THREATROOM

AI Transparency Notice

Information on the use of artificial intelligence pursuant to Art. 50 of Regulation (EU) 2024/1689 (the “EU AI Act”)

This English translation is provided for convenience only. The German version is the authoritative and legally binding version.

1. What ThreatRoom uses AI for

ThreatRoom is a training platform for cyber crisis simulations. The exercise content is generated during a session using generative AI models. In particular, the following is AI-generated:

  • Scenario texts: fictitious companies, events, tasks, situation reports and press headlines,
  • Images: fictitious screenshots, documents and newspaper front pages,
  • Voice output: synthetic voices of fictitious callers (e.g. journalists, authority representatives, customers) in simulated phone calls,
  • Evaluations: the automated scoring of free-text answers (solely for awarding points in the game) as well as debrief and report drafts.

All of this content is entirely fictitious and serves training and exercise purposes only. Persons you appear to interact with in the game (such as callers) are not real people but AI-generated game characters.

2. Labelling of AI-generated content

AI-generated content is labelled as such on several levels:

  • Visible: a notice before the exercise starts (briefing), “AI-generated” / “AI voice” labels on images and audio content, a notice in the call overlay, and disclaimers on all exported PDF documents.
  • Machine-readable: generated images (PNG) and audio files (MP3) carry embedded metadata with the IPTC provenance value digitalsourcetype/trainedAlgorithmicMedia; API delivery additionally sets the HTTP header X-AI-Generated: true.

Simulated media content (e.g. fake press articles or calls) is part of a recognisably fictitious training scenario. It is intended exclusively for use within the exercise and must not be redistributed as genuine content.

3. Models and service providers used

Generation takes place via the AI gateway provider Requesty (EU endpoint), which routes requests to language, image and audio models of third-party providers (e.g. Anthropic, Google, OpenAI). Details on data processing can be found in our privacy policy (section “AI-generated scenarios”).

4. No decisions with legal effect

The automated evaluation of game answers serves solely to award points in the game. It has no legal or similarly significant effect on participants; exercise reports are the responsibility of the respective exercise lead. ThreatRoom does not use emotion recognition or biometric categorisation.

5. Limitations of AI-generated content

Despite careful design, AI-generated content may contain technical inaccuracies. It does not constitute legal, security or other professional advice (see also Terms of Service, § 7 Simulation character).

6. Contact

Please direct questions about the use of AI to the contact details given in the legal notice.

Version: August 2026