Trust
AI you can put in front of a regulator.
Agents and models that make decisions inside a regulated business need governance, not enthusiasm. Here is ours.
Your data is not an input to anyone else's model.
We do not send client data to third parties for training, we do not retain it for our own model development, and that is written into the contract rather than promised in a sales call. Where a model provider's default terms would allow training on submitted data, we configure the enterprise agreement that does not.
What we operate.
Model inventoryEvery model in every system we run is listed with its purpose, its provider, its version, and the decisions it touches. An AI system nobody has inventoried cannot be governed.
Human reviewConsequential decisions carry a human in the loop by design. A model may rank, draft, flag or route; a person approves anything that affects a customer's money, care or eligibility.
Evaluation before releaseAn evaluation set agreed with you before build, with a stated success threshold. You keep the evaluation set.
Logging and reversibilityModel inputs, outputs and the human decision are logged so an action can be explained after the fact and reversed.
Management systemISO/IEC 42001 operated as the AI management system, with NIST AI RMF applied to every model deployment.
What we will not build.
Fully automated consequential decisionsWe will not ship a system that denies a claim, a loan or a course of care without a person able to review and overturn it.
Undisclosed AI in a human channelAn agent that speaks to your customers identifies itself as one. We will not build a system whose job is to be mistaken for a person.
Inference on protected characteristicsWe will not build models that infer protected characteristics as a feature, and we test for proxies that do it accidentally.