← Allviss

Methodology & AI Act Transparency

Allviss produces AI-drafted intelligence-style analysis (a BLUF, competing hypotheses, indicators, NATO-standard probability language) from open-source material, written for a human reader. This page states plainly what that means for how the output should be used, and what accountability measures are in place — in the spirit of the EU AI Act's transparency obligation (Article 50).

This is an engineering-level self-assessment, published for transparency. It is not a legal compliance certification. Allviss self-classifies as a limited-risk system under the EU AI Act: it is not designed or licensed for automated decisions about a named, identifiable individual (hiring, credit, immigration, insurance, or law-enforcement risk scoring).

The intelligence cycle

Underneath the analytic steps sits the doctrinal intelligence cycle: the Norwegian Armed Forces' unclassified Etterretningsdoktrine 2021 describes an intelligence process whose four phases allviss runs as an ordered pipeline for every analysis.

How allviss reasons

Allviss follows the four-step structured-analysis method taught at the Norwegian Intelligence School (Etterretningsskolen). The published account of that framework is Skjelderup, Haugestad, Pedersen & Stivang, Etterretningsanalyse: Kritisk tenkning og strukturerte analyseteknikker (Fagbokforlaget, 2025). A method is a shared professional practice, not something one book owns — what follows is our own account of how allviss executes it, condensed for a public reader. The full account, written so a domain expert can check each claim against the code that implements it, is in our engineering documentation.

Every analysis runs the same four analytic steps, inside the Analysis phase of the cycle above:

The report leads with a Bottom Line Up Front and standalone falsifiable Key Judgments — 2 to 5 numbered, dated statements, each carrying a probability word mapped to a fixed numeric band (NATO/PHIA-style words of estimative probability) so "likely" means the same thing in every report.

Quality gates and source independence

Generated output is not trusted because it parsed. A two-tier evaluator checks each step first with deterministic structural rules and then, where those flag something, with an independent model review; a failed check triggers one retry. A separate grounding gate checks Step 3's evidence against the collected source material and fails closed on anything that cannot be verified — an unproven citation never silently passes. Source corroboration is weighted by counting independent voices, not rows: reference URLs are clustered by shared domain, shared wire-service byline, and near-duplicate headline, so ten reprints of one wire story count as one voice, not ten — the doctrinal defence against circular reporting.

What the model cannot yet do

Two gaps, stated plainly rather than papered over. First, there is no calibration record: allviss cannot yet tell you whether its past "likely" calls have historically meant 70%. Probability words map to fixed numeric bands, but nothing yet scores past forecasts against real-world outcomes — read the probability language as a well-specified estimate, not a track-record-backed one. Second, Steps 2 through 4 are produced by a single model rather than a team reasoning from genuinely independent priors; the challenge layers run on different models, which is real cross-model checking, but it is not the same as independent analysts.

Every report says what it is

Every channel Allviss delivers through — the PDF report, the web report, the chat assistant, and onboarding email — carries an explicit AI-generated disclosure, not a one-time notice buried in terms of service. Reports are generated with that disclosure built into the drafting step itself, not added after the fact.

Decision support, not a decision-maker

Allviss is built and positioned as a prioritization and flagging aid for a human analyst — never as a substitute for one, and never as an automated determination of fact. Report language is written to state implications and watch items, not verdicts, and to flag rather than assert when a claim cannot be adequately sourced.

Traceable, checkable output

Data protection

Users can request export or deletion of their data at any time (GDPR Articles 15 and 17). Retention periods and encryption-at-rest are documented and enforced, not left to policy alone. User-submitted questions and report content are never exposed outside the authenticated account that owns them — including in our own operational tooling and logs.

What we haven't finished

We'd rather say this plainly than imply otherwise: there is no lawyer-reviewed risk-tier determination on file yet, and "human oversight" today is a product-design commitment rather than a hard technical gate — nothing currently stops a reader from acting on a report without pausing at the disclosure. We're not claiming more than that.