Last updated: 8 September 2026 · Version 1.0 · Reviewed annually and on material change
Enablai builds and deploys artificial intelligence for organisations. That work carries obligations we take seriously, and this statement sets out what we commit to — in our own operations, in the systems we build for clients, and on this website.
We publish it because we think a firm that sells AI capability should be willing to state publicly how it governs its own.
1. Our principles
Human accountability. A named person is accountable for every AI system we build or operate. Accountability does not transfer to a model. Where a system informs a decision about a person, a human must be able to understand it, question it, and overrule it.
Proportionality. We match governance to risk. A tool that drafts internal meeting notes does not need the controls of a system that screens job applicants. We assess this explicitly rather than applying the same process to everything.
Transparency. People should know when they are dealing with an AI system, what it does, what data it uses, and what its limits are. We do not disguise machines as people.
Contestability. Anyone materially affected by an AI-supported decision should be able to get an explanation and ask a human to review it. A right that exists only on paper is not a right.
Data minimisation and provenance. We use the least data that will do the job, we know where it came from, and we do not use client or personal data to train third-party models.
Fairness. We test for disparate outcomes across the groups a system affects, we document what we find, and we say so when a system is not fit for a use case. We would rather lose the work than ship something we do not trust.
Security by design. AI systems introduce failure modes conventional software does not: prompt injection, training-data poisoning, model extraction, and the leakage of data through outputs. We design against them from the start.
Honesty about limits. Generative models produce fluent output that can be wrong. We say so, we measure it, and we design for it rather than around it.
Environmental awareness. Compute has a footprint. We choose right-sized models, avoid unnecessary retraining, and treat efficiency as a design goal rather than an afterthought.
We decline work. Some applications we will not build. See §7.
2. How we govern AI in client work
Every engagement involving an AI system runs through the following. It is a condition of the engagement, not an optional extra.
| Stage | What we do |
|---|---|
| Intake | Classify the intended use against the EU AI Act risk tiers and any applicable UK regulator expectations. Identify who could be affected and how. Confirm the use case is not on our prohibited list. |
| Data assessment | Establish lawful basis, provenance, licensing, and quality of every data source. Identify special category data and whether it can be avoided. Complete a data protection impact assessment where required. |
| Design | Define the human oversight model before building. Specify what the system will not be used for. Set the evaluation criteria and the thresholds for go and no-go. |
| Build | Version-control data, prompts, configuration, and model choice. Log inputs and outputs to the extent proportionate and lawful. Apply security controls proportionate to the system's risk, designed against the failure modes in §1. |
| Evaluate | Test accuracy, robustness, and consistency against agreed criteria. Test for disparate performance across affected groups where the use case warrants it. Red-team for prompt injection, jailbreaks, and data leakage. Document results including failures. |
| Handover | Provide a model or system card: purpose, data, limits, known failure modes, evaluation results, oversight requirements, monitoring plan, and the conditions under which the system should be withdrawn. |
| Post-deployment | Where we are retained for it, monitor drift and incidents against the agreed baseline, and review quarterly. Where we are not, we say plainly at handover what monitoring the client must do and what happens if they do not. |
Where an engagement makes us a provider or deployer under the EU AI Act, we say so in writing at the start, identify which obligations fall to whom, and document it in the statement of work. Getting this allocation wrong is one of the most common and most expensive failures we see.
3. Article 50 disclosures for this website and our own tools
Article 50 of the EU AI Act has applied since 2 August 2026. Our position:
Chat and conversational interfaces. We do not operate an AI chat assistant on this website.
AI-generated and AI-assisted content. Some of the content on this site is drafted with AI assistance. Where that is the case:
- every page of this site carries a notice that some content is drafted with the assistance of artificial intelligence and reviewed by a named editor before publication;
- that editor is Max Ayers, Director, who reviews everything we publish here and holds editorial responsibility for it;
- we do not publish synthetic audio or video of real people, including our own directors.
Article 50(4) exempts text published to inform the public on matters of public interest from the deployer disclosure requirement where the content has been through human review or editorial control and a natural or legal person holds editorial responsibility for its publication. We meet both limbs, and we tell you anyway, because we think you should know.
Emotion recognition and biometric categorisation. We do not use either on this website or in our marketing, and we do not build them for clients — see §7.
Deepfakes. We do not create them.
Machine-readable marking. Where we are the provider of a generative system supplied to a client, we implement machine-readable marking of outputs in line with Article 50(2). Transitional arrangements for that duty apply only to providers of systems placed on the market before 2 August 2026; our own commitment is not contingent on them.
4. AI in our own operations
We use AI tools internally for drafting, research, code assistance, and analysis. Our rules:
- Approved tools only. We use only AI tools we have approved after reviewing their terms. At present that is the Anthropic Claude API, which we use under commercial terms. Client material may not be put into anything else without the same review and approval.
- No training on your data. Our provider's commercial terms do not permit our inputs to be used to train its models, and we will not approve a provider that does not give an equivalent commitment.
- No client confidential information into any consumer-tier or free service.
- Human review before anything leaves. No AI output reaches a client, a regulator, or the public without a named person reading it and taking responsibility for it.
- No automated decisions about people. We do not use AI to screen job applications, to make hiring or promotion decisions, or to monitor anyone's productivity.
- Disclosure on request. If you want to know whether AI was used in preparing a deliverable for you, ask us and we will tell you.
5. What we tell you about limits
We would rather set expectations correctly than win work on an implied promise. So, plainly:
- Large language models generate plausible text, including plausible text that is factually wrong. This is a property of how they work, not a bug that a better prompt removes.
- The same input can produce different outputs. Where reproducibility matters, it has to be engineered, and that has a cost.
- A model's behaviour can change when a provider updates it, without notice to us.
- Bias in training data appears in outputs. Testing reduces the risk; it does not remove it.
- Benchmark performance is not production performance.
- Any claimed accuracy figure is specific to a dataset, a task, and a point in time.
- Legal and regulatory positions on AI are moving quickly. Advice that was right last quarter may not be right now, which is why our engagements include a review cadence rather than a single sign-off.
6. Third-party models and suppliers
We do not train foundation models. We build on models supplied by third parties — at present, principally Anthropic — and we are open about which. Before adopting one we assess its documented training data and provenance disclosures, its terms on data retention and training, its safety evaluations and published model cards, its security posture, its data location and transfer mechanism, and its stability and deprecation policy.
Where a client requires a specific model or provider we will implement it, and we will record in writing any concern we have about that choice.
7. Work we will not do
We decline engagements whose purpose is:
- social scoring of individuals by public or private bodies;
- emotion recognition in workplaces or educational settings;
- untargeted scraping of facial images to build recognition databases;
- biometric categorisation to infer race, political opinion, religious or philosophical belief, trade union membership, sex life, or sexual orientation;
- real-time remote biometric identification in publicly accessible spaces for law enforcement, outside the narrow exceptions in law;
- predicting the risk that a person will commit a criminal offence based solely on profiling or on assessed personality traits;
- exploiting the vulnerability of a person or group by reason of age, disability, or specific social or economic situation, in a way that materially distorts behaviour and causes or is likely to cause significant harm;
- subliminal, manipulative, or deceptive techniques that materially distort behaviour in a way causing or likely to cause significant harm;
- generating disinformation, synthetic media of real people without consent, or content designed to be mistaken for a genuine communication from a real organisation;
- autonomous decision-making that determines a person's access to employment, credit, housing, insurance, healthcare, education, or benefits without meaningful human review;
- developing or targeting weapons systems.
The first several of these are prohibited practices under Article 5 of the EU AI Act, which has applied since 2 February 2025 — this is a current obligation, not a future one. The rest are our own line. We will also decline any work where a client refuses the governance in §2, or insists on deploying a system our evaluation says is not fit for the stated purpose.
8. Governance and accountability
| Accountable director | Max Ayers, Director |
| AI governance lead | Max Ayers, Director |
| Escalation route | max@enablai.co.uk |
| Review cycle | This statement is reviewed annually and on any material change to law, our services, or our tooling |
| Framework alignment | We align our practice to the NIST AI Risk Management Framework and the UK's cross-sector AI regulatory principles. We are not currently certified to ISO/IEC 42001. |
| Training | Both directors complete AI governance and safety training annually |
9. Raise a concern
If you believe an AI system we built or operate has caused harm, produced an unfair outcome, or been deployed outside its intended use, tell us. We would rather hear it from you than from a regulator.
max@enablai.co.uk — reviewed by the AI governance lead, acknowledged within 5 working days.
You may raise a concern anonymously. We do not retaliate against anyone who does, whether they work for us, for a client, or for neither. If you are affected by a decision an AI system we built contributed to, you can ask for an explanation and for human review, and we will pass the request to the accountable party and tell you who that is.
Our general process is in our complaints procedure.
This statement describes our commitments. It does not create legal rights enforceable against us beyond those in the contract governing a particular engagement or those conferred by law. It is not legal advice about your own AI obligations.