AI notice — transparency on the Portal’s assistant
This English translation is provided for convenience only; in case of discrepancy, the Italian version prevails.
Last updated: 23 July 2026.
1. You are interacting with an artificial intelligence system
The Security Portal’s assistant is a generative AI system: answers are produced automatically by a language model, with no human intervention in real time. This page explains how it works, what its limits are and what responsibilities remain with those who use it. A short transparency note is always visible below the conversation window.
Regulatory reference: transparency obligations under art. 50 of Regulation (EU) 2024/1689 (“AI Act”). The system is not designed to fall within the “high-risk” use cases of Annex III — it does not take decisions with legal or similarly significant effects on individuals; Unleaf acts as a deployer of a third-party provider’s model.
2. How it works (in short)
- Your question is converted into a numerical representation (embedding) and used to search for the most relevant passages exclusively within the Portal’s knowledge base (Unleaf editorial content and excerpts from authorised public sources — see the Sources & method page).
- The retrieved passages are passed as context to an OpenAI language model (currently gpt-4o-mini), with instructions requiring it to answer only from that context and to cite the sources used in the [Source N] format.
- If the Portal contains no relevant information, the assistant is instructed to state this explicitly (“I don’t have enough information in the portal to answer”) instead of improvising.
- Cited sources are shown below the answer and are clickable: they lead to the content page on the Portal or to the original external source, with the attributions required by the respective licences.
The system adapts the selection of sources to the role of your account (e.g. more technical answers for CISOs and professionals, more accessible ones for non-specialist staff) and to the interface language. This is an ordering preference, not a filter: it does not exclude content and does not produce decisions about you.
3. Limits you need to know
- Answers may contain errors. Even with source grounding, a generative model can misunderstand, oversimplify, combine passages incorrectly or translate imprecisely. Always check the cited sources before relying on an answer.
- The assistant only knows the Portal’s corpus. It does not browse the web in real time and does not cover what has not been indexed: the absence of information on the Portal does not mean it does not exist. The knowledge base is updated periodically by the editorial team and by an automated nightly ingestion from authorised sources.
- No real-time human review. Answers are not reviewed by a person before being shown to you. Quality is checked on samples, after the fact, through a periodic review process (automatic pre-assessment + human verdict).
- Answers are not professional advice. They are general information and do not replace personalised assessments by qualified professionals (see Terms of use, art. 7). In particular, do not base security, legal or organisational decisions with significant consequences solely on an assistant’s answer.
- Sources may be in another language. The assistant may draw on Italian or English sources and translate them into the interface language: the translation is automatic and may introduce terminological imprecision.
4. Your responsibilities
- Verify information against the cited sources before using it.
- Do not include in the conversation unnecessary personal data of third parties, classified or confidential information you have no right to dispose of, or unlawful content.
- Use the answers within the limits of the Terms of use (internal professional use, no public redistribution, no training of other AI systems).
5. What happens to your data when you use the assistant
- The text of your question is sent to OpenAI to generate the embedding; to generate the answer, the passages retrieved from the corpus and the previous messages of the same conversation (your questions and the assistant’s answers) are sent as well. For API customers such as Unleaf, OpenAI states that data is not used to train its models and is normally retained for no more than 30 days for service delivery and abuse detection, subject to legal obligations and exceptions for specific endpoints documented by OpenAI.
- Question, generated answer, cited sources, role, model used, your user identifier and email, and date/time are recorded in an audit log you can consult from your dashboard, used for traceability, security, enforcement of the monthly usage cap (100 queries/month) and answer quality review. The full text of questions and answers is anonymised after 90 days; the remaining pseudonymised metadata (sources, role, timestamps, outcome) is deleted after 12 months.
Full details, legal bases and your rights in the Portal’s privacy notice.
6. Reports
If an answer seems wrong or incomplete, or cites a source improperly, you can report it through the channel indicated in the “Reports & corrections” section of Sources & method. Reports feed the quality review process and, where necessary, content corrections.