Responsible AI

Trust isengineered,not promised.

Responsible AI isn’t a policy document. It’s a set of practices built into every project, from the first workshop to the last model update. Here’s exactly what we do.

Our practices

Eight commitments on every project.

Assess

Risk assessment first

Before we build, we assess who could be affected and how, and support your data protection impact assessment (DPIA).

Measure

Evaluation before launch

Every model is tested on a held-out evaluation set against a baseline, with results shared in full.

Fairness

Bias testing

We check performance across relevant groups, record the results and fix gaps before launch.

Oversight

People stay in charge

Significant decisions have a person in the loop, with the information and authority to override the AI.

Transparency

No hidden AI

People are told when they’re dealing with AI, and answers show their sources wherever possible.

Privacy

Data minimisation

We use only the data a task needs, redact what we can, and never use your data to train other clients’ models.

Security

Red-teaming

We test for prompt injection, data leakage, jailbreaks and harmful outputs, following the NCSC’s secure AI guidelines.

Accountability

Documentation

Model cards, data lineage and decision logs, so you can explain what the AI does to customers, auditors and regulators.

Regulatory map

The rules we design around.

A summary for orientation, not legal advice. For the full picture, read our UK AI regulation guide.

FrameworkApplies toWhat it means in practice
UK GDPR and Data Protection Act 2018Any processing of personal data in the UKA lawful basis, data minimisation, DPIAs for high-risk processing, and rights for the people whose data you use
Data (Use and Access) Act 2025Automated decision-making about peopleUpdated rules in force since February 2026: safeguards, information for the people affected, and the right to human review and to contest decisions
Sector regulatorsFCA, PRA, MHRA, CMA, Ofcom, SRA and othersExisting sector rules apply to AI, such as the FCA’s Consumer Duty and MHRA medical device rules
EU AI ActUK firms whose AI is placed on the market or used in the EUProhibited practices and general-purpose AI duties apply now. Transparency duties apply from August 2026. High-risk rules are deferred to December 2027 or August 2028
ISO/IEC 42001Organisations that want a certifiable AI management systemA structured way to govern AI risk, roles and continual improvement
NCSC secure AI guidelinesAnyone building AI systemsSecurity across design, development, deployment and operation
Algorithmic Transparency Recording StandardPublic sector bodiesPublishing clear information about the algorithmic tools used in decisions

Where we draw the line

Work we turn down.

Saying no is part of doing this responsibly. We don’t take on projects that:

  • Deceive peopleImpersonating real people, fake reviews, or hiding from people that they’re talking to AI.
  • Make significant decisions with no human reviewAutomated decisions about people’s jobs, money, health or legal rights without meaningful human oversight and a way to challenge them.
  • Use data unlawfullyScraped personal data without a lawful basis, or data used for purposes people weren’t told about.
  • Fall under prohibited practicesAnything the EU AI Act prohibits, such as social scoring or manipulative techniques, even where it would only be used in the UK.

Start a conversation

Tell us the problem.
We’ll tell you honestly if AI can solve it.