Artificial Intelligence and Machine Learning Statement
Last updated: June 2026
At Lokalise, artificial intelligence (AI) is central to how we help teams break language barriers and scale their localization operations globally. Our AI-enabled features are built directly into the Lokalise platform, ensuring localization workflows are faster, smarter, and more consistent, without compromising the security or privacy of customer content.
This Statement outlines our commitment to the responsible use of AI, including how customer content may be used in AI processes, and how we approach transparency, data security, and ethical AI governance. It is also intended to support Lokalise's compliance with the obligations of the EU Artificial Intelligence Act (AI Act), Regulation (EU) 2024/1689, which becomes fully applicable on 2 August 2026. These obligations include, in particular, the transparency requirements under Article 50 (disclosure of AI interaction to users), the AI literacy requirements under Article 4, and the information obligations applicable to providers of AI systems under Article 13. This Statement further supports compliance with the GDPR, Regulation (EU) 2016/679, and other applicable regulations.
We recognise that trust is the foundation of our relationship with customers. This Statement keeps customers fully informed about how their content is handled across all AI-enabled features on the Lokalise platform.
1. Definitions
AI Act - Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence.
AI System - A machine-based system designed to operate with varying levels of autonomy, which infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions.
Customer Content - Any content that a Lokalise customer or its users upload to, create within, or translate (including resulting translated content) using the Lokalise platform.
Custom AI Profile - A customer-configured translation profile that uses Retrieval-Augmented Generation (RAG) to retrieve relevant examples from the customer's own translation memory and prior translated content at inference time. Retrieved context is injected into the prompt to personalise AI output for that customer's style, terminology, and domain. The underlying LLM is not fine-tuned or modified. Retrieved context is always scoped to the customer whose profile is active and is never shared across customers.
GDPR - Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.
LLM - Large Language Model.
MT - Machine Translation.
AI Routing Service - Lokalise's internal AI routing service that manages LLM provider selection, fallback logic, multi-tenancy isolation, and request handling for most AI-powered features.
RAG - Retrieval-Augmented Generation: a technique that retrieves relevant context from a customer's own data at inference time to improve AI output quality, without training or fine-tuning the underlying model.
TM - Translation Memory.
2. AI System Classification
The Lokalise platform represents an AI system within the meaning of the AI Act. Lokalise, as its provider, is responsible for ensuring compliance with the AI Act and other applicable regulations.
No prohibited practices
None of Lokalise's AI features engage in practices prohibited under the AI Act, including manipulating users, performing social scoring, or exploiting user vulnerabilities.
Not classified as high-risk
Lokalise does not use AI for activities such as critical infrastructure management, biometric identification, or employment-related decisions that would require special oversight under the AI Act.
Aligned with EU AI Act ahead of enforcement
Lokalise has implemented the measures required to meet its transparency, literacy, and governance obligations under the EU AI Act ahead of the Act's full application date of 2 August 2026. This includes fulfilment of AI literacy obligations under Article 4, transparency disclosure obligations under Article 50, and information obligations under Article 13.
3. AI-Enabled Solutions at Lokalise
Customer-facing AI features are not applied automatically. They are only used when a customer or authorized user actively initiates the relevant AI functionality, such as creating an AI translation task or triggering AI suggestions.
How AI requests are routed
Lokalise routes AI requests through a small set of carefully vetted providers, all of which are bound by strict contractual data protection obligations.
For the full and up-to-date list of AI sub-processors, including their location and role, see our AI Sub-processor List.
All data exchanged with AI providers is encrypted in transit using a minimum of TLS 1.2.
Where requests are routed through AWS Bedrock, they remain within the AWS network and do not traverse the public internet.
| Feature | Summary | Trained with Customer Content? |
|---|---|---|
| AI Suggestions | Context-aware translation suggestions in the editor, enriched with TM, glossary, style guide, and screenshots. When delivered via a Custom AI Profile, customer TM data is used as RAG context. | NO |
| AI Translations (Bulk) | One-click automated translation of all localization keys in a project. | NO |
| AI Tasks & Workflow Automations | Automated translation task creation, execution, and smart workflow routing. | NO |
| Language Quality Assessment (LQA / AI Scoring) | Automated quality scoring of translated content to identify segments requiring human review. | YES (with consent) |
| Custom AI Profiles | Personalized AI translation using Retrieval-Augmented Generation (RAG) on the customer's own TM and existing translations. | YES - as RAG context at inference time only; not used for model training |
| AI Assistant | In-app conversational AI agent with streaming and tool use. | NO |
| Style Guide Generation | Generates style guides from uploaded documents using LLM. | NO |
| AI Profile Evaluation | AI-assisted evaluation of custom AI profile performance. | NO |
AI Disclosure
In accordance with Article 50(1) of the EU AI Act, Lokalise ensures that users interacting with AI-powered features that involve direct human-AI interaction are clearly informed that they are engaging with an AI system. This disclosure is provided at the point of interaction within the Lokalise platform interface.
Key feature details
AI Suggestions, AI Translations and AI Tasks
Customer Content (source string, TM matches, glossary, style guide) is passed to the LLM at inference time only to generate a translation. Customer Content is never used to train or fine-tune the underlying LLM. All data in transit is encrypted with TLS. Customers agreements with OpenAI and Anthropic prohibit use of Customer Content for training purposes.
Custom AI Profiles
Custom AI Profiles use Retrieval-Augmented Generation (RAG). Lokalise retrieves the most relevant examples from the customer's own TM and existing project translations and passes them as context to the LLM alongside the source string. This improves output quality without modifying or fine-tuning any AI model. Each customer's data is fully isolated and never shared with other customers. Available on Advanced and Enterprise plans.
Language Quality Assessment (LQA / AI Scoring)
AI Scoring applies a trained internal model to evaluate translated content and output a continuous quality score. This score can be used to configure workflow routing - for example, automatically flagging low-scoring segments for human review before publication. The model is trained on prior translation quality assessments, subject to customer consent. The model outputs a numerical score only - no Customer Content is retrievable from the model. Training data is subject to regular deletion in line with GDPR and our Privacy Notice.
AI Assistant and Style Guide Generation
These features route directly to OpenAI (GPT models). Customer Content is passed to OpenAI at inference time only. Enterprise-level agreements ensure Customer Content is not stored or used for training by OpenAI.
AI Profile Evaluation
Requests are processed through Lokalise's internal routing service that manages LLM provider selection and inference.
4. Data Governance and Consent
4.1 Consent Model
Customer Content may be used to improve Lokalise's services unless the customer opts out via the AI Addendum. Customers have the right to opt out at any time.
Customer Content is never shared with third-party LLM providers for their own training purposes.
Lokalise operates two independent consent categories:
- Consent to train Lokalise internal AI models. Allows Lokalise to use Customer Content (input/output) to train proprietary models such as AI Scoring. Governed by the AI Addendum (Annex C, Section 3). Customers can withdraw this consent at any time, which may limit access to certain AI features.
- Consent to use data for Custom AI Profile features. Applies only where the customer uses Custom AI Profile features. Can be withdrawn at any time, in which case Custom AI Profile features will be disabled.
4.2 What Lokalise Does and Does Not Do with Translation Data
What we do
- Retain translation data as part of delivering the service (translation memory, editor, version history).
- Use aggregate, metadata-level signals to improve platform reliability and quality.
- Use Customer Content to train internal quality models (AI Scoring, LQA) where customer consent is given.
What we do not do
- Share Customer Content with third-party LLM providers for model training - contractually prohibited in all provider agreements.
- Mix content from different customers in the same LLM prompt.
- Mix content from different customers in the same LLM prompt or RAG retrieval context.
- Allow LLM providers to correlate requests back to specific Lokalise customers (no tenant identity is passed to providers).
4.3 Provider Data Retention
A complete and up-to-date list of Lokalise's AI subprocessors, including the services used, data processed, retention periods, processing regions, and whether each provider trains on customer data, is maintained at https://lokalise.com/ai-subprocessor-list.
4.4 Information to Deployers (Article 13 EU AI Act)
Where Lokalise's customers act as deployers of Lokalise's AI system within the meaning of the EU AI Act, Lokalise provides sufficient information to enable those deployers to understand the AI system's capabilities, limitations, and data handling practices, and to fulfil their own obligations under applicable law. This information is made available through:
- This AI and ML Statement;
- The AI Addendum (Annex C to MSA);
- The AI Sub-processor List;
- Lokalise's Data Processing Addendum.
Customers with questions about deployer obligations under the EU AI Act are encouraged to contact privacy@lokalise.com.
5. Data Security and Infrastructure
Encryption in transit
All data exchanged between customers and the Lokalise platform, and between Lokalise and AI/MT providers, is encrypted using TLS (minimum TLS 1.2).
Traffic to AWS Bedrock does not traverse the public internet - it uses AWS internal transport within the same region.
Encryption at rest
All platform databases and object storage are encrypted at rest using AES-256 via AWS KMS. Application secrets and API keys are managed via HashiCorp Vault.
Multi-tenant isolation
Every AI request carries a system-generated tenant ID and owner ID. All database queries are scoped by tenant ID - no cross-tenant data access is possible at the application layer. Content from different customers is never pooled into the same LLM prompt. Provider requests do not carry tenant identity, so providers cannot correlate requests to specific Lokalise customers.
Access controls
AI-translated content is only accessible to authorised personnel within the customer's Lokalise account. Strict authentication mechanisms prevent unauthorised access.
Lokalise holds ISO 27001 and SOC 2 Type II certifications, which apply to all infrastructure supporting AI-powered features.
6. General Principles of AI Governance
6.1 Ethical Considerations and Privacy
Lokalise is guided by principles of fairness, transparency, and respect for individual rights in all AI development and deployment. Our AI features are designed to support human translators and localization teams.
6.2 Human Oversight and Control
- Translation review: AI Scoring identifies which translations require human review. Teams are never required to publish AI output without the opportunity to review it.
- Opt-out controls: Customers can opt out of AI training data use at any time via the AI Addendum.
- Feedback mechanisms: Users and employees can flag issues with AI outputs for structured review by Lokalise's product and engineering teams.
- Legal oversight: Lokalise's Legal and Compliance teams oversee AI governance to ensure ongoing regulatory compliance.
6.3 AI Literacy
In accordance with the EU AI Act, Lokalise ensures that all personnel involved in developing, deploying, and supervising AI systems have an adequate understanding of AI concepts, risks, and best practices. Lokalise will update its training materials, policies, and documentation as the regulatory landscape evolves.
6.4 Regulatory Compliance
| Framework | Status |
|---|---|
| EU AI Act (Regulation 2024/1689) | Compliance measures in place. No Lokalise AI features fall within prohibited or high-risk categories. AI literacy obligations (Article 4) fulfilled from February 2025. Transparency obligations (Article 50), information obligations (Article 13), and general provider obligations are implemented ahead of full application on 2 August 2026. |
| GDPR (Regulation 2016/679) | All AI-related data processing conducted under appropriate legal bases. Individual data subject rights supported. Customers may exercise objection rights at any time. |
| ISO 27001 / SOC 2 Type II | Certified. Applies to all infrastructure supporting AI-powered features. |
| CCPA / CPRA | Opt-out rights for AI training honoured within required timeframes. Privacy risk assessments in progress per California regulations effective January 2026. |
7. Conclusion
We reserve the right to revise this Statement as our AI capabilities evolve and as the EU AI Act and other applicable regulations come into effect. We are committed to updating this Statement to remain a current and accurate reflection of our AI practices.
If you have questions or requests regarding this Statement, or wish to exercise any rights relating to the use of your data in AI systems, please contact us at privacy@lokalise.com.
Case studies

Behind the scenes of localization with one of Europe’s leading digital health providers
Read more Case studiesSupport
Company
Localization workflow for your web and mobile apps, games and digital content.
©2017-2026
All Rights Reserved.