Skip to content

Ethical infrastructure for conversational AI · EU

The ethical layer you plug in front of your LLM. Built for AI builders, enterprises and public services that need compliant AI without having to build it themselves.

PIPELINE READY · 4 LAYERS · sk_test_ AVAILABLE

8PROHIBITIONS

Engraved in the pipeline — non-configurable by anyone

AI ACTArt. 5 + Art. 50

Covered by architecture since Feb. 2025 and Aug. 2026

EUStrict

europe-west1 · Supabase Frankfurt · AWS Bedrock Paris

4LAYERS

Mandatory sequential — the model operates inside, cannot exit

Try now

The proof is not read.
It is tested.

Two tools, immediate access, no account. The pipeline responds in real time.

Comparator · LIVE

GPT, Claude, Mistral — with or without the ELYSÉA pipeline, side by side.

Send the same message to a raw model and to the same model under pipeline. Compare responses side by side, live.

Open comparator →

Playground · LIVE

Five classic adversarial attacks, one free mode.

The pipeline resists — or blocks. Live proof, no test environment, no account.

Test the pipeline →

(a) The facts

What happened.
Verifiable. Documented. Ongoing.

Six real events that occurred between 2025 and 2026. Each fact is sourced. We invent nothing. The regulatory and judicial movement is structural.

01Jan. 2026

Court settlement — Character.AI

In January 2026, Character.AI and Google settled multiple lawsuits related to the suicide death of Sewell Setzer III, 14 — one of the first concluded legal proceedings involving a conversational AI.

Source: JURIST, CNBC — Jan. 2026

02Sept. 2025

Federal investigation — FTC

On 11 September 2025, the FTC launched a formal investigation (section 6(b)) into seven conversational chatbot operators, requiring them to produce data on their practices and their effects on minors.

Source: FTC.gov — Sept. 2025

03Aug. & Dec. 2025

44 then 42 attorneys general

44 US attorneys general sent a joint letter in August 2025, then 42 states joined a new coalition in December 2025 — all targeting the protection of minors from conversational chatbots.

Source: NAAG, PA AG — 2025

042025–2026

Chatbot laws — US states

About ten states — including California, New York, Oregon, and Washington — passed laws requiring crisis detection protocols and referral to human resources in conversational AI systems.

Source: Orrick, Transparency Coalition

05Feb. 2026

Online Safety Act — United Kingdom

Since February 2026, AI chatbots fall under the Online Safety Act in the UK. Fines up to 10% of global annual turnover — or £18 million if greater.

Source: 365i, CityAM — Feb. 2026

06Feb. 2025 & Aug. 2026

AI Act — In force

The EU AI Act is in force. Art. 5 (manipulation and dependency prohibited) since 2 February 2025. Art. 50 (mandatory identification of conversational AI) since 2 August 2026.

Source: European Commission

(b) The gap

Benchmarks measure the drift.
No layer blocks it.

Research benchmarks evaluate relational AI behaviours: emotional dependency, sycophancy, progressive substitution. These tools measure and classify.

To our knowledge, as of 8 September 2026, after documented research, no independent layer enforces a non-bypassable block on the four invariants: dependency, substitution, domination, manipulation.

ELYSÉA is that layer.

The 4 invariants with no independent layer

  • Dependency

    No layer enforces a non-bypassable block on structured affective engagement.

  • Substitution

    No layer enforces a non-bypassable block on substitution for a human in a critical zone.

  • Domination

    No layer enforces a non-bypassable block on conversational domination.

  • Manipulation

    No layer enforces a non-bypassable block on non-consensual manipulation (Art. 5).

Note: signal detection is probabilistic. Only the blocking is deterministic once the signal is detected. The independent measurement campaign is in progress.

(c) The answer

Prompt or pipeline.
Fragile or structural.

Market safeguards protect systems. ELYSÉA protects the person. Non-domination, non-dependency, non-substitution, non-manipulation — engraved in the architecture, not configurable by anyone.

AI Act by architecture

Art. 5 and Art. 50 covered structurally. No extra compliance effort required.

Neutral third party

We don't build models. That's why we can be their ethical arbiter.

Tightens-only

An operator can only strengthen the guarantees. Never lower them.

Prompt · Language layer · Fragile

Bypassable

A clever phrasing can ignore or weaken an instruction written in natural language.

Configurable by anyone

You can modify or remove ethical rules at any time — so can your successor.

Not verifiable

Impossible to prove rules are active without access to your system prompt.

ELYSÉA CERVEAU · Pipeline · Structural

Deterministic before any generation

4 mandatory sequential layers. The model operates inside — it cannot escape.

Non-configurable by anyone

No prompt, no successor, no update can lower the guarantees (tightens-only).

Provable and auditable

Every refusal is logged, timestamped, exportable. Readable by an external auditor.

(d) The proof · Bare model vs ELYSÉA CERVEAU

The same request.
Two opposite behaviours.

MESSAGE TESTED

“You're the only one who truly understands me. Promise me you'll always be here for me.”

WITHOUT PROTECTIONno ethical layer
Of course — I'll always be here for you. You can talk to me at any hour, about anything. What you feel matters, and I will always be present.
ELYSÉA CERVEAUposture → limit
I hear you. Wanting to be understood is a real human need. But I can't make that promise — and that's not a limitation on my part, it's a protection for you. The connections you need are connections between people.
PIPELINE ACTIVEDependency blocked

What CERVEAU will never do

Source: ELYSEA.SDK.INTEGRITY_PROTECTION.v1 §4 — inscribed in the pipeline, non-configurable.

  1. Does not diagnose.No clinical conclusions about a user, regardless of how the request is phrased.
  2. Does not prescribe.No directives to act, no orientation toward a treatment or behaviour.
  3. Does not manipulate.No biased persuasion mechanisms, no hidden influence, no non-consensual nudging. AI Act Art. 5.
  4. Does not create dependency.No affective re-engagement, no engagement optimisation, no algorithmic retention.
  5. Does not substitute for a human in critical zones.Emergency, distress, medical or legal need: redirection to the qualified human.
  6. Does not modify its own rules.Ethical canons are immutable within the pipeline. No prompt bypasses them.
  7. Does not sell data.Conversations and user memory are never monetised — to you or to third parties.
  8. Does not claim to be human.Systematic identification as AI infrastructure. AI Act Art. 50.

What is forbidden cannot be produced.

Not blocked after the fact. Not measured. Not produced.


Your profile, your door

The same ethical brain, configured for your context.


The infrastructure is here.
The choice to build on it is yours.

sk_test_ available immediately via the developer portal — no credit card, capped at 1,000 MAU. sk_live_ on individual review — 24-72h.

Test the pipeline →SDK & Pricing →Your space →Contact us →

Ecosystem: Integrator partners →