Risk assessment first
Before we build, we assess who could be affected and how, and support your data protection impact assessment (DPIA).
Responsible AI
Responsible AI isn’t a policy document. It’s a set of practices built into every project, from the first workshop to the last model update. Here’s exactly what we do.
Our practices
Before we build, we assess who could be affected and how, and support your data protection impact assessment (DPIA).
Every model is tested on a held-out evaluation set against a baseline, with results shared in full.
We check performance across relevant groups, record the results and fix gaps before launch.
Significant decisions have a person in the loop, with the information and authority to override the AI.
People are told when they’re dealing with AI, and answers show their sources wherever possible.
We use only the data a task needs, redact what we can, and never use your data to train other clients’ models.
We test for prompt injection, data leakage, jailbreaks and harmful outputs, following the NCSC’s secure AI guidelines.
Model cards, data lineage and decision logs, so you can explain what the AI does to customers, auditors and regulators.
Regulatory map
A summary for orientation, not legal advice. For the full picture, read our UK AI regulation guide.
| Framework | Applies to | What it means in practice |
|---|---|---|
| UK GDPR and Data Protection Act 2018 | Any processing of personal data in the UK | A lawful basis, data minimisation, DPIAs for high-risk processing, and rights for the people whose data you use |
| Data (Use and Access) Act 2025 | Automated decision-making about people | Updated rules in force since February 2026: safeguards, information for the people affected, and the right to human review and to contest decisions |
| Sector regulators | FCA, PRA, MHRA, CMA, Ofcom, SRA and others | Existing sector rules apply to AI, such as the FCA’s Consumer Duty and MHRA medical device rules |
| EU AI Act | UK firms whose AI is placed on the market or used in the EU | Prohibited practices and general-purpose AI duties apply now. Transparency duties apply from August 2026. High-risk rules are deferred to December 2027 or August 2028 |
| ISO/IEC 42001 | Organisations that want a certifiable AI management system | A structured way to govern AI risk, roles and continual improvement |
| NCSC secure AI guidelines | Anyone building AI systems | Security across design, development, deployment and operation |
| Algorithmic Transparency Recording Standard | Public sector bodies | Publishing clear information about the algorithmic tools used in decisions |
Where we draw the line
Saying no is part of doing this responsibly. We don’t take on projects that:
Start a conversation