This page sets out where Stats4U uses a language model, what that model is allowed to see and to do, and what Regulation (EU) 2024/1689 (the AI Act) covers of it.
In short
A language model appears in exactly one place: two or three sentences about a counter's development, at the top of its public statistics page. Nowhere else.
The model runs on a second machine belonging to the operator, not at a cloud provider. No model vendor's service is called. Only figures that are already public on the statistics page are sent to it.
The model decides nothing. It phrases. Every number in its sentence was handed to it, and every number is checked afterwards; if the sentence does not hold, it is discarded.
What is outstanding is here too: there is currently no machine-readable marking of the generated sentences as required by Art. 50(2). The reason is under 11.
This page is information, not legal advice. It states the operator's own assessment and has not been reviewed by any authority or lawyer.
1. Why this page exists
The AI Act does not require a page like this. What it requires is a disclosure where the generated text appears — and that is where it is: beneath every box, in the language of the page.
This page is voluntary and goes further. It also says where no artificial intelligence is involved (6.), what role the operator has under the Regulation (8.), and what is still missing (11.). With a visitor counter, the more common question is not what a model does but whether one is counting at all.
It is information and not legal advice. Anyone who needs a legal assessment of their own case should get it from someone who answers for it.
2. The one place
At the top of a counter's statistics page there may be a box with two or three sentences: which weekday was strongest, how many countries the visitors came from, how the last few days compare with the days before them. Those sentences were written by a language model.
The box says so. A line in the language of the page states that a language model wrote the text from the measured figures beside it and that none of the numbers come from the model; next to it stand the name of the model and the date. That is the Art. 50 disclosure — it belongs with the text, not on this page.
Most of the time there is nothing there. A counter only gets sentences if it measured enough over thirty days, and most counters here are below that threshold. How often it comes out that way is counted and stated in the blog.
The box exists only on statistics pages that are public anyway. A counter marked private and a password-protected counter get none.
3. Which model, and where it computes
The operator develops no model. He downloads open model weights from third parties and runs them unchanged. Which model wrote a given sentence is stated beneath that sentence — there and not here, because the model can change and a name in a legal text would then be wrong.
The models run on a second machine belonging to the operator, through a local model server. There is no interface to any model vendor — nothing is transmitted to OpenAI, Google, Anthropic, Mistral or any other service, and nothing comes back from one.
The reason for the second machine is compute time, not data protection: a model needs seconds per answer, the heaviest query in this application needs milliseconds. The two do not belong on the same machine. The measurement is in the blog.
There is no training and no fine-tuning. The weights stay as they were downloaded. No counter data feeds into any training, neither the operator's nor anyone else's.
4. What the model gets to see
Only already aggregated figures for a single counter and the address of the site it sits on: visitors over the last few days against the days before, the share of the strongest country, the number of countries, the strongest weekday, the most visited subpage, device shares.
No IP addresses. No visitor identifiers. No raw data. Nothing that could be assigned to an individual person. There is no row in this system that describes a single visit in the first place.
And only from counters whose statistics page is public. That condition sits in the code at the point where the jobs are handed out — not later, in the display. Without it the whole thing would be a transfer of other people's data to a second device.
The second machine therefore learns nothing that a visitor to the statistics page could not also read. The same is stated in section 5.10 of the privacy policy.
5. What the model may do — and what it may not
It may phrase. Nothing else.
The selection is made by the server: which figure is worth mentioning is computed and decided by code. The model is given one job per fact and writes one sentence from it. It never sees two facts side by side.
Back on the server, every run of digits in the sentence is held against the job. If it does not occur there, the sentence is discarded. Names — weekday, country, device, page — are checked as well: the right one must appear, the ones it could be confused with must not.
The model does not calculate, does not round, does not select and decides nothing. It makes no decision about a person, it rates nobody, it blocks nothing, and it affects neither the counting nor the figures shown.
What the checks do not catch belongs in the same paragraph: a sentence that says something false without using digits, and a sentence about a different subject than its fact. Both are described where they belong, namely in the blog. A check you believe to be watertight is worse than one whose gaps are named.
6. Where no artificial intelligence is involved
With a visitor counter that is the more common question, so the answer stands here rather than in the small print:
- The counting itself — a database query and one more row. No model.
- Detection of automated access ("bots") — the user agent compared against a list of strings. No learning procedure, no estimate, no assessment of a person.
- Determining origin from the IP address — a table of address ranges. Looked up, not guessed.
- Counter images, charts, weekly letters, monthly reports — generated by code from figures.
- Excluding your own visits, recovering a counter, deleting one — fixed rules, readable and repeatable.
There is nowhere any automated decision-making about a person within the meaning of Art. 22 GDPR, and no profiling. The same is stated in section 11 of the privacy policy.
7. Third-party services on these pages
Advertising from Google runs on the statistics pages, and the enquiry form is protected against automated submissions by Google reCAPTCHA. Whether procedures covered by the AI Act are used there is determined by Google and not by the operator; a provider's obligations fall on that provider.
For those services the operator is at most a deployer within the meaning of Art. 3(4) and not a provider. He generates no content with them and makes no decision about a person with them. Which services are embedded, and for what, is set out in sections 5 and 6 of the privacy policy.
8. What role Stats4U has under the AI Act
The Regulation distinguishes the provider (Art. 3(3)) — whoever develops an AI system or has one developed and places it on the market or puts it into service under their own name or trademark, whether for payment or free of charge — from the deployer (Art. 3(4)), who uses an AI system under their own authority.
In the operator's assessment he is both here. Around a third-party model stands a system of his own: selection of the figures, one job per fact, checking of the answer, display. He puts that system into service under his own name on his own site — that is the provider role — and he uses it under his own authority — that is the deployer role. That it is handed to nobody changes nothing: putting into service for one's own use is included.
The operator is expressly not the provider of the model. The weights come from third parties, they are used unchanged, and no model is placed on the market.
This classification is the operator's assessment and not a finding by any authority. It stands here because a page about one's own use of AI that leaves out the question of role avoids the question that matters. Anyone who thinks it wrong will find under 15. where to turn.
9. Risk class
Prohibited practices (Art. 5): none. There is no subliminal manipulation, no exploitation of vulnerability, no social scoring, no biometric identification, no emotion recognition and no inference of protected characteristics.
High-risk (Art. 6 read with Annex III): no. None of the categories listed there is touched — no biometrics, no critical infrastructure, no education or vocational training, no employment, no access to essential private or public services, no law enforcement, no migration, no administration of justice. A sentence about visitor numbers decides nothing about anybody and has legal effect for nobody.
What remains is a system that generates synthetic text and therefore falls under the transparency obligations of Art. 50. Those are the subject of 10. and 11.
10. Article 50 in detail
The article has several paragraphs with different addressees. In order, so that the outcome can be followed:
- Paragraph 1 — systems that interact directly with people must make themselves known as AI. Not applicable: there is no conversation and no input here. The text stands finished on a page before anyone opens it.
- Paragraph 2 — providers of systems that generate synthetic content must mark the output in a machine-readable format. Applicable, and the marking is still outstanding here. See 11.
- Paragraph 3 — emotion recognition and biometric categorisation. Not applicable.
- Paragraph 4, first subparagraph — deep fakes. Not applicable: no images, audio or video are generated, only two sentences of text.
- Paragraph 4, second subparagraph — generated text published in order to inform the public on matters of public interest must be disclosed as such. Doubtful whether applicable — matters of public interest plainly means the formation of public opinion and not every published line. It is disclosed regardless.
- Paragraph 5 — clearly and distinguishably, at the latest at the time of first exposure. Met: the note stands directly beneath the text, in the language of the page, with nothing to unfold and no link to follow.
The second subparagraph of paragraph 4 deserves one more sentence. It exempts text that has undergone human review or editorial control and for which somebody holds editorial responsibility. The operator does not rely on that: the sentences are not read by a human before they appear — they are checked by machine. That is a different thing, and it would be convenient to pass one off as the other.
A disclosure made only when it is compulsory says nothing about the text. This one has stood beneath every box since the first generated sentence.
11. Outstanding: the machine-readable marking
Art. 50(2) requires more of a provider than a visible sentence. The output is to be marked in a machine-readable format and detectable as artificially generated, with solutions that are effective, interoperable, robust and reliable as far as this is technically feasible.
The visible note beneath the box is not that. It addresses the reader, not a machine. There is currently no machine-readable marking of the generated sentences on these pages.
This stands here because a page about one's own use of AI that lists only the obligations already met misses its purpose. Anyone wanting to know where they stand learns more from what is missing than from what is there.
What it turns on: for two sentences of running text on an HTML page there is no established procedure that meets the four properties named. Watermarking was developed for images and audio; in two sentences there is little to hide anything in that would survive a translation, a quotation or a copy-and-paste. The Regulation reckons with this itself: Art. 50(7) provides for codes of practice at Union level, and the European Commission published guidelines on Art. 50 on 20 July 2026.
What is already there: the visible note beneath every box, the name of the model, the date of the sentence, and this page. What is missing is thereby named rather than asserted away.
12. AI literacy (Art. 4)
Art. 4 requires providers and deployers to ensure a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of the systems on their behalf. The duty has applied since 2 February 2025 and applies irrespective of risk class.
Stats4U is a sole trader with no employees. The only person who deals with the system built it; the three checks under 5. arose from measured failures of the model and not from any training course. The duty therefore largely runs empty — not because it does not apply, but because there is nobody for it to reach.
Art. 4 carries no fine; the penalties in Art. 99 do not name it.
13. General-purpose AI models
The obligations in Art. 53 et seq. — technical documentation, information for downstream providers, a copyright compliance policy, a sufficiently detailed summary of the training content — fall on the provider of the model, that is, whoever places the weights on the market. They have applied since 2 August 2025.
Stats4U is not that. It downloads finished weights, does not change them, and passes no model on.
Whether and how a model provider meets those obligations is something the operator cannot verify. That is a known limit and not a claim to the contrary.
14. Dates
The AI Act entered into force on 1 August 2024 and applies in stages:
- since 2 February 2025: prohibited practices (Art. 5) and AI literacy (Art. 4),
- since 2 August 2025: the obligations for general-purpose AI models, the governance structure and the penalties,
- since 2 August 2026: general applicability, and with it the transparency obligations of Art. 50,
- for high-risk systems under Annex III the date was moved to 2 December 2027 by Regulation (EU) 2026/1744 (the "Digital Omnibus", in the Official Journal on 24 July 2026), and for high-risk systems in regulated products to 2 August 2028. Neither matters for Stats4U, see 9.
That amendment did not postpone the transparency obligations of Art. 50. For the machine-readable marking under paragraph 2, the amending act sets 2 December 2026 for systems already on the market on 2 August 2026; whether the present case falls under that has not been conclusively examined by the operator. Section 11 stands regardless.
These dates were looked up, not remembered. They last changed in July 2026 and may change again. Anyone relying on them should check the Official Journal of the European Union.
15. Supervision
The national market surveillance authority under Art. 70(1) of the Regulation is, in Poland, the Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (Commission for the Development and Safety of Artificial Intelligence). It was established by the Polish Act on artificial intelligence systems (Dz.U. 2026 item 1003, in force since 11 August 2026).
Anyone who believes that the use described here breaches the AI Act may turn to it. They may also write to stats4u@lukaswojcik.com; that is faster and changes nothing about the right.
A different authority is responsible for data protection complaints — it is named in section 10 of the privacy policy.
16. Further documents
These apply and explain in addition:
- the privacy policy — section 5.10 on what is put before the model, and section 11 on the absence of automated decision-making,
- the page on the Data Act — access to your own data, export and switching,
- the terms of service and the data processing agreement,
- the imprint.
How the sentences come about, what went wrong along the way and where the checks fail is set out at length, with measurements, in the blog.
Version
Version 1.0, as of 1 September 2026. This page is information about actual practice and not legal advice; it states the operator's own assessment and has not been reviewed by any authority or lawyer.