Inferaq Trust Centre
Responsible AI Policy
Inferaq’s principles for lawful, safe, transparent, fair, secure and accountable AI design, deployment and use.
Last updated: 19 September 2026
AI should serve a defined human and business purpose. Capability alone is not justification for deployment. Inferaq applies controls according to likely impact, keeps accountable people involved and distinguishes demonstrated evidence from aspiration.
1. Scope
This policy applies to AI and machine-learning systems designed, built, integrated, evaluated or operated by Inferaq, including predictive models, generative AI, retrieval systems, copilots, agents, intelligent automation and internal uses of AI. Client responsibilities and sector-specific obligations are defined in the relevant engagement.
2. Core principles
Purpose and proportionality
Define the decision or task, intended users, affected people, boundaries and evidence of value before selecting AI.
Safety, security and robustness
Threat-model foreseeable misuse, test failure modes, limit permissions and monitor performance appropriate to risk.
Transparency and explainability
Tell people when they are interacting with AI where material, document limitations and provide explanations suited to the context.
Fairness
Examine data, design and outcomes for unjustified disadvantage, discriminatory proxies and accessibility barriers.
Accountability and governance
Assign owners, approvals, records, escalation routes and review dates. A model is not the accountable decision-maker.
Contestability and redress
Provide a meaningful route to question, correct or appeal important outcomes and reach an authorised person.
3. Risk-based lifecycle
- Discover: define purpose, stakeholders, legal context, alternatives and unacceptable uses.
- Assess: consider data protection, equality, security, human rights, sector rules and operational harm; complete a DPIA or AI impact assessment where appropriate.
- Design: minimise data, select evidence and models deliberately, establish human control and fail-safe behaviour.
- Evaluate: test accuracy, robustness, bias, security, context sufficiency, explainability and usability against documented acceptance criteria.
- Deploy: control access, version components, document limitations, train operators and enable monitoring.
- Operate: review incidents, drift, complaints, supplier changes and real-world outcomes; suspend or retire systems that no longer meet requirements.
4. Data and intellectual property
Inferaq seeks to use data that is lawfully obtained, relevant, proportionate and appropriately governed. Confidential client information is not used to train general models unless expressly authorised under a suitable agreement. Public availability does not automatically establish permission, quality or fitness for a particular use.
5. Human oversight and automated decisions
Oversight must be meaningful: the reviewer needs authority, sufficient information, time and a practical ability to change the outcome. Inferaq will not design solely automated decisions with legal or similarly significant effects without a documented lawful basis, required safeguards, meaningful information and a route for human intervention.
6. Generative AI and agents
- Ground material claims in approved evidence where the use case requires it.
- Separate instructions, retrieved data and untrusted user content.
- Restrict tools and data to the minimum necessary permissions.
- Require approval before irreversible, financial, external-communication or high-impact actions.
- Set cost, time, token and action limits.
- Record material actions and sources where proportionate.
- Make uncertainty and limitations visible rather than fabricating confidence.
7. Uses Inferaq will not support
Inferaq will not knowingly build AI for unlawful discrimination, deceptive impersonation, covert manipulation causing material harm, indiscriminate surveillance, unauthorised access, malicious cyber activity, fabrication of evidence or removal of legally required human review. Additional exclusions may apply by sector, client or jurisdiction.
8. Reporting concerns
Questions or concerns about an Inferaq AI system may be sent to info@inferaq.com. Include the system, outcome, date and impact. Security vulnerabilities should use the Responsible Disclosure route.
Reference framework
UK Government: AI regulation principlesNCSC: secure AI system developmentICO: AI and data protectionLast updated: 19 September 2026
