Legal & Compliance

Responsible AI Policy

Governance principles for AI development and deployment.

Effective and last updated: July 13, 2026

This public policy is a baseline. A signed order form, enterprise agreement, or data-processing agreement may contain additional terms and prevails to the extent of a conflict.

Principles

  • Lawfulness, fairness, privacy, security, safety, accessibility, and respect for intellectual-property and human rights.
  • Meaningful human accountability for consequential decisions; AI output is evidence to assess, not authority to obey.
  • Risk-proportionate testing, documentation, monitoring, traceability, incident management, and change control.
  • Clear communication of material capabilities, limitations, intended uses, and known failure modes without presenting experimental results as guarantees.

High-impact use

Customers must not use HEOSSI systems as the sole decision-maker where a decision produces legal or similarly significant effects on a person. High-impact deployments require qualified human review, documented authority, validation for the use context, avenues for contest and correction where required, and compliance with sector-specific law.

Data and model governance

Teams must assess provenance, licence, relevance, representativeness, privacy, security, and bias risks for data and models. Access is limited by role. Evaluation results, material changes, overrides, and incidents should be recorded in proportion to risk. Customer data is not used to train general models unless expressly agreed.

Limitations and reporting

AI systems can produce inaccurate, incomplete, biased, insecure, or outdated results. Users must independently verify outputs before relying on them in safety-critical, financial, legal, medical, employment, security, or operational contexts. Suspected harmful behaviour or policy violations may be reported to security@heossi.com.