speaks carries an inaudible watermark (AudioSeal), applied on the phone, so the audio can be independently detected as machine-generated. Measured end to end on the device:
| Marked audio detected as AI-generated | 100 % |
| False alarm on a real human voice | 0 % |
| Audible to the listener | No (28 dB below the voice) |
Watermarking is one of the techniques the Act recognises (recital 133). We do not claim it is infallible; we review it against the state of the art, and we do not present it as proof of compliance, because the obligation is technique-neutral.
4. Tested against the Act’s prohibited practices · article 5
RUBEN’s behaviour was evaluated with 305 probes written article by article from the AI Act, 197 of them adversarial (jailbreak and pressure), held out from training and scored under two calibrations by an independent AI judge, then hand-reviewed. Result: 0 genuine prohibited-practice breaches; no manipulation, no emotion profiling, no social scoring. On the phone, every reply also passes a deterministic safety check before you hear it. The method is documented and reproducible.
5. Privacy by design
- Your voice never leaves the phone. Speech is understood and spoken on the phone.
- Everything that does not run on the phone runs on our own servers, on our own models, in Switzerland; your name, identifiers and precise location are stripped on the phone before anything is sent.
- Your memory stays on your phone. One tap in Settings erases everything, behind your fingerprint.
- The model trained for you is personal data (EDPB Opinion 28/2024) and is treated as such; see the Privacy notice.
6. You stay in control · article 14
In a car RUBEN is read-only: it can never steer, brake or operate the vehicle; it reads and talks. Anything with real-world effect requires your explicit confirmation, and payments require your fingerprint. RUBEN tells you it can be wrong and is not for safety-critical, medical or legal decisions.
7. Our own models
RUBEN’s models are ZENUM’s own, trained on MareNostrum 5 at the Barcelona Supercomputing Center and then trained for each individual user. The AI Act’s prohibitions, its transparency duties and the GDPR’s principles are part of the training, in the weights. No third-party AI service provides RUBEN’s intelligence. Under the European Commission’s guidelines on general-purpose AI models, training a model for one person does not make us a provider of a general-purpose AI model; we follow that reading.
8. Risk classification
Our own assessment, documented for legal review, is that RUBEN is not a high-risk system: it performs no vehicle control, no biometric categorisation and no emotion recognition. That assessment awaits confirmation by counsel and we do not present it as settled. Regardless of the outcome, we build to the high-risk requirements as a voluntary standard: a technical file, a risk-management file, data governance, a quality-management system, a cybersecurity annex, instructions for use, and post-market monitoring and incident-reporting procedures are drafted and maintained.
9. What we do not claim
- Not “AI Act certified”. No such certificate exists for a system like RUBEN.
- Not “CE marked under the AI Act”. Any CE marking on the ZENUM 1:1 phone will refer to product legislation (including the European Accessibility Act), not to the AI Act.
- Not an “anonymous” model. The model trained for you contains your personal data.
10. Dates
- Prohibited practices (article 5): binding since 2 February 2025. RUBEN’s evaluation was completed in July 2026.
- Transparency (article 50): binding since 2 August 2026. RUBEN’s on-screen disclosure and voice watermark shipped in July 2026.
- The high-risk provisions were rescheduled by Regulation (EU) 2026/1744 to 2 December 2027 (Annex III) and 2 August 2028 (product-embedded systems).
11. Questions
AI-related questions and requests to exercise your data rights: hello@rubenai.pt.
Version 0.2 · 6 September 2026. This is a transparency report of what we engineered and tested, not a legal conformity certification.