Classify
Purpose, user impact and regulatory risk.

Purpose, user impact and regulatory risk.
Named owners review data, model and safeguards.
Consequential use retains meaningful human review.
Bias, safety and adversarial thresholds.
Production behaviour and material changes.
Registers, evaluations and accountable contacts.
People remain responsible for consequential decisions and users retain routes to challenge, correct or escalate an outcome.
The policy covers every AI system operated, developed or integrated by October—including Luna, Ash, Ivy, hiring-support tools, assessment engines and internal AI tooling. Each system is governed from design through retirement.
Every system is classified before deployment using the EU AI Act framework. Unacceptable-risk systems are prohibited; hiring-support tools receive high-risk controls; conversational agents carry limited-risk transparency obligations.
The CEO is accountable for the programme. The CTO owns technical oversight, the DPO coordinates privacy and regulatory compliance, the Product Director owns per-system risk and the AI Governance Lead maintains the register and audit cycle.
Design reviews set purpose, data minimisation and fairness plans. Development requires versioned prompts and peer review. Deployment is staged. Production is monitored for drift and escalation. Retirement closes access and follows a documented deletion schedule.
Conversation data is not shared with providers for training. DPAs, zero-retention API configurations, SCCs and the UK IDTA govern international processing. High-risk systems require a DPIA before deployment.
Users are told when they are interacting with AI. Material system purpose, provider and risk information is published. Consequential recommendations must be explainable enough for a person to review and challenge.
AI supports—not replaces—human judgment. Hiring recommendations remain advisory. Clinical-adjacent and high-risk signals surface the appropriate human or emergency pathway rather than allowing an agent to act beyond scope.
Performance, safety, drift, user feedback and escalation rates are reviewed continuously. Model, prompt and configuration changes trigger relevant regression, fairness and safety testing before release.
AI incidents enter the security and privacy response process with severity, owner, containment, investigation and closure evidence. Material incidents are escalated to the DPO and executive owner.
Protected-characteristic testing is designed before deployment and repeated after material change. Outcomes that exceed the defined disparity or differential-response threshold require review and remediation.
Review published evaluationsProviders are due-diligenced for security, privacy, retention, training use, geographic processing and contractual safeguards. The public model register records current providers and deployment contexts.
Open the model registerEffective 1 February 2025 · version 1.0 · next scheduled review Q1 2027, or earlier after a material regulatory, provider or system change.
See the safety and fairness evaluations, with their methods, results and limitations.