01 What Is the Brain?
An agentic AI platform for workforce empowerment
Not a Chatbot. A Structured Knowledge Workspace.
The brain is a persistent, agentic AI platform where human operators command specialized AI agents through natural language. Each brain is a structured workspace — with its own identity, knowledge base, tools, and memory — that empowers a professional to operate at a level that would otherwise require a team of specialists.
The AI model (currently Claude API by Anthropic) is the engine. The brain — the accumulated knowledge, the operating rules, the audit trail — belongs to the user. The model is replaceable. The brain is not.
02 Architecture
Five layers that make a brain
boot/wiki/tools/agents/diary/03 Data Flow
How information moves through the system
CONSTRAINT — every external action requires explicit human approval
04 Why High-Risk Under the EU AI Act
Annex III, Point 4 — Employment & Recruitment AI
When used for candidate screening, scoring, or assessment support, this platform falls under Annex III, point 4(a) of Regulation (EU) 2024/1689: AI systems intended for recruitment or selection of natural persons. Full compliance with Articles 6-49 required by 2 August 2026.
Our position: compliance by architecture, not by retrofit. Human oversight, transparency, and bias mitigation are structural properties — not features that can be toggled off.
05 Live Deployments
This is not a concept — it runs daily
David — CEO Brain
8+ specialized agents. Manages recruitment operations, business development, finance, legal, social media, client communications. Non-coder operating at specialist level across domains.
Yoni — Director Brain
Same architecture, different content. Client delivery, pipeline management, operational workflows. Proves the multi-user model works independently.
Emisfera — 6 Agency Brains
Six brains deployed at an Italian web agency. Independent organization, independent users. Third-party proof that the model works beyond the founders.
01 Infrastructure & Data Sovereignty
Belgian-hosted, EU-sovereign, no cloud dependency
Belgian On-Premise Server
Dedicated server physically located in Belgium. No cloud database, no US provider dependency for data storage. Full EU data sovereignty. Data at rest never leaves Belgian jurisdiction.
File-System Based
The brain uses structured files (markdown + YAML), not a cloud database. Full portability, no vendor lock-in, version control via Git, standard formats. The user can export their entire brain at any time.
02 Workspace Isolation
Each brain is sandboxed
Multi-Tenant Security Model
- Every brain workspace has its own isolated credentials (
.envwith 600 permissions) - Workspaces cannot see, access, or interact with other workspaces' data
- File-system permissions enforce isolation at the OS level
- Shared tools verify credentials before executing — no credentials = no action, clean error
- Each brain has separate API keys, email accounts, and calendar access
03 GDPR — Native by Design
- Pseudonymization is mandatory. Candidates always referenced by initials (M.R., A.B.) — enforced at the system level
- No full names in logs or diary entries
- Salary data protected in context
- Client data separation enforced (no cross-client leakage)
- Right to deletion fully supported (file-based = easy to locate and delete)
- Active recruitment: Duration + 6 months
- Talent pool (with consent): Maximum 2 years
- Unsuccessful candidates: 3-6 months post-process
- Background checks: 6 months post-completion
- Deletion certificates generated for audit trail
04 Security Measures
| Measure | Implementation | Status |
|---|---|---|
| Encryption at rest | AES-256 for stored data | Active |
| Encryption in transit | TLS 1.3 for all API communications | Active |
| Access controls | Role-based access, SSH key authentication | Active |
| Credential isolation | Separate .env per workspace, 600 permissions | Active |
| Audit logging | Git version control — full change history | Active |
| Breach response | 72-hour notification protocol per GDPR Art. 33 | Documented |
| Data Processing Agreements | DPA with clients (controller-processor) | Active |
| Incident response playbook | Severity classification, response procedures | Published |
05 AI Model Communication
What goes to the API — and what doesn't
Anthropic API — Data Safeguards
When the brain processes a request, relevant context is sent to Claude's API for inference. Safeguards:
- Anthropic does NOT train on API customer data (contractual commitment)
- API inputs are not stored beyond the request lifecycle
- The brain minimizes data sent — only relevant context, never full database exports
- No biometric data, no photos, no social media scraping is ever performed
- Candidate data is pseudonymized before AI processing where possible
01 AI Model: Claude API
Clear boundaries between model provider and deployer
No Training on User Data
Anthropic's contractual commitment: API customer data is not used to train or improve models. Conversations are not stored for training. No fine-tuning occurs on user inputs.
Model Provider Obligations
Anthropic is subject to EU AI Act GPAI obligations (Title V, Art. 51-56). Responsible for model-level compliance, training data transparency, EU Copyright Directive obligations.
02 Brain Content Ownership
The user owns everything in their brain
User-Owned Intellectual Property
- The brain is the user's property. All files in wiki/, diary/, tools/, and public/ belong to the user/organization
- File-system based — export the entire brain at any time as standard files
- No proprietary lock-in — brain files are markdown, YAML, HTML, Python
- Version history via Git — full provenance of every change
- The platform is infrastructure; the knowledge is the user's intellectual property
03 IP Protection Boundaries
| Element | Ownership | Protection |
|---|---|---|
| Brain content (wiki/, diary/) | User / Organization | File-system ownership, Git history, fully exportable |
| Agent specifications (agents/) | User / Organization | Custom configurations owned by deployer |
| Generated outputs (reports, emails, portals) | User / Organization | Work product, standard IP rules |
| Platform infrastructure (shared/) | Platform provider | Licensed for use, not user-owned |
| AI model (Claude) | Anthropic | API license, no training on user data |
| Client data processed | Client (data controller) | GDPR, DPA, processor obligations |
No Scraping. No Sharing. No Aggregation.
The brain platform does not scrape external data, does not share user data with third parties beyond the API inference call, and does not aggregate data across workspaces. Each brain is an island. The only external data flow is the API call for inference — transient and not retained by the model provider.
01 Human Oversight
Architectural enforcement, not an optional feature
- Step 1: AI generates a draft
- Step 2: Draft shown to human in chat
- Step 3: Human reviews, modifies if needed
- Step 4: Explicit confirmation required
- No email is ever sent without human approval
- Publishing content → human approval required
- Calendar events → human approval required
- Client communications → human approval required
- Data deletion → human approval required
- The AI proposes; the human disposes. Always.
02 Audit Trail
Every significant action logged and reconstructible
Complete Decision Traceability
diary/captures every decision, action, and interaction with timestamps- Git version control: complete change history for every file modification
- Agent activations, mode switches, and command executions are traceable
- Candidate screening decisions include reviewer attribution and timestamp
- Logs retained indefinitely via Git; minimum 6 months guaranteed per Art. 26(5)
03 Agent Boundaries
Each mode has defined scope — agents cannot exceed it
| Agent | Scope | Can Do | Cannot Do |
|---|---|---|---|
| Recruiter | Recruitment ops | Draft outreach, screen CVs, prepare presentations | Make hiring decisions, reject candidates autonomously |
| Finance | Financial analysis | P&L modeling, projections, invoice tracking | Execute payments, sign contracts, commit obligations |
| Legal | Legal advisory | Draft contracts, review compliance, research | Provide binding advice, sign agreements |
| Social | LinkedIn content | Draft posts, editorial calendar, translation | Publish without approval, comment as the user |
| Background Check | Verification | Structure process, generate templates | Make pass/fail decisions, contact refs without approval |
| Client Ops | Project management | Score applications, generate notices, prep assessments | Reject candidates without human confirmation |
04 Bias Monitoring
Built-In Bias Mitigation
Blind screening (initials only, no photos/age/gender). Nationality excluded from scoring. Culturally-adapted psychometrics. Adverse impact analysis after each scoring run. Interviews 60% / tests 40% — human judgment dominates.
ULB-KTO Validation
Partnership with Université Libre de Bruxelles for algorithmic auditing. Focus: bias detection in screening, fairness constraints. Third-party, academically rigorous validation of AI-assisted decisions.
05 Fundamental Rights Impact Assessment
FRIA completed March 2026 per Article 27
Five Fundamental Rights Analyzed
A comprehensive FRIA has been completed for the CEFTA Secretariat recruitment project (6 positions, Western Balkans candidate pool). It covers:
- Right to non-discrimination (EU Charter, Art. 21; ECHR, Art. 14)
- Right to privacy and data protection (EU Charter, Art. 7-8; GDPR)
- Right to human dignity (EU Charter, Art. 1)
- Right to effective remedy and fair trial (EU Charter, Art. 47)
- Right to good administration (EU Charter, Art. 41)
This FRIA methodology is reusable across all client engagements and serves as a compliance template for AI deployment in recruitment.
06 Self-Assessment
Status against key EU AI Act articles
| Article | Requirement | Status | Evidence |
|---|---|---|---|
| Art. 9 | Risk Management System | Green | FRIA completed, risk register maintained |
| Art. 10 | Data Governance | Green | GDPR framework, pseudonymization, retention schedules |
| Art. 12 | Record-Keeping | Green | diary/ logs, Git version control, audit trails |
| Art. 13 | Transparency | Green | Full documentation of capabilities and limitations |
| Art. 14 | Human Oversight | Green | Architecturally enforced — all external actions gated |
| Art. 15 | Accuracy & Robustness | Amber | Operational validation; formal metrics in progress |
| Art. 26(2) | Human Oversight (Deployer) | Green | Designated persons with competence and authority |
| Art. 26(5) | Log Retention | Green | Retained indefinitely via Git; 6+ months guaranteed |
| Art. 26(11) | Inform Individuals | Amber | AI disclosure notice on forms; update in progress |
| Art. 27 | FRIA | Green | Completed March 2026 |
| Art. 4 | AI Literacy | Green | Operator deeply trained in AI capabilities/limitations |
| Art. 5 | Prohibited Practices | Green | No emotion recognition, biometric categorization, social scoring |
01 Empowerment, Not Replacement
The brain amplifies human capability — it doesn't automate away roles
- Gives professionals access to domain expertise, playbooks, and tools that would require years of experience or a specialist team
- A non-technical CEO manages finance, legal, and client comms through specialized agents
- A junior recruiter operates at senior level from day one
- Knowledge stays in the organization when people leave
- Capability compounds over time
- Does NOT make autonomous hiring or firing decisions
- Does NOT replace human judgment in critical matters
- Does NOT operate without human supervision
- Does NOT create dependency — deliberate "struggle zones" where humans must apply judgment
- Does NOT eliminate jobs — elevates the scope of what each person can accomplish
02 The "Broken Rung" Problem
Why this matters right now
The Paradox
Companies are eliminating junior roles (AI handles grunt work that was also the learning path) while struggling to find capable people (nobody's getting trained anymore). The brain bridges this gap: juniors arrive productive immediately while still developing real skills — because the brain coaches rather than dictates.
03 Living Proof
Non-coders empowered, not replaced
David — IT Proficiency: 2/10
Manages complex RPO operations, builds client portals, handles P&L modeling, drafts legal documents, creates compliance frameworks, runs trilingual content strategy. The brain gave him capabilities that would otherwise require 5-6 specialists.
Yoni — Not a Coder Either
Independent client delivery, pipeline management, operational workflows, personal style adaptation. Same architecture, different person, different content — proves the model works universally.
Emisfera — 6 Independent Users
Web agency in Italy. Six brains deployed for their own operations. Not our company, not our employees. Strongest proof the architecture works beyond the founders.
04 Anti-Shallow-Competence Design
The Brain Coaches — It Doesn't Dictate
Stanford research shows 28% skill degradation when AI is removed after 6 months. The brain addresses this deliberately:
- Struggle zones: Areas where the user must apply their own judgment — the brain provides framework, not answers
- Escalation, not automation: Complex decisions go to the human, not resolved by AI
- Transparent reasoning: The brain explains its logic so the user learns, not just follows
- Progressive autonomy: As the user grows, they handle more complexity with less scaffolding
The goal: capability that compounds WITH the person, not instead of them.
05 Impact on Employment
Net positive across every dimension
| Dimension | Traditional AI Risk | Brain-Powered Approach |
|---|---|---|
| Job displacement | Automates tasks, eliminates roles | Amplifies roles, expands scope per person |
| Skill development | Creates dependency, atrophies skills | Coaches through struggle zones, builds competence |
| Knowledge retention | Trapped in models, not portable | Owned by user, stays in org, fully portable |
| Access to expertise | Gatekept by expensive tools/training | Democratized through brain templates |
| Junior workforce | "Broken rung" — juniors disappear | Bridge: productive from day 1, still learning |
| Human oversight | Optional, often bypassed | Architectural requirement, cannot be bypassed |
Kill Switch
Any AI agent can be disabled at any time. Every process can complete entirely without AI — slower but fully functional. No AI system is a single point of failure. The human can always revert to manual operation.