AI Transparency Statement and Instructions for Use

Version 2026-08.2 — Effective August 6, 2026

1. What this document is

Ploid AI Biotech, S.L., a Spanish limited liability company with Tax ID (CIF) B19786623, registered office at Avenida Diagonal, 612 - P. 1 PTA. 3, 08021 Barcelona, Spain ("Ploid", "we", "us"), is the provider of the AI system described here.

This document serves two purposes:

  1. It is our transparency statement under Article 50 of Regulation (EU) 2024/1689 (the AI Act): it tells you that you are interacting with an AI system, on whose behalf that system acts, and how content it generates is marked.
  2. It is our instructions for use: what the system is for, what it can and cannot do on its own, where it is known to fail, and what a competent user has to do to use it safely.

It applies to every Ploid deployment, including deployments Ploid operates exclusively for a single organization. Unlike our other legal documents, this one is not conditional on a Ploid contract governing your use: the obligations it discharges are ours as provider of the system, and they do not change because your organization signed a separate agreement. Where Ploid operates a dedicated deployment, the AI system is provided by Ploid and operated on behalf of that organization, and both are disclosed to you in the application.

This document is referenced from Sections 4A and 9A of our End User License Agreement and forms part of it.

2. Intended purpose

The Services are a research platform for bioinformatics and life-sciences analysis. Their intended purpose is to help a qualified researcher explore data, write and run analysis code, execute computational workflows, and draft research documents — with that researcher retaining responsibility for the scientific conclusions.

The Services are intended for research and informational use only. In particular:

Section 4 of the EULA makes these prohibitions binding obligations, not merely stated intentions. If you place the Services on the market under your own name, modify them substantially, or change their intended purpose so that the system falls into a high-risk category, you become a provider of that system and assume the corresponding obligations; Section 9A of the EULA sets this out.

3. What the agent does, and what it does without asking

The Services are agentic: on a single request the AI agent plans a course of action and carries it out over many steps, rather than answering once. It works inside a per-study sandbox — an isolated computing environment holding that study's files.

Acts the agent performs on its own, with no confirmation step:

Read that list carefully. The agent is not asked to approve each command before it runs it. Oversight of execution is retrospective — you see every command and its result in the conversation, and you can stop a run in progress — rather than a prior approval gate. This is a deliberate design choice for research work, and it is the single most important thing to understand about supervising this system.

Acts that require your explicit confirmation before they take effect:

Acts the agent cannot perform at all:

Where it stops and asks you. The agent can pause and put a question to you when a request is ambiguous or a decision is yours to make. While it is waiting, the conversation is blocked until you answer. You can also stop any run in progress at any point.

The record of what it did. Every step — each command run, each result returned, each question asked and answered — is kept and shown to you in the conversation. Section 6 describes how to read it as a single record and download it.

4. The agents you may interact with

Requests are handled by an orchestrating agent, which may delegate parts of the work to specialized worker agents. Each is an AI system component, and each is identified as such where its work is shown to you:

AgentWhat it is allowed to do
OrchestratorPlans the work and executes it with full sandbox access, including running code. Delegates to the workers below.
ExplorerRead-only. Inspects the sandbox, lists files and datasets, reads files, searches code, reviews workflow runs, and queries the web. Cannot write files or run scripts.
OperatorExecution. Writes and edits files, runs Python, R and shell commands, starts workflow runs, and stages datasets and scripts from sandbox output.

You do not choose between them; the orchestrator decides when to delegate. Their work appears in the conversation attributed to the agent that performed it. You do choose the model tier the agent runs on, which trades speed against depth of reasoning.

5. Known limitations, and how outputs fail

Outputs are generated by large language models. They are probabilistic: the same request can produce different results on different runs, so an analysis is not reproducible from the request alone — it is reproducible from the code and the workflow the agent produced, which is why both are kept in the study.

The failure modes below are the ones we consider realistic and material. They are not hypothetical, and they are not exhaustive.

6. Human oversight

The Services are built on the assumption that a qualified researcher reviews the work rather than accepting the conclusion. These are the points at which that is enforced rather than merely expected:

7. Accuracy, validation, and what we do not claim

8. Data types, and human data in particular

The Services are built for research data, and their design assumptions — including that no output is a clinical finding — follow from that.

Each workspace declares its data type. A workspace is created as holding plant, animal or microbial data, and an owner or administrator can declare that it holds human data instead. Declaring human data requires an explicit confirmation that your organization has a lawful basis under Article 9(2) GDPR, and that confirmation is recorded against the person who made it. While the declaration is in force, the workspace carries a research-use-only notice that cannot be dismissed, and that notice is written into every report exported from it, on every page. Workspaces that hold no human data carry none of this.

Where you process personal data, you are the controller and Ploid is the processor; our Data Processing Agreement governs that processing and our Privacy Policy explains the boundary between the data we hold as controller and the data we hold as processor.

Human genetic, clinical and other special-category data. Data of this kind is special-category personal data under Article 9 GDPR. You must not place it in the Services unless:

Ploid does not inspect the content you upload and cannot detect a failure to meet these conditions. Section 4 of the EULA, Section 2.3 of the DPA and Section 3.3 of the Privacy Policy state the same requirement as a binding obligation.

Research on plants, animals, microbial and environmental data, where no personal data is involved, does not engage these conditions.

9. How generated content is marked

Reports, figures and documents the Services produce are synthetic content: they are generated by an AI system, not authored by a person.

Two deliberate limits on what is marked:

If you republish or circulate content the Services generated, the obligation to disclose that it is AI-generated travels with it. Removing or obscuring the provenance record does not remove that obligation, and Section 4 of the EULA prohibits presenting outputs as human-authored or as clinically validated.

10. Third-party models and where inference runs

Producing an output requires sending the relevant part of your content to a model inference provider. Those providers are sub-processors, and they are named with their role and location at Subprocessors.

A workspace is created with EU data residency, under which model calls are routed to inference endpoints inside the European Union. An administrator of your workspace may change it to global residency, which permits routing outside the EU; that is a controller decision, and Sections 5.3 and 7 of the DPA govern the resulting transfer.

Ploid selects inference providers whose terms prohibit them from using data submitted through their APIs to train their own models, and configures the Services accordingly. Whether Ploid may use your content to improve its own models depends on your plan, and is governed by Section 6 of the EULA — the single authoritative statement of those terms.

11. Changes, and how to reach us

We will update this document as the Services change. Each version carries a version identifier and an effective date, and material changes are notified in the application.

Ploid AI Biotech, S.L. Avenida Diagonal, 612 - P. 1 PTA. 3, 08021 Barcelona, Spain CIF B19786623 (EU OSS VAT ID ESB19786623) Email: legal@ploid.ai

12. Related documents