AI Policy
Responsible AI Policy
Last updated: 8 July 2026
This AI Policy explains how Nentis AI uses, designs, builds, and deploys artificial intelligence in a responsible, secure, and business-focused way. We work mainly in a European context and design our services with data protection, cybersecurity, responsible AI, and European regulatory expectations — including the EU AI Act — in mind.
We believe AI only matters when it creates real business value. Our goal is not to add AI for its own sake, but to build systems that save time, reduce manual work, improve quality, and support better decisions. This policy should be read together with our Privacy Policy, Cookie Policy, Terms & Conditions, and any project-specific agreement signed with a client.
1. Legal status of this policy
This AI Policy explains our general approach to responsible AI. It does not replace our Privacy Policy, Terms & Conditions, a Data Processing Agreement, a Statement of Work, or any project-specific agreement. Where there is a conflict with a signed client agreement, the signed agreement prevails for that project.
This policy does not guarantee that every AI system, use case, or deployment is automatically compliant with all applicable laws — compliance depends on the specific use case, data, sector, and configuration. It is not legal advice; clients remain responsible for obtaining their own legal advice for regulated, sensitive, or high-impact AI use cases.
2. Our approach to AI
We do not treat AI as a standalone product. We treat it as one possible tool inside a broader business system. Before recommending or building an AI solution, we aim to understand how the business works, where the workflow is slow or error-prone, what data is involved, what value could be created, and whether AI is actually the right solution.
Where a simpler automation, integration, or non-AI solution is more appropriate, we may recommend that instead. Our delivery approach rests on four principles: understand the business before building; design around real workflows; apply data protection and security from the start; and keep humans in control where AI supports important decisions.
3. Scope
This policy applies to AI systems we use internally, AI systems we design, build, configure, or deploy for clients, and AI-assisted work performed during discovery, implementation, and support. It covers AI agents, assistants, chatbots, document-processing systems, workflow automations, and reporting systems, as well as AI-generated content produced through our systems.
It does not replace a client's own legal, regulatory, sector-specific, or professional obligations.
4. Responsible AI principles
We apply the following principles when using or building AI systems:
- Clear business purpose — every AI system should have a defined purpose, users, data needs, limits, and required level of human oversight.
- Human oversight — AI should support people, not blindly replace them, especially where outputs affect customers, employees, finances, legal obligations, or important decisions.
- Privacy and data protection — we apply purpose limitation, data minimisation, security, accuracy, and accountability where personal data is processed.
- Security — we treat access to sensitive tools and data seriously, using limited access, secure credentials, and appropriate separation of environments.
- Transparency — people should know when they are interacting with AI where this is legally required or reasonably expected.
- Accuracy and reliability — AI outputs are reviewed before use where they may affect rights, finances, safety, or important decisions.
- Fairness — AI systems should not be designed or used to unlawfully discriminate.
- Accountability — each AI system needs clear ownership of the process, access, review, maintenance, and failure handling.
5. Human oversight
AI should support people, not replace their judgement. Depending on the use case, human oversight may include human approval before an output is sent or acted on, escalation to a human when the AI is uncertain, manual review of sensitive cases, limits on what the system can do, and periodic quality checks.
Unless expressly agreed, legally reviewed, and properly safeguarded, our systems are not intended to make fully automated decisions that produce legal effects or similarly significant effects on individuals.
6. EU AI Act and transparency
The EU AI Act introduces obligations that apply progressively. In particular, transparency obligations under Article 50 — including informing people when they interact with an AI system and labelling AI-generated or manipulated content where required — apply from 2 August 2026.
For AI systems that interact directly with customers, employees, or the public, we help clients design clear transparency notices (such as interface labels, disclaimers, or chatbot messages). Our legal role may vary depending on the project — we may act as a provider, deployer, or another role defined by applicable law — and this is confirmed in the applicable project documentation.
7. AI risk screening
Before implementing an AI system for a client, we perform a preliminary risk screening based on the intended purpose, users, affected persons, data involved, autonomy level, sector, and possible impact on rights, safety, or access to services.
If a use case may fall within a prohibited, high-risk, regulated, or sensitive category, we may require additional legal review, documentation, testing, human oversight, technical safeguards, or client approvals before proceeding. We may refuse, pause, limit, or redesign a project where risks are not adequately addressed.
8. Prohibited and restricted uses
We do not knowingly design, deploy, or support AI systems for unlawful, deceptive, harmful, or abusive purposes. In particular, we will not knowingly support AI intended to:
- manipulate people or exploit vulnerabilities in unlawful or harmful ways;
- perform unlawful discrimination or unlawful surveillance;
- generate fraud, spam, phishing, or deceptive communications;
- create or distribute illegal content, or non-consensual intimate or synthetic content;
- create deepfakes intended to deceive, defame, harass, or harm;
- make high-impact decisions about people without appropriate human oversight and legal review.
We reserve the right to refuse, suspend, or terminate work that may create unacceptable legal, ethical, security, or reputational risk.
9. High-risk and sensitive use cases
Projects involving recruitment, worker monitoring, education, creditworthiness, insurance eligibility, healthcare, biometric identification, law enforcement, or similarly sensitive decisions require additional assessment before we accept or implement them. Where appropriate, this may include legal review, a Data Protection Impact Assessment, human-oversight design, technical documentation, logging, bias testing, and additional contractual safeguards.
10. Client data and model training
Unless expressly agreed in writing, we do not use client confidential information or client personal data to train public AI models. Where third-party AI tools are used, their treatment of input and output data depends on their own terms and configuration; we aim to choose tools and settings appropriate to the sensitivity of the data.
Where personal data is processed on behalf of a client, this is governed by a Data Processing Agreement, and we do not use client personal data for purposes outside the agreed project unless authorised or legally required.
11. Third-party AI providers
Our systems may use third-party AI infrastructure and platforms (for example model providers, cloud providers, and automation platforms). Each provider is subject to its own data-processing and usage terms, which we evaluate before integration. Where such providers process personal data on behalf of a client, they may act as subprocessors, identified in the applicable agreement or subprocessor list.
12. No guarantee of perfect output
AI systems are probabilistic and may produce incorrect, incomplete, outdated, or biased outputs. We reduce risk through design, testing, documentation, and human oversight, but we do not guarantee that AI outputs will always be accurate, complete, lawful, or suitable for every purpose. Clients and users should review AI outputs before relying on them in important contexts.
13. How we use AI internally
We may use AI internally to support research, drafting, code assistance, workflow design, documentation, and productivity. Internal AI use remains subject to confidentiality, data protection, and security rules. We do not submit client confidential information, credentials, or personal data to public AI tools unless this is authorised for the project and appropriate safeguards are in place.
14. Client responsibilities
Clients are responsible for using AI systems lawfully and appropriately in their own environment. This includes defining the intended use accurately, confirming they have the right to provide or connect the relevant data, informing employees or customers where required, maintaining appropriate human oversight, reviewing outputs where necessary, and telling us if the use case, data, or risk profile changes after deployment.
15. Changes to this policy
AI technology and regulation evolve quickly. We may update this AI Policy from time to time to reflect changes in our services, tools, legal obligations, or practices. The updated version will be published on this page with a new “Last updated” date.
16. Contact
For questions about this AI Policy or our use of AI, contact us at contact@nentisai.com.
Questions about this document? Contact us at contact@nentisai.com