mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-05 02:41:56 +00:00
fix: correct Article 26 citation and add Article 50 section
Address Greptile review: - P1: Article 26(6) → Article 26(5) for deployer log retention - P1: Add dedicated Article 50 section for user-facing transparency (was referenced in scope section but had no corresponding section)
This commit is contained in:
parent
9de47978b4
commit
980b60cda1
1 changed files with 25 additions and 1 deletions
|
|
@ -151,7 +151,7 @@ class ComplianceLogger(CustomLogger):
|
|||
litellm.callbacks = [ComplianceLogger()]
|
||||
```
|
||||
|
||||
Whichever option you choose, connect to a persistent backend with a retention policy of at least 6 months (Article 26(6) for deployers; Article 18 requires 10 years for providers).
|
||||
Whichever option you choose, connect to a persistent backend with a retention policy of at least 6 months (Article 26(5) for deployers; Article 18 requires 10 years for providers).
|
||||
|
||||
## Article 13: Transparency
|
||||
|
||||
|
|
@ -184,6 +184,30 @@ What you need to build for Article 14 compliance:
|
|||
|
||||
LiteLLM provides the **logging and hook infrastructure** to build human oversight on top of. The oversight logic itself — review queues, approval workflows, kill switches — lives in your application layer.
|
||||
|
||||
## Article 50: Transparency for AI-interacting systems
|
||||
|
||||
Article 50 applies to **all AI systems that interact directly with users**, not just high-risk systems. If your LiteLLM deployment powers a chatbot, virtual assistant, or any interface where a user communicates with AI-generated responses, you must:
|
||||
|
||||
1. **Inform users they are interacting with an AI system** — before or at the start of the interaction
|
||||
2. **Mark AI-generated content** — if the system generates text, audio, images, or video that could be mistaken for human-created content, it must be machine-readable as AI-generated (Article 50(2))
|
||||
3. **Disclose deepfakes** — if the system generates or manipulates content depicting real people or events, this must be disclosed (Article 50(4))
|
||||
|
||||
LiteLLM itself does not handle user-facing disclosure — it operates at the API gateway layer. Your application must implement the disclosure:
|
||||
|
||||
```python
|
||||
# Example: Add AI disclosure header to responses
|
||||
response = litellm.completion(model="gpt-4", messages=messages)
|
||||
|
||||
# Your application layer adds the disclosure
|
||||
user_response = {
|
||||
"content": response.choices[0].message.content,
|
||||
"ai_disclosure": "This response was generated by an AI system.",
|
||||
"model_used": response.model, # Transparency: which model answered
|
||||
}
|
||||
```
|
||||
|
||||
Article 50 obligations exist **independently of Annex III classification**. Even if your system is not high-risk, this section applies.
|
||||
|
||||
## GDPR considerations
|
||||
|
||||
LiteLLM processes user prompts. If those prompts contain personal data:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue