AI usage principles and policy

What we do, what we will not do, and what you can hold us to. Written to be quoted back at us, not to be admired.

  1. 01

    A person is accountable for every system

    Every system we build has a named human accountable for what it does, and a documented way to turn it off. "The model decided" is not an answer anyone gets to give, so we do not build systems where it could be.

  2. 02

    Your data is not our training data

    We do not train on client data, and we do not pass it to a provider who will. It is returned or destroyed on request, and we can tell you where it lived while we held it. This is in the contract, not just on this page.

  3. 03

    Provenance over plausibility

    A confident answer with no source is a liability. Outputs are traceable to the documents, records and rules that produced them, so a wrong answer can be investigated rather than argued about.

  4. 04

    A human decides anything that affects a person

    Where an output affects someone’s money, health, housing, employment or legal position, a person reviews it before it takes effect, and the review is a real step rather than a rubber stamp.

  5. 05

    Purpose limitation is enforced in the build

    Data gathered for one purpose is not quietly turned to another. A new use is a new conversation with you, not a configuration change on our side. Under the Privacy Act that is the law; we make it a property of the system as well.

  6. 06

    You can leave

    Documentation, handover and the right to take the system elsewhere are part of the build, never an exit fee. If the only reason you stay is that leaving is painful, we have built the wrong thing.

What we will not build

A policy that only lists what a company is willing to do says nothing. These are refusals, and they hold even where the work is offered and paid for.

  • Build surveillance or scoring systems aimed at the people whose data trained them.
  • Deploy a system that makes a consequential decision about a person with no human in the loop.
  • Use client data, iwi data or te reo Māori content as training data.
  • Ship a system we cannot explain, or whose outputs we cannot trace.
  • Present model output as human work, or human work as model output.
  • Take an engagement where the measure of success is headcount removed.

The frameworks we build to

These are other people’s frameworks, not ours. We describe what each asks for and what we do about it, and we claim no endorsement or accreditation from any of them.

This is a statement of how we work, not legal advice, and it does not replace the terms of any engagement. Where a framework governs your organisation, take your own advice on it.

Inference that answers to tikanga, not just to a benchmark.

We build and run inference against the six principles of Māori data sovereignty set out by Te Mana Raraunga. For an organisation holding data about its own people, that is not a line at the bottom of a page. It decides where the model runs, what it is allowed to see, and who can switch it off.

Māori data stays Māori owned. Running a model over it does not transfer it, licence it, or turn it into training data.

  • Rangatiratanga

    Authority

    You decide what the model may see and what it may do with it. Access is yours to grant and yours to withdraw, and a withdrawal takes effect at the next inference, not at the next contract review.

  • Whakapapa

    Relationships

    Every output can be traced back to the documents, the records and the rules that produced it. Nothing arrives without a provenance you can follow.

  • Whanaungatanga

    Obligations

    Data gathered for one purpose is not quietly turned to another. A new use is a new conversation with you, not a schema change on our side.

  • Kotahitanga

    Collective benefit

    The gain comes back to the people the data came from, as hours returned to their staff and services that work better for their whānau.

  • Manaakitanga

    Reciprocity

    We leave you able to run it without us. Documentation, handover and the right to take the system elsewhere are part of the build, never an exit fee.

  • Kaitiakitanga

    Guardianship

    We hold your data in trust and never take ownership of it. It does not train our models or anyone else’s, it is returned or destroyed on request, and inference runs somewhere you can point at, on-shore or inside your own tenancy.

The six principles are those of Te Mana Raraunga, the Māori Data Sovereignty Network. The commitments beside them are ours.