AI policy
Effective 27 August 2026 · EU AI Act (Regulation (EU) 2024/1689) · UK GDPR
Draft pending legal review. This page is published so that the terms are visible and can be evaluated, but it has not yet been reviewed by counsel.
CostSlice is operated by Media Yard LLC. CostSlice is not a model. It is a pass-through OpenAI proxy and a customer P&L. This page is our EU AI Act statement and how we handle AI traffic.
What Media Yard LLC is not
We do not place an AI system on the Union market under our name. We are not a provider of a general-purpose AI model. We are not the deployer of the AI feature in your product. You are. OpenAI is the provider of the model that fulfills the completion, under the OpenAI API key you provide. CostSlice does not generate content for a natural person, does not chat with an end user, and does not make a decision about a person.
Article 50 transparency sits with you and OpenAI
If your product interacts with people in the EU using a model, you (as deployer) and OpenAI (as provider) own the Art. 50 disclosures: that a person is interacting with AI, and any labelling of AI-generated output. We do not rewrite prompts or completions, so we do not strip watermarks, provenance headers, or other markers the model provider attaches. We do not prohibit you from making required disclosures. We do not add our own user-facing AI chat.
Not high-risk, not prohibited
CostSlice is a cost and usage report. It is not an Annex III high-risk AI system (it is not used for hiring, credit, education access, law enforcement, or the other listed uses). We do not offer prohibited practices (social scoring, untargeted scraping of faces, emotion recognition in the workplace). If you send that kind of traffic through the proxy, you are still the deployer of your system. Do not use CostSlice to run a prohibited practice.
No automated decisions about people
The P&L does not cap, block, or auto-price a customer. Humans raise a price, trim a window, or export a CSV. That is not UK GDPR Article 22 automated decision-making, and it is not an AI Act high-risk decision. Opaque tags should not be a person’s name.
We do not train on your traffic
We do not store prompt bodies. We do not store completion bodies. We do not use your content to train, fine-tune, or evaluate a model. We do not sell it. Usage metadata (model, tokens, latency, tags, timestamps) is enough to build the P&L. Retention follows the plan: 7, 90, or 365 days. See Privacy and the DPA.
Your AI still answers
If CostSlice is slow or a tag is missing, the completion still returns. Untagged traffic lands in untagged. We would rather show a messy row than drop a customer reply. That is the opposite of a gateway that blocks.
What we do not claim
We are not SOC 2 or HIPAA certified. We are not an AI-safety vendor and we do not sell Art. 12 audit packs. We are not a model provider. UK data-protection complaints: ICO. Policy questions: hello@costslice.com.