October
Request a demo
Responsible AI · Policy

Accountable by design.

Policy in briefNext review · Q1 2027

The five things to know.

  • Every AI system is classified before deployment.
  • High-risk and clinical-adjacent signals break to a human or emergency pathway.
  • Conversation data is never supplied to providers for model training.
  • Material model and prompt changes trigger fresh testing.
  • A named executive remains accountable for every consequential use.
Governance lifecycleSix operating controls
01

Classify

Purpose, user impact and regulatory risk.

02

Approve

Named owners review data, model and safeguards.

03

Oversee

Consequential use retains meaningful human review.

04

Test

Bias, safety and adversarial thresholds.

05

Monitor

Production behaviour and material changes.

06

Report

Registers, evaluations and accountable contacts.

Human oversight

AI supports judgment. It does not erase accountability.

People remain responsible for consequential decisions and users retain routes to challenge, correct or escalate an outcome.

Full policy12 control areas
01

Purpose and scope

The policy covers every AI system operated, developed or integrated by October—including Luna, Ash, Ivy, hiring-support tools, assessment engines and internal AI tooling. Each system is governed from design through retirement.

02

Risk classification

Every system is classified before deployment using the EU AI Act framework. Unacceptable-risk systems are prohibited; hiring-support tools receive high-risk controls; conversational agents carry limited-risk transparency obligations.

03

Named accountability

The CEO is accountable for the programme. The CTO owns technical oversight, the DPO coordinates privacy and regulatory compliance, the Product Director owns per-system risk and the AI Governance Lead maintains the register and audit cycle.

04

Lifecycle governance

Design reviews set purpose, data minimisation and fairness plans. Development requires versioned prompts and peer review. Deployment is staged. Production is monitored for drift and escalation. Retirement closes access and follows a documented deletion schedule.

05

Data governance and privacy

Conversation data is not shared with providers for training. DPAs, zero-retention API configurations, SCCs and the UK IDTA govern international processing. High-risk systems require a DPIA before deployment.

06

Transparency and explainability

Users are told when they are interacting with AI. Material system purpose, provider and risk information is published. Consequential recommendations must be explainable enough for a person to review and challenge.

07

Human oversight

AI supports—not replaces—human judgment. Hiring recommendations remain advisory. Clinical-adjacent and high-risk signals surface the appropriate human or emergency pathway rather than allowing an agent to act beyond scope.

08

Monitoring and audit

Performance, safety, drift, user feedback and escalation rates are reviewed continuously. Model, prompt and configuration changes trigger relevant regression, fairness and safety testing before release.

09

Incident response

AI incidents enter the security and privacy response process with severity, owner, containment, investigation and closure evidence. Material incidents are escalated to the DPO and executive owner.

10

Bias and fairness

Protected-characteristic testing is designed before deployment and repeated after material change. Outcomes that exceed the defined disparity or differential-response threshold require review and remediation.

Review published evaluations
11

Third-party providers

Providers are due-diligenced for security, privacy, retention, training use, geographic processing and contractual safeguards. The public model register records current providers and deployment contexts.

Open the model register
12

Review schedule

Effective 1 February 2025 · version 1.0 · next scheduled review Q1 2027, or earlier after a material regulatory, provider or system change.

Next step

Read the evidence behind the policy.

See the safety and fairness evaluations, with their methods, results and limitations.