Trumpai
1. Bendrieji principai
- Technologija siūlo, žmogus sprendžia. DI parengia pasiūlymą, sprendimą priima ir atsakomybę prisiima žmogus. G-Procure nepriima sprendimų dėl tiekėjų ar asmenų.
- Skaidrumas. Visada matyti, kas parengta DI, kas siunčiama į DI ir kur. Prie kiekvieno DI mygtuko parašyta, kas bus išsiųsta.
- Atsekamumas. Kur DI remiasi jūsų dokumentu, jis pateikia citatą, o citata programiškai patikrinama prieš ją parodant. Be rastos citatos pasiūlymo priimti negalima.
- Teisė - iš oficialių šaltinių, ne iš DI. Teisės aktų nuorodos, vertės ribos ir terminai imami iš registro, kurio kiekvienas įrašas sutikrintas su oficialiu tekstu e-tar ar EUR-Lex. Juos skaičiuoja testais tikrinamos taisyklės.
- Duomenų kiekio mažinimas. Siunčiama tik tai, ko reikia konkrečiam veiksmui. Pavyzdžiui, pirkimo sąlygų įrankis numatomos vertės į atsakymų pasiūlymus nesiunčia.
- Duomenys lieka pas jus. Darbas saugomas naršyklėje, atsarginė kopija - jūsų faile. Serveris tik persiunčia DI užklausą.
- Saugumas pagal nutylėjimą. API raktas tik serveryje, bibliotekos - su vientisumo patikra, į puslapį įterpiamas tik ekranuotas tekstas.
- Nuolatinis tobulinimas. Kiekvienas pakeitimas tikrinamas automatiniais testais, DI tikslumas matuojamas su tikrais viešais pirkimų paketais, o šis puslapis peržiūrimas kas pusmetį.
2. Paskirtis ir technologija
G-Procure yra viešųjų pirkimų skaitmeninių įrankių rinkinys visam pirkimo ciklui: planavimui, techninei specifikacijai, kvalifikacijos reikalavimams, pirkimo sąlygoms, grafikams, komisijos sprendimams, deryboms ir ataskaitoms. DI naudojamas tik ten, kur jis sutaupo laiko rengiant ar tikrinant tekstą.
Kur DI naudojamas
| Įrankis | Ką daro DI | Ką sprendžia žmogus |
|---|---|---|
| Techninės specifikacijos asistentas | Parengia TS projekto skyrius, analizuoja TS (aiškumas, konkurencijos ribojimai, „arba lygiavertis“), pateikia kainos įvertį | Peržiūri, redaguoja ir tvirtina kiekvieną skyrių. Dokumentas pažymimas kaip juodraštis, kurį turi peržiūrėti pirkimo komisija |
| Kvalifikacijos reikalavimai | Pasiūlo reikalavimus pagal VPT Metodiką ir juos patikrina (proporcingumas, aiškumas) | Tvirtina kiekvieną reikalavimą. DI pataisas taiko tik pažymėjęs. Nepatvirtintas rinkinys eksportuojamas su žyma JUODRAŠTIS |
| Pirkimo sąlygos | Sąlygų tekstą kuria šablonų variklis, ne DI. DI tik pasiūlo atsakymus į klausimus iš jūsų dokumentų (su citata), atpažįsta paraiškos kortelės duomenis ir pasiūlo vertimus | Kiekvieną pasiūlymą priima arba atmeta. Pasiūlymo be patikrintos citatos priimti negalima |
| Anglies pėdsako skaičiuoklė (EPD) | Ištraukia GWP reikšmę iš EPD dokumento, nurodo puslapį ir citatą | Patvirtina arba atmeta reikšmę |
| ESG ir atitiktis | Pateikia preliminarų sankcijų rizikos vertinimą orientavimuisi | Sprendimą priima ir įrašo atsakingas asmuo. DI galutinio verdikto nepateikia |
| G-Procure Tiekėjams | Atsako į tiekėjo klausimus apie CVP IS pirkimo paketą, sudaro pasirengimo kontrolinį sąrašą. Kiekvienas teiginys su citata, nepatikrintos citatos atmetamos | Tiekėjas pats sprendžia, kaip naudoti atsakymą. Atsakymas nėra teisinė konsultacija |
| Teisės stebėsena (redakcija) | Parengia registro įrašo santraukos juodraštį | Įrašas pažymimas „AI juodraštis, nepatvirtinta“, kol jį patvirtina specialistas |
Kur DI nenaudojamas
Skelbimo parengties patikra (tik taisyklės), pirkimų grafikai, komisijos protokolai ir pranešimai, mažos vertės pirkimų pažymos, ekonominio naudingumo skaičiuoklė, kaštų ir naudos analizė, rinkos rodikliai, metinio plano centralizavimo analizė (algoritmas naršyklėje). Protokolų ir derybų įrankiai gali parengti užkoduotą užklausą (tiekėjai - kodais, sumos - procentais nuo numatomos vertės) jūsų organizacijos patvirtintam DI įrankiui; patys jie nieko nesiunčia.
Technologija
- Kalbos modeliai: Anthropic Claude didieji kalbos modeliai, naudojami per komercinę Anthropic API. Numatytasis - Claude Sonnet 4.6; TS asistente galima pasirinkti Claude Opus 4.6 ar Claude Haiku 4.5. G-Procure modelių nemoko ir nederina jūsų duomenimis.
- Architektūra: jūsų naršyklė siunčia užklausą į G-Procure tarpinį serverį (
api.g-procure.com, ES), o šis - į Anthropic API. Viešas EPD įrankis tiekėjams naudoja atskirą tarpinį tašką (epd-api.g-procure.com, Cloudflare). API raktas yra tik serveryje. - Kas vyksta naršyklėje: dokumentų skaitymas (PDF, DOCX, XLSX, ZIP), šablonų pildymas, taisyklių patikros ir darbo išsaugojimas.
- Apsauga nuo klaidinančio turinio dokumentuose: įkelti dokumentai modeliui perduodami kaip duomenys, ne kaip nurodymai; kai kuriuose įrankiuose papildomai ieškoma bandymų pakeisti modelio elgseną.
3. Žmogaus priežiūra
- DI rezultatas visada pažymėtas: „Siūloma (nepatvirtinta)“, „AI parengė“, „DI atsakymas“ ar „AI juodraštis“. Patvirtintu jis tampa tik žmogaus veiksmu.
- Niekas nepritaikoma savaime. Pasiūlymą reikia priimti, atmesti ar pakeisti atskirai.
- Sprendimai „Taip / Ne“ be pagrindo neužpildomi už jus. Kas pašalinama ar pakeičiama, parodoma peržiūroje ir patikroje.
- Kol DI parengtos dalys nepatvirtintos, kvalifikacijos reikalavimų dokumentas žymimas JUODRAŠČIU; TS projektas pažymėtas kaip juodraštis, kurį turi peržiūrėti komisija.
- Tik automatizuotai priimamų sprendimų, kaip apibrėžta BDAR 22 straipsnyje, nėra.
| Sistemos teikėjas (G-Procure) | Naudotojas (pirkimo vykdytojas, komisija, organizatorius, tiekėjas) |
|---|---|
| Kuria įrankius taip, kad DI tik siūlytų, o žmogus tvirtintų | Peržiūri kiekvieną DI pasiūlymą prieš jį priimdamas ir prieš skelbdamas dokumentą |
| Žymi DI turinį ekrane ir eksportuojamuose dokumentuose | Prisiima atsakomybę už pirkimo dokumentų turinį ir sprendimus |
| Prie kiekvieno DI mygtuko pasako, kas bus siunčiama | Nesiunčia įslaptintos informacijos ir be poreikio nesiunčia asmens duomenų |
| Palaiko teisės nuorodų registrą ir taisykles, tikrindamas jas su oficialiais šaltiniais | Laikosi savo organizacijos vidaus taisyklių dėl DI naudojimo |
| Testuoja įrankius ir matuoja DI tikslumą su tikrais viešais pirkimų paketais | Praneša apie klaidas ir netikslumus (žr. 6 skyrių) |
| Kiekviename įrankyje paaiškina, kaip juo naudotis ir kas siunčiama į DI | Rūpinasi savo darbuotojų raštingumu DI srityje (DI akto 4 straipsnis) |
4. Kaip saugoma informacija
- Jūsų naršyklėje. Planai, kortelės, protokolų juodraščiai, projektai ir nustatymai saugomi tik jūsų naršyklėje (localStorage). Kiti žmonės ir G-Procure jų nemato.
- Jūsų faile. Darbą perkelti ar apsaugoti nuo praradimo galite atsargine kopija - tai failas jūsų kompiuteryje (atsarginė kopija).
- G-Procure serveryje - nieko. Tarpinis serveris (Hetzner, Vokietija) tik persiunčia DI užklausą ir jos turinio nesaugo bei į žurnalus nerašo (patikrinta prie šaltinio 2026-07-17; pakartotinė patikra - žr. 9 skyrių).
- DI paslaugos teikėjas. Anthropic API įvesties ir išvesties duomenis ištrina per 30 dienų; ilgiau jie saugomi tik išimtiniais atvejais (pvz. naudojimo politikai vykdyti ar to reikalaujant teisės aktams). Modeliams mokyti jie nenaudojami.
- Ko nesiųsti. Įslaptintos informacijos ir duomenų, kurių jūsų organizacijos taisyklės neleidžia perduoti išorės paslaugų teikėjams.
Išsamiai - privatumo pranešime: kas tvarko duomenis, kokie paslaugų teikėjai pasitelkiami, saugojimo terminai, perdavimas už ES ribų ir jūsų teisės.
5. Atitiktis teisės aktams
ES dirbtinio intelekto aktas
Vertinome G-Procure pagal Reglamentą (ES) 2024/1689 su Reglamento (ES) 2026/1744 pakeitimais (tekstas perskaitytas EUR-Lex 2026-10-05).
- Ne didelės rizikos DI sistema. Viešųjų pirkimų dokumentų rengimas ir tikrinimas nepatenka į didelės rizikos sritis (III priedas), o G-Procure nėra jokio gaminio saugos komponentas (6 straipsnio 1 ir 1a dalys). DI atlieka parengiamąsias ir pagalbines užduotis, sprendžia žmogus.
- Draudžiamos DI praktikos (5 straipsnis) G-Procure netaikoma.
- Skaidrumas (50 straipsnis): G-Procure Tiekėjams asistente iš karto pasakoma, kad atsakymus rengia DI; DI sugeneruotas tekstas pažymimas ekrane ir Word failuose, taip pat kompiuterio skaitomu požymiu.
- Raštingumas DI srityje (4 straipsnis): kiekviename įrankyje - paaiškinimas „Kas tai ir kaip naudotis“, pastabos prie DI mygtukų ir DI rezultatų žymos.
- Bendrosios paskirties DI modelis: Claude modelių tiekėjas yra Anthropic; jam taikomos DI akto V skyriaus pareigos.
Asmens duomenų apsauga (BDAR)
Laikomės BDAR 5 straipsnio principų:
- teisėtumo, sąžiningumo ir skaidrumo - aiškiai sakome, kas, kada ir kur siunčiama;
- tikslo apribojimo - turinys siunčiamas tik jūsų pasirinktam veiksmui ir modeliams mokyti nenaudojamas;
- duomenų kiekio mažinimo - siunčiama tik veiksmui reikalinga dalis;
- tikslumo - DI teiginiai su citatomis, kurias galite patikrinti;
- saugojimo trukmės apribojimo - serveris turinio nesaugo, DI teikėjas jį ištrina per 30 dienų;
- vientisumo ir konfidencialumo - šifruotos jungtys, raktas tik serveryje, darbas tik naršyklėje;
- atskaitomybės - priemones aprašome šiame puslapyje ir privatumo pranešime, jas peržiūrime kas pusmetį.
Viešųjų pirkimų principai
Įrankiai padeda laikytis lygiateisiškumo, nediskriminavimo, abipusio pripažinimo, proporcingumo ir skaidrumo principų: kvalifikacijos reikalavimų proporcingumas vertinamas pagal VPT Metodiką, TS patikra ieško prekės ženklų be „arba lygiavertis“ ir subjektyvių terminų, o PĮ ir VPĮ taisyklės nesumaišomos (pirkimo vykdytojo režimas nurodomas pirkimo kortelėje).
Informacijos saugumas
- API raktai tik serverio pusėje; klientas raktų ir papildomų antraščių siųsti negali.
- Visos jungtys šifruotos (HTTPS).
- Išorinės bibliotekos įkeliamos su vientisumo patikra (Subresource Integrity), PDF skaitymo darbininkas - tik patikrinus jo maišos reikšmę.
- Duomenys, failai ir DI atsakymai į puslapį įterpiami tik ekranuoti (apsauga nuo kodo įterpimo).
- Serverio prieigos instrukcijos pašalintos iš dabartinės viešos kodo saugyklos versijos; serverio prieiga stiprinama (žr. 9 skyrių).
- Kiekvienas pakeitimas automatiškai tikrinamas regresijos testais tikroje naršyklėje.
G-Procure neturi ISO/IEC 27001 sertifikato. Čia išvardytos priemonės yra tai, ką taikome šiandien; jas nuolat stipriname (žr. 9 skyrių).
6. Incidentų valdymas ir kokybės kontrolė
Kaip pranešti
Rašykite arunas.jurgelaitis@litgrid.eu. Nurodykite įrankį ir veiksmą, ką DI pasiūlė ir kas buvo neteisinga; jei galite - ekrano nuotrauką be konfidencialių duomenų. Atsakome per 5 darbo dienas.
| Pranešimo rūšis | Pavyzdys | Kaip reaguojame |
|---|---|---|
| Netikslus ar klaidinantis DI atsakymas | Išgalvota nuoroda, citatos nėra dokumente, reikalavimas prieštarauja Metodikai | Užregistruojame, atkartojame, taisome instrukcijas ar patikras ir papildome testą, kad klaida nesikartotų |
| Taisyklės ar teisės nuorodos klaida | Neteisinga vertės riba ar straipsnio numeris | Patikriname su oficialiu tekstu ir taisome registre, iš kurio nuorodas ima visi įrankiai |
| Saugumo incidentas | Įtariama neteisėta prieiga ar duomenų atskleidimas | Nedelsdami vertiname ir ribojame poveikį |
| Asmens duomenų saugumo pažeidimas | Asmens duomenys pateko netinkamam gavėjui | Duomenų valdytojui pranešame nepagrįstai nedelsdami (BDAR 33 straipsnio 2 dalis) |
Kokybės kontrolė
- Automatiniai testai kiekvienam pakeitimui visuose įrankiuose; svarbūs testai tikrinami ir mutacijomis (tyčia sugadinus kodą, testas turi tai pagauti).
- Matavimai su tikrais duomenimis: DI pasiūlymų tikslumas lyginamas su viešais CVP IS pirkimų paketais.
- Teisės šaltiniai: teisės nuorodų registras sutikrintas su oficialiais tekstais, teisės pokyčių šaltiniai peržiūrimi kas savaitę.
- Peržiūra kas pusmetį: šį puslapį, rizikų matricą ir DI akto vertinimą peržiūrime kas pusmetį ir kaskart, kai keičiasi DI funkcijos ar teisės aktai.
7. Rizikų valdymo ir kontrolės matrica
| Rizika | Galimas poveikis | Kontrolės priemonės | Atsakinga rolė |
|---|---|---|---|
| Netikslūs, išgalvoti („haliucinuojantys“) ar klaidinantys DI atsakymai ir teisiniai neatitikimai | Neteisėtos ar dviprasmiškos sąlygos, pretenzijos ir ginčai, priežiūros institucijos pastabos, vėlavimas | DI tik siūlo, tvirtina žmogus. Citatos tikrinamos programiškai. Teisės nuorodos, ribos ir terminai - iš patikrinto registro ir taisyklių. Juodraščio žyma. Testai ir matavimai su tikrais paketais | Teikėjas: kontrolės, testai, registras. Naudotojas: peržiūra ir galutinis sprendimas |
| Konfidencialios pirkimo informacijos atskleidimas (numatoma vertė, pasiūlymai, neskelbti dokumentai) | Konkurencijos iškraipymas, procedūros pažeidimas, reputacinė žala | Darbas tik naršyklėje. Į DI - tik paspaudus ir tik tai, kas nurodyta prie mygtuko. Serveris turinio nesaugo. Anthropic nenaudoja mokymui ir ištrina per 30 d. Užklausos išoriniams DI įrankiams - tik užkoduotos. Įspėjimas nesiųsti įslaptintos informacijos | Teikėjas: architektūra ir sutartys. Naudotojas: ką siųsti, vidaus taisyklės |
| Per didelis pasitikėjimas DI (automatizavimo šališkumas) | Klaidos patenka į paskelbtus dokumentus | Būsenos „Siūloma“ ir „Patvirtinta“ tik žmogaus veiksmu, kiekvienas pasiūlymas atskirai, jokių tylių numatytųjų, paaiškinimai įrankiuose | Naudotojas: atidi peržiūra, darbuotojų DI raštingumas. Teikėjas: sąsaja |
| Konkurenciją ribojantys ar neproporcingi reikalavimai | Diskriminacija, mažiau tiekėjų, sąlygų ginčijimas | Proporcingumas pagal VPT Metodiką, TS patikra (prekės ženklai be „arba lygiavertis“, subjektyvūs terminai), patikros pastabos su pagrindimu | Teikėjas: taisyklės ir patikros. Naudotojas: pagrindimas ir sprendimas |
| Asmens duomenų tvarkymas (kontaktiniai asmenys, specialistai, parašai) | BDAR pažeidimas | Siunčiama tik reikalinga dalis, saugoma tik naršyklėje, paslaugų teikėjai įvardyti, pranešimas valdytojui apie pažeidimą be nepagrįsto delsimo | Naudotojas (valdytojas): teisinis pagrindas, poveikio vertinimas, jei reikia. Teikėjas (tvarkytojas): saugumas ir pranešimai |
| Pasenusios taisyklės ar teisės nuorodos | Neteisingas būdas, terminai, reikalavimai | Vienas registras visiems įrankiams, teisės pokyčių stebėsena, savaitinė šaltinių peržiūra, įrašai su patikros data, testai lygina skaičius su registro tekstu | Teikėjas: registro priežiūra. Naudotojas: tikrina, ar teisės aktas aktualus jo pirkimui |
| Paslaugos sutrikimas ar modelio elgsenos pokytis | Darbo sutrikimas, nepilnas rezultatas | Nepavykęs ar dalinis rezultatas niekada nerodomas kaip „atlikta“: sakoma, ko trūksta, siūloma bandyti dar kartą; „Atšaukti“ ilgam veiksmui; modelis nustatomas centralizuotai, pakeitus kartojami matavimai | Teikėjas |
| Klaidinantis turinys įkeltuose dokumentuose (nurodymų įterpimas) | Iškraipyti pasiūlymai ar atsakymai | Dokumentai modeliui - kaip duomenys, ne nurodymai; įterpimo požymių paieška; citatų patikra; žmogaus peržiūra | Teikėjas: apsaugos priemonės. Naudotojas: patikimi dokumentai, peržiūra |
8. Kas atsako
G-Procure kūrėjas ir teikėjas (DI akto prasme - DI sistemos tiekėjas) yra Arūnas Jurgelaitis. G-Procure sukurta EPSO-G grupei. Pirkimo vykdytojas, naudojantis G-Procure, yra DI sistemos diegėjas ir savo dokumentuose esančių asmens duomenų valdytojas.
Kontaktas DI valdymo, duomenų apsaugos ir saugumo klausimais: arunas.jurgelaitis@litgrid.eu.
9. Ką stipriname toliau
Saugumą ir atitiktį stipriname nuolat. Artimiausi darbai:
- pakartotinė serverio patikra, kad užklausų turinys nesaugomas ir nerašomas į žurnalus, su nauja patikros data šiame puslapyje;
- serverio apsaugos sustiprinimas: užklausų ribojimas, leidžiami tik G-Procure naudojami modeliai, prieiga tik saugiu raktu;
- viešų įrankių apsauga nuo automatizuotų užklausų;
- DI turinio žymėjimo derinimas su Europos Komisijos rengiamu praktikos kodeksu.
Puslapis atnaujintas 2026-10-05. Kita peržiūra - ne vėliau kaip 2027-04-05. Šis puslapis informuoja apie G-Procure DI naudojimą ir rizikų valdymą; jis nėra teisinė konsultacija ir nekeičia pirkimo vykdytojo pareigų pagal pirkimus reglamentuojančius teisės aktus.
At a glance
1. General principles
- Technology suggests, people decide. AI prepares a suggestion; a person decides and takes responsibility. G-Procure makes no decisions about suppliers or persons.
- Transparency. It is always visible what AI prepared and what is sent to AI and where. Each AI button states what will be sent.
- Traceability. Where AI relies on your document, it gives a quote, and the quote is checked by code before it is shown. A suggestion without a verified quote cannot be accepted.
- Law from official sources, not from AI. Legal references, value thresholds and deadlines come from a register in which every entry was checked against the official text (e-TAR or EUR-Lex), and are calculated by tested rules.
- Data minimisation. Only what a given action needs is sent. For example, the procurement conditions tool does not send the estimated value for answer suggestions.
- Your data stays with you. Work is stored in the browser and backups in your own file. The server only relays the AI request.
- Security by default. The API key exists only on the server, libraries are loaded with integrity checks, and only escaped text is inserted into pages.
- Continuous improvement. Every change is checked by automated tests, AI accuracy is measured on real public procurement packages, and this page is reviewed every six months.
2. Purpose and technology
G-Procure is a set of digital public procurement tools for the whole procurement cycle: planning, technical specifications, qualification requirements, procurement conditions, schedules, committee decisions, negotiations and reports. AI is used only where it saves time when drafting or checking text.
Where AI is used
| Tool | What AI does | What the person decides |
|---|---|---|
| Technical specification assistant | Drafts specification sections, analyses a specification (clarity, restrictions of competition, "or equivalent"), estimates the price | Reviews, edits and approves each section. The document is marked as a draft to be reviewed by the evaluation committee |
| Qualification requirements | Suggests requirements under the Public Procurement Office methodology and checks them (proportionality, clarity) | Approves each requirement. AI corrections are applied only when ticked. An unapproved set is exported marked DRAFT |
| Procurement conditions | The text of the conditions is produced by a template engine, not by AI. AI only suggests answers from your documents (with a quote), reads the request card and suggests translations | Accepts or rejects each suggestion. A suggestion without a verified quote cannot be accepted |
| Carbon footprint calculator (EPD) | Extracts the GWP value from an EPD with page and quote | Confirms or rejects the value |
| ESG and compliance | Gives a preliminary sanctions-risk assessment for orientation | The responsible person decides and records the result. AI gives no final verdict |
| G-Procure for Suppliers | Answers a supplier's questions about a CVP IS procurement package and prepares a readiness checklist; every statement with a quote, unverified quotes are discarded | The supplier decides how to use the answer. An answer is not legal advice |
| Legal monitoring (editorial) | Drafts a summary for a register entry | The entry is marked "AI draft, not approved" until a specialist approves it |
Where AI is not used
Notice readiness check (rules only), procurement schedules, committee minutes and notices, low-value procurement reports, the most economically advantageous tender calculator, cost-benefit analysis, market indicators, annual plan centralisation analysis (an algorithm in the browser). The minutes and negotiation tools can prepare an encoded request (suppliers as codes, amounts as percentages of the estimated value) for an AI tool approved by your organisation; they send nothing themselves.
Technology
- Language models: Anthropic Claude large language models through Anthropic's commercial API. The default is Claude Sonnet 4.6; in the specification assistant Claude Opus 4.6 or Claude Haiku 4.5 can be chosen. G-Procure does not train or fine-tune models on your data.
- Architecture: your browser sends the request to the G-Procure relay server (
api.g-procure.com, EU), which forwards it to the Anthropic API. The public EPD tool for suppliers uses a separate relay (epd-api.g-procure.com, Cloudflare). The API key exists only on the server. - In the browser: reading documents (PDF, DOCX, XLSX, ZIP), filling templates, rule checks and saving your work.
- Protection against misleading content in documents: uploaded documents are passed to the model as data, not as instructions; some tools additionally look for attempts to change the model's behaviour.
3. Human oversight
- AI output is always labelled: "Suggested (not approved)", "AI prepared", "AI response" or "AI draft". It becomes approved only by a person's action.
- Nothing is applied automatically. Each suggestion is accepted, rejected or changed separately.
- Yes / No decisions without a basis are not pre-filled for you. Whatever is removed or changed is shown in the preview and the check.
- While AI-prepared parts are not approved, the qualification requirements document is marked DRAFT; the specification is marked as a draft to be reviewed by the committee.
- There are no decisions based solely on automated processing within the meaning of Article 22 GDPR.
| System provider (G-Procure) | User (contracting authority or entity, committee, organiser, supplier) |
|---|---|
| Builds the tools so that AI only suggests and a person approves | Reviews every AI suggestion before accepting it and before publishing a document |
| Labels AI content on screen and in exported documents | Is responsible for the content of procurement documents and for decisions |
| States next to each AI button what will be sent | Does not send classified information and does not send personal data without need |
| Maintains the legal reference register and rules, checked against official sources | Follows the organisation's internal rules on the use of AI |
| Tests the tools and measures AI accuracy on real public procurement packages | Reports errors and inaccuracies (see section 6) |
| Explains in each tool how to use it and what is sent to AI | Ensures the AI literacy of its staff (Article 4 of the AI Act) |
4. How information is stored
- In your browser. Plans, procurement cards, draft minutes, projects and settings are stored only in your browser (localStorage). Neither other people nor G-Procure can see them.
- In your file. You can move your work or protect it against loss with a backup, which is a file on your computer (data backup).
- Nothing on the G-Procure server. The relay server (Hetzner, Germany) only forwards the AI request and neither stores its content nor writes it to logs (checked at source on 2026-07-17; re-check, see section 9).
- The AI service provider. Anthropic deletes API inputs and outputs within 30 days; they are kept longer only in exceptional cases (for example to enforce its usage policy or where the law requires). They are not used to train models.
- What not to send. Classified information and data that your organisation's rules do not allow to be passed to external service providers.
Details are in the privacy notice: who processes the data, which service providers are used, retention periods, transfers outside the EU and your rights.
5. Legal compliance
EU Artificial Intelligence Act
We assessed G-Procure against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (text read on EUR-Lex on 2026-10-05).
- Not a high-risk AI system. Drafting and checking public procurement documents is not among the high-risk areas (Annex III), and G-Procure is not a safety component of any product (Article 6(1) and (1a)). AI performs preparatory and assistive tasks; people decide.
- Prohibited AI practices (Article 5) do not apply to G-Procure.
- Transparency (Article 50): the G-Procure for Suppliers assistant states up front that answers are prepared by AI; AI-generated text is labelled on screen and in Word files, including a machine-readable property.
- AI literacy (Article 4): each tool has a "What it is and how to use it" panel, notes next to AI buttons and labels on AI output.
- General-purpose AI model: the provider of the Claude models is Anthropic; the obligations of Chapter V of the AI Act apply to it.
Data protection (GDPR)
We follow the principles of Article 5 GDPR:
- lawfulness, fairness and transparency - we state clearly what is sent, when and where;
- purpose limitation - content is sent only for the action you choose and is not used to train models;
- data minimisation - only the part needed for the action is sent;
- accuracy - AI statements come with quotes you can check;
- storage limitation - the server does not store content and the AI provider deletes it within 30 days;
- integrity and confidentiality - encrypted connections, key only on the server, work only in the browser;
- accountability - the measures are described on this page and in the privacy notice and reviewed every six months.
Public procurement principles
The tools help to apply the principles of equal treatment, non-discrimination, mutual recognition, proportionality and transparency: proportionality of qualification requirements is assessed under the Public Procurement Office methodology, the specification check looks for brand names without "or equivalent" and for subjective terms, and the rules for contracting entities (utilities) and contracting authorities are kept apart (the regime is set on the procurement card).
Information security
- API keys only on the server side; the client cannot send keys or extra headers.
- All connections are encrypted (HTTPS).
- External libraries are loaded with Subresource Integrity; the PDF worker runs only after its hash is verified.
- Data, files and AI responses are inserted into pages only after escaping (protection against code injection).
- Server access instructions have been removed from the current version of the public code repository; server access is being hardened (see section 9).
- Every change is automatically checked by regression tests in a real browser.
G-Procure is not ISO/IEC 27001 certified. The measures listed here are what we apply today; we keep strengthening them (see section 9).
6. Incident management and quality control
How to report
Write to arunas.jurgelaitis@litgrid.eu. State the tool and the action, what AI suggested and what was wrong; if possible add a screenshot without confidential data. We reply within 5 working days.
| Type of report | Example | How we respond |
|---|---|---|
| Inaccurate or misleading AI response | An invented reference, a quote not in the document, a requirement contrary to the methodology | We log it, reproduce it, fix the instructions or checks and add a test so that the error does not recur |
| Rule or legal reference error | A wrong value threshold or article number | We check it against the official text and correct the register from which all tools take references |
| Security incident | Suspected unauthorised access or disclosure | We assess it and limit the impact immediately |
| Personal data breach | Personal data reached the wrong recipient | We notify the controller without undue delay (Article 33(2) GDPR) |
Quality control
- Automated tests for every change in all tools; important tests are also checked with mutations (when the code is deliberately broken, a test must catch it).
- Measurements on real data: the accuracy of AI suggestions is compared with public CVP IS procurement packages.
- Legal sources: the legal reference register is checked against official texts, and sources of legal changes are reviewed weekly.
- Review every six months: this page, the risk matrix and the AI Act assessment are reviewed every six months and whenever AI functions or the law change.
7. Risk management and control matrix
| Risk | Possible impact | Controls | Responsible role |
|---|---|---|---|
| Inaccurate, invented ("hallucinated") or misleading AI responses and legal non-compliance | Unlawful or ambiguous conditions, complaints and disputes, findings by the supervisory authority, delays | AI only suggests, a person approves. Quotes are checked by code. Legal references, thresholds and deadlines come from the checked register and rules. Draft marking. Tests and measurements on real packages | Provider: controls, tests, register. User: review and final decision |
| Disclosure of confidential procurement information (estimated value, tenders, unpublished documents) | Distortion of competition, breach of procedure, reputational harm | Work only in the browser. Sent to AI only on click and only what is stated next to the button. The server does not store content. Anthropic does not use it for training and deletes it within 30 days. Requests for external AI tools only in encoded form. Warning not to send classified information | Provider: architecture and contracts. User: what to send, internal rules |
| Over-reliance on AI (automation bias) | Errors reach published documents | "Suggested" and "Approved" states only by a person's action, each suggestion separately, no silent defaults, explanations in the tools | User: careful review, staff AI literacy. Provider: interface |
| Requirements that restrict competition or are disproportionate | Discrimination, fewer suppliers, challenges to the conditions | Proportionality under the methodology, specification check (brand names without "or equivalent", subjective terms), check comments with reasons | Provider: rules and checks. User: justification and decision |
| Processing of personal data (contact persons, specialists, signatures) | GDPR infringement | Only the necessary part is sent, stored only in the browser, service providers named, controller notified of a breach without undue delay | User (controller): legal basis, impact assessment where needed. Provider (processor): security and notifications |
| Outdated rules or legal references | Wrong procedure, deadlines, requirements | One register for all tools, legal change monitoring, weekly source review, entries with check dates, tests compare figures with the register text | Provider: register upkeep. User: checks the act applies to the procurement |
| Service outage or change in model behaviour | Disrupted work, incomplete result | A failed or partial result is never shown as "done": what is missing is stated and a retry offered; "Cancel" for long actions; the model is set centrally and measurements are repeated after a change | Provider |
| Misleading content in uploaded documents (prompt injection) | Distorted suggestions or answers | Documents go to the model as data, not instructions; injection pattern detection; quote checks; human review | Provider: safeguards. User: trusted documents, review |
8. Who is responsible
The creator and provider of G-Procure (the provider of the AI system within the meaning of the AI Act) is Arūnas Jurgelaitis. G-Procure was built for the EPSO-G Group. A contracting authority or entity using G-Procure is the deployer of the AI system and the controller of the personal data in its documents.
Contact for AI governance, data protection and security: arunas.jurgelaitis@litgrid.eu.
9. What we are strengthening next
We keep strengthening security and compliance. Next steps:
- a repeated server check that request content is neither stored nor logged, with the new check date on this page;
- stronger server protection: request rate limits, only the models G-Procure uses allowed, access by secure key only;
- protection of public tools against automated requests;
- aligning the labelling of AI content with the code of practice being prepared by the European Commission.
Page updated on 2026-10-05. Next review no later than 2027-04-05. This page describes how G-Procure uses AI and manages the risks; it is not legal advice and does not change the obligations of contracting authorities and entities under procurement law.