EU AI Act Transparency — versions

Versions of this document

Every change to the text creates a new version with its own checksum. This list shows which text applied when.

Version

Date

What changed

Checksum (sha256)

Text

3.2.0 (current)

25.09.2026

English version fully aligned with the German one; § 5 on roles completed.

sha256-4a76b532c278c08be6ca86eae3afb9f4e1689f63f99170f4eb246204d1438f62

Full text

3.1.2

23.09.2026

Links in the English version updated to their final addresses.

sha256-8c0e85eb35a12815b8d0b1c896a0cc001eaed46d0cfba59a10210cf15e29a1cb

Full text

3.1.1

23.09.2026

Links updated to the new addresses of the legal texts.

sha256-4daba6c3cd18290c4ac5fd74d18db4667b3cb9ea6060a01f56689bbe042f9257

Full text

3.1.0

23.09.2026

Reasoning in § 5 of the German version written out in full.

sha256-573394f8f0afa270432e23372ab45e84facf03e38410d154666912457e65d7a4

Full text

3.0.0

22.09.2026

Clarified that the AI feature is currently not active in any park; the text is now a commitment for the case of activation. References linked.

sha256-58d641f2d468fb7afed20a9c28009897335aeaf0531bd1d2e4f1acdbf7446d69

on request

2.1.0

16.09.2026

Role as deployer described in more detail and distinguished from the provider's obligations (Art. 50(2)).

sha256-2ccafb2de8714a21f4932fd64ac59cb19dd922a3e2c0c39ba00fefb144114f33

on request

2.0.0

16.09.2026

In-house AI models removed – we use Google Vertex AI only. Our role as deployer under Art. 50(4) AI Act named.

sha256-584516b8c723556fc7ee0bc766aecf3f6c0c0103da73ab7f9d098edf5beb1f06

on request

1.0.0

10.08.2026

Earliest archived version.

sha256-bf4bd25058c47b95a0f1f83b80d4db737b6083bf4f3389c66b6e98c019ae0a92

on request

Full texts of early working versions containing internal review notes are available on request from max@ultido.com; their checksum is shown in the list.

Version 3.2.0 · as of 25.09.2026

Checksum: sha256-4a76b532c278c08be6ca86eae3afb9f4e1689f63f99170f4eb246204d1438f62

1. Why this page

Ultido builds digital guest experiences that include AI features – in particular the optional stylisation of guest photos into themed images. The EU AI Act (Regulation (EU) 2024/1689) requires transparency for AI-generated content (Art. 50, applicable since 2 August 2026). This page explains how we implement it.

2. What AI we use

  • AI image stylisation (product): on request, a guest photo is turned into a stylised themed image. The computation runs on the external AI service Google Vertex AI. Ultido operates no models of its own for this.

  • Currently not in use: the feature is not enabled in any of our deployments. It is not part of the standard scope and is switched on separately per park. Until then, no AI processing of guest photos takes place. The following sections describe what applies from activation onwards.

  • No AI on this website: ultido.com itself uses no AI systems towards visitors (no chatbot, no automated decision-making).

3. How we implement Art. 50 of the AI Act

From activation of the feature:

  • Labelling: every AI-generated image is labelled visibly as AI-generated. The machine-readable marking is provided by the model provider (Art. 50(2)).

  • Information before use: guests give explicit consent and are informed in advance what happens to their photo (platform AI info page).

  • No deception: the feature produces clearly stylised themed images – no deepfakes of real situations.

  • Before switch-on we complete a data protection impact assessment and evidence the labelling.

4. What we do not do

No facial recognition or biometric identification, no emotion recognition, no social scoring, no prohibited practices within the meaning of Art. 5 AI Act. In our assessment we operate no high-risk AI system (Annex III AI Act). Guest photos are processed only transiently and are not used to train models.

5. Roles and responsibility

Ultido integrates a third-party AI system (Google Vertex AI) into its product and is responsible for its use towards users. Ultido is therefore a deployer within the meaning of the AI Act, not a provider; the provider is Google. This gives rise to the disclosure duty under Art. 50(4). The machine-readable marking under Art. 50(2) is the provider's obligation. The disclosure duty under Art. 50(4) applies to image content that constitutes a deepfake; purely fantastical game content falls outside that definition according to the Commission's guidelines. We label throughout regardless, because the line would otherwise have to be drawn per style class. Human oversight: style catalogues and output are editorially curated; abuse reports: max@ultido.com.

6. Data protection

The data protection side (consent, transience, US transfer on the Vertex route) is governed by the platform Privacy Notice and the AI info page.

7. Status and maintenance

This page is updated whenever our use of AI changes (version line and change history at the end of the page).

Version 3.1.2 · as of 23.09.2026

Checksum: sha256-8c0e85eb35a12815b8d0b1c896a0cc001eaed46d0cfba59a10210cf15e29a1cb

1. Why this page: Ultido builds guest experiences that include AI features – in particular optional stylisation of guest photos into themed images. The EU AI Act (Regulation (EU) 2024/1689) requires transparency for AI-generated content (Art. 50, applicable since 2 August 2026).
2. What AI we use: image stylisation via Google Vertex AI. Ultido hosts no models of its own. The feature is not enabled in any of our deployments; it is not part of the standard scope and is switched on per park. Until then no AI processing of guest photos takes place, and the sections below describe what applies from activation onwards. ultido.com itself uses no AI towards visitors (no chatbot, no automated decision-making).
3. How we implement Art. 50 (from activation): every AI-generated image is labelled visibly as AI-generated, with the machine-readable marking provided by the model provider (Art. 50(2)); guests are informed and consent before use (platform AI info page); the feature produces clearly stylised themed images – no deceptive deepfakes. Before switch-on we complete a data protection impact assessment and evidence the labelling.
4. What we do not do: no facial recognition or biometric identification, no emotion recognition, no social scoring, no prohibited practices (Art. 5); in our assessment no high-risk system (Annex III); photos are transient and never used for model training.
5. Roles: Ultido integrates a third-party model into its product and is responsible for its use towards users – i.e. deployer within the meaning of the AI Act, with the disclosure duty of Art. 50(4) for image content that constitutes a deepfake. Purely fantastical game assets fall outside the deepfake definition per the Commission guidelines; we label throughout regardless, because the delineation would otherwise have to be made per style class. Human oversight through curated style catalogues; abuse reports: max@ultido.com.
6. Privacy: consent, transience and US transfers are governed by the platform Privacy Notice and AI info page.
7. Versioning: updated whenever our AI use changes (version line + change history).

Version 3.1.1 · as of 23.09.2026

Checksum: sha256-4daba6c3cd18290c4ac5fd74d18db4667b3cb9ea6060a01f56689bbe042f9257

1. Why this page: Ultido builds guest experiences that include AI features – in particular optional stylisation of guest photos into themed images. The EU AI Act (Regulation (EU) 2024/1689) requires transparency for AI-generated content (Art. 50, applicable since 2 August 2026).
2. What AI we use: image stylisation via Google Vertex AI. Ultido hosts no models of its own. The feature is not enabled in any of our deployments; it is not part of the standard scope and is switched on per park. Until then no AI processing of guest photos takes place, and the sections below describe what applies from activation onwards. ultido.com itself uses no AI towards visitors (no chatbot, no automated decision-making).
3. How we implement Art. 50 (from activation): every AI-generated image is labelled visibly as AI-generated, with the machine-readable marking provided by the model provider (Art. 50(2)); guests are informed and consent before use (platform AI info page); the feature produces clearly stylised themed images – no deceptive deepfakes. Before switch-on we complete a data protection impact assessment and evidence the labelling.
4. What we do not do: no facial recognition or biometric identification, no emotion recognition, no social scoring, no prohibited practices (Art. 5); in our assessment no high-risk system (Annex III); photos are transient and never used for model training.
5. Roles: Ultido integrates a third-party model into its product and is responsible for its use towards users – i.e. deployer within the meaning of the AI Act, with the disclosure duty of Art. 50(4) for image content that constitutes a deepfake. Purely fantastical game assets fall outside the deepfake definition per the Commission guidelines; we label throughout regardless, because the delineation would otherwise have to be made per style class. Human oversight through curated style catalogues; abuse reports: max@ultido.com.
6. Privacy: consent, transience and US transfers are governed by the platform Privacy Notice and AI info page.
7. Versioning: updated whenever our AI use changes (version line + change history).

Version 3.1.0 · as of 23.09.2026

Checksum: sha256-573394f8f0afa270432e23372ab45e84facf03e38410d154666912457e65d7a4

1. Why this page: Ultido builds guest experiences that include AI features – in particular optional stylisation of guest photos into themed images. The EU AI Act (Regulation (EU) 2024/1689) requires transparency for AI-generated content (Art. 50, applicable since 2 August 2026).
2. What AI we use: image stylisation via Google Vertex AI. Ultido hosts no models of its own. The feature is not enabled in any of our deployments; it is not part of the standard scope and is switched on per park. Until then no AI processing of guest photos takes place, and the sections below describe what applies from activation onwards. ultido.com itself uses no AI towards visitors (no chatbot, no automated decision-making).
3. How we implement Art. 50 (from activation): every AI-generated image is labelled visibly as AI-generated, with the machine-readable marking provided by the model provider (Art. 50(2)); guests are informed and consent before use (platform AI info page); the feature produces clearly stylised themed images – no deceptive deepfakes. Before switch-on we complete a data protection impact assessment and evidence the labelling.
4. What we do not do: no facial recognition or biometric identification, no emotion recognition, no social scoring, no prohibited practices (Art. 5); in our assessment no high-risk system (Annex III); photos are transient and never used for model training.
5. Roles: Ultido integrates a third-party model into its product and is responsible for its use towards users – i.e. deployer within the meaning of the AI Act, with the disclosure duty of Art. 50(4) for image content that constitutes a deepfake. Purely fantastical game assets fall outside the deepfake definition per the Commission guidelines; we label throughout regardless, because the delineation would otherwise have to be made per style class. Human oversight through curated style catalogues; abuse reports: max@ultido.com.
6. Privacy: consent, transience and US transfers are governed by the platform Privacy Notice and AI info page.
7. Versioning: updated whenever our AI use changes (version line + change history).