AIW builds systems that reason and act. This policy states what those systems are, what they are not, what we will not build, and the conditions under which what we build may be used.
1. Scope
This policy applies to every system, agent, workflow, assistant, portal, and automation AIW designs, builds, or operates, and to the use of the AI capabilities on this website. It forms part of every Engagement.
2. What AIW Systems Are
AIW systems combine third-party foundation models, retrieval over client documents and data, deterministic business logic, integrations with client systems, and guardrails. They ingest, reason, act through tools, and verify.
They are probabilistic. Identical inputs may produce different output. Output can be plausible and wrong.
They are not authoritative. AIW systems do not provide legal, medical, tax, financial, investment, engineering-certification, or employment-law advice, and must not be positioned as doing so.
They are not autonomous in consequence. Where a system is permitted to act — send, commit, pay, schedule, publish, hire, reject, price — the permission boundary is designed, documented, and approved in writing before deployment.
3. Transparency Commitments
3.1 Disclosure of AI interaction. Any AIW system that communicates directly with a natural person is designed to make clear that the person is interacting with an AI system, unless that is obvious from the context. The client, as deployer, keeps that disclosure in place.
3.2 Synthetic content. AI-generated or AI-manipulated text, image, audio, and video produced by an AIW system is marked as such where the deployment context requires it, including machine-readable marking where technically feasible.
3.3 Emotion recognition and biometric categorisation. AIW does not build these into workplace or education deployments. Where any such component is contemplated in a permitted context, affected persons must be informed by the deployer.
3.4 Documentation. Each Deliverable is accompanied by documentation of purpose, data sources, model dependencies, guardrails, known limitations, oversight points, and logging. This is the record the client needs for its own compliance obligations.
4. Human Oversight
4.1 Consequential decisions require a human decision-maker. A consequential decision is one that materially affects a person's legal position, employment, credit, education, access to services, health, or safety, or that commits the client financially or contractually beyond an agreed threshold.
4.2 For those decisions, AIW builds review checkpoints, confidence signals, and reversible actions by default. Removing a checkpoint is a change request under the General Terms of Engagement, made in writing, with the client accepting responsibility for the altered risk profile.
4.3 The client designates who holds oversight of each deployed system, ensures they understand its limitations, and gives them the practical authority and the means to override, pause, or shut it down.
5. Regulatory Positioning
5.1 The EU AI Act allocates duties by role. In the ordinary AIW engagement, the client is the provider of the system it puts into service under its own name and the deployer in its own operations; AIW acts as a contracted developer. The statement of work records the allocation where it differs.
5.2 Prohibited practices. AIW will not build systems for social scoring, exploitative manipulation of vulnerable persons, untargeted scraping of facial images to build recognition databases, real-time remote biometric identification in publicly accessible spaces, predictive policing directed at individuals, or emotion inference in workplaces and schools.
5.3 High-risk use cases. Where an intended use appears to fall within a high-risk category — employment and worker management, access to education, creditworthiness, essential public or private services, critical infrastructure, law enforcement, migration — AIW will say so, and will proceed only where the client accepts and resources the conformity, documentation, logging, oversight, and registration obligations that attach to it.
5.4 General-purpose model obligations sit with the model providers. AIW selects providers that publish the required documentation and passes it through to the client.
5.5 Nothing in this policy is a legal opinion on the classification of a particular system. Classification is decided with the client and, where the stakes warrant it, with the client's counsel.
6. Acceptable Use
AIW systems, and access granted by AIW, may not be used to:
- Harm people — facilitate violence, weapons, self-harm, stalking, harassment, threats, or child sexual abuse material of any kind
- Deceive — generate impersonations of real people, fraudulent identities, non-consensual intimate imagery, disinformation, fake reviews, or election manipulation
- Discriminate — make or support decisions that discriminate on the basis of race, ethnicity, religion, sex, gender identity, sexual orientation, disability, age, or any other protected characteristic
- Breach privacy — conduct covert surveillance of employees or individuals, re-identify anonymised data, or process personal data without a lawful basis
- Break the law — infringe intellectual property, evade sanctions, launder money, or commit any criminal or regulatory offence
- Attack systems — develop malware, conduct unauthorised access, or exploit vulnerabilities outside an authorised engagement
- Practise unlicensed — deliver legal, medical, or financial advice to third parties as if from a qualified professional
- Evade controls — remove disclosures, disable guardrails, bypass rate limits or oversight checkpoints, or extract system prompts, model weights, or credentials
- Train competitors — use AIW-built systems, prompts, or outputs to train a model or build a product competing with AIW Framework IP
7. Client Responsibilities
7.1 Maintain lawful basis, notices, and any consent required for the data the system processes.
7.2 Keep the system within its documented scope; re-purposing requires a fresh assessment.
7.3 Monitor Output quality, report material failures, and retain logs as designed.
7.4 Train the people who use the system and inform those affected by it.
7.5 Consult works councils, regulators, and professional bodies where required by its own sector.
8. Enforcement
8.1 AIW may suspend or terminate access, or terminate the Engagement, where use breaches this policy, immediately where a breach involves a prohibited practice or an imminent risk of harm.
8.2 AIW reports what it is legally required to report.
8.3 Suspension for breach does not relieve the client of payment obligations, and the indemnity in the General Terms of Engagement applies.
9. Reporting A Concern
Misuse, unexpected behaviour, harmful output, or a suspected compliance gap: admin@agentsiw.com, subject line AI CONCERN. Reports are reviewed within two business days. Security vulnerabilities go to the Responsible Disclosure Policy.
10. Changes
AI regulation and model capability both move quickly. This policy is reviewed at least annually and whenever a material legal or technical change requires it. The effective date above marks the current version.