Artificial Intelligence (AI) Policy
1. Vision and Ethical Mission
Our goal is to provide affordable, practical, and accessible technology that enables local economies to innovate while retaining ownership of their digital futures. We use AI to accelerate business transformation, not to replace the human-centric expertise that defines the voluntary and community sector.
2. Mandatory "Red Line" Prohibitions
To prevent negligent misrepresentation or data breaches, all CiviCode personnel must adhere to these prohibitions:
- Public Data Entry: No un-anonymised client data may be entered into public AI models.
- Unverified Financial Narratives: AI may draft financial reports, but the CFO (Brent Diffin) must verify every figure and calculation for accuracy.
- Automated Decision-Making: AI must never be the sole determinant for high-impact project milestones or client strategy recommendations.
- Disclaiming Accountability: CiviCode will never treat an AI tool as a separate legal entity. We remain 100% accountable for all AI-assisted outputs.
- Tooling Restriction: CiviCode staff have access to the best AI packages that are private to the organisation - therefore, no use of AI tools outside of these (Gemini & Devin) are permitted without prior written director approval.
3. Professional Standards: Using accepted Prompting Frameworks
Every prompt used for client work must follow the COSTAR standard to ensure "pattern matching" results are contextually accurate:
- C - Context: Background on the task.
- O - Objective: The specific task for the AI.
- S - Style: The professional "voice" (e.g., "like a Technical Architect").
- T - Tone: The emotional quality (e.g., "cautious and analytical").
- A - Audience: Who is reading this? (e.g., "Board of Trustees").
- R - Response: The exact format (e.g., "A 3-column table with an executive summary").
4. Technical Guardrails & Governance
- DPO Oversight: The DPO (Michael) is responsible for conducting Data Protection Impact Assessments (DPIAs) for any high-risk AI project or new vendor integration.
- Security Model: All AI tools must operate within our Zero Trust and MFA environment. We prioritise "Edge AI" and local models to keep data within client-controlled accounts where possible.
- Anonymisation: Before processing any client dataset for "Discovery," all PII must be stripped using industry-standard anonymisation techniques.
5. Client Transparency
- Disclosure: We will always inform clients when AI has been used to generate reports or analysis.
- Training: As part of our service, we will train clients on the limitations of AI (hallucinations and bias) to ensure they can sustain their digital maturity safely.