DeepL and the EU AI Act
Cologne-based company offering machine translation and writing tools via web, apps and API, widely used by European businesses.
What the Act means when you deploy DeepL
DeepL is an EU-based, task-specific AI vendor — translation tooling is generally low-drama under the Act, and DeepL is not primarily a GPAI model provider in the Act's sense. Your review is mostly about data: what you paste or send through the API can contain personal or confidential content, so processing location, retention and training-use are the questions that matter, alongside checking that no high-stakes workflow (e.g. legal or safety-relevant text) silently depends on unreviewed machine output.
Questions to send DeepL
Copy these into your supplier questionnaire. Answers in writing beat answers on a call — your Article 26 file needs evidence, not recollection.
- Q1
Under which plans is our text excluded from being used to improve your models, and where is that stated contractually?
- Q2
Where are our texts processed and stored, and how long are they retained on the plan we use?
- Q3
What does your DPA cover for API usage, and who are the sub-processors?
- Q4
What options exist for SSO and admin controls so we can govern which teams send content to the service?
Documents to request for your file
- Instructions for use / product documentation for the exact service and version you deploy
- Identification of the underlying model(s) and their provider, plus the documentation passed through to you
- Data processing agreement, sub-processor list and processing locations
- Security documentation: certifications, retention defaults and access controls
- Written statement on whether your inputs and outputs are used for training, and how to opt out
- Licence terms for the exact version you deploy, including commercial-use conditions
Which of these you can actually obtain depends on your contract and tier — treat the list as a checklist to work through with the vendor, not as an entitlement.
Articles to have on the table
- Art. 26Deployer obligations
If you use this vendor's technology professionally in a high-risk context, you must follow the instructions for use, assign competent human oversight, keep logs and monitor operation.
- Art. 25When you become the provider
Putting your own name on the system, changing its intended purpose or substantially modifying it moves you from deployer to provider — with Article 16 obligations attached.
- Art. 50Transparency towards people
Where people interact with an AI system, or where content is AI-generated or manipulated, disclosure and — in defined cases — machine-readable marking are required. This duty sits with you, not the vendor.
Most buyers of AI land in the deployer role. Read the full deployer obligations under Article 26 — or the overview of all operator roles if you are not sure which one you hold.
Go to the source
Verify everything on this page with DeepL directly. Public pages change; profiles do not update themselves.
Important: what this page is not
This profile is based on publicly available information about DeepL and describes only who they are and what they offer. It makes no assessment of DeepL’s compliance, contains no rating or certification claim, and is not endorsed by or affiliated with DeepL.
EU AI Act obligations depend on how you deploy this vendor's technology and on your role (provider, deployer, importer, distributor). Verify every fact and commitment directly with the vendor before relying on it — this profile is a starting point, not legal advice.
Nothing here is legal advice. Confirm the facts with the vendor and your own counsel before you rely on them.
Run the free 2-minute checker — deterministic classification, no sign-up.