Last updated: 29 August 2026
This Data & AI Transparency Notice explains how boxbank s.r.o., operating under the WEBDANGER brand, uses artificial-intelligence systems and AI-assisted tools in connection with WEBDANGER Services.
It is intended to provide clear information about:
- where AI may be used;
- how WEBDANGER may interact with third-party AI providers;
- when users are interacting with AI;
- what data may be processed by AI systems;
- human review and limitations;
- AI-generated content;
- safety and prohibited uses;
- and the controls WEBDANGER applies to AI-enabled processing.
This Notice should be read together with our:
- Privacy Policy;
- Terms of Service;
- Acceptable Use & Abuse Policy;
- Cookie & Tracking Policy;
- and applicable service-specific terms.
1. Who operates WEBDANGER
WEBDANGER is operated by:
boxbank s.r.o.
Registered office:
Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
Company identification number (IČO):
24048232
Commercial Register:
Municipal Court in Prague, Section C, File No. C 437675
Primary website:
webdanger.com
Contact:
contact@webdanger.com
Telephone / SMS:
+420 734 627 827
2. Scope
This Notice may apply to AI used in connection with:
- public website chat;
- customer dashboards;
- website generation;
- software development;
- source-code assistance;
- debugging;
- QA;
- content preparation;
- translation;
- document analysis;
- file analysis;
- image generation;
- media generation;
- support;
- project planning;
- automation;
- internal agents;
- security analysis;
- classification;
- summarisation;
- and other WEBDANGER features.
Not every feature described in this Notice is active in every WEBDANGER Service.
AI ROLES
3. WEBDANGER may have different AI roles
The legal role of WEBDANGER depends on the specific AI feature and technical arrangement.
Depending on context, WEBDANGER may act as:
- a deployer of a third-party AI system;
- a provider of a WEBDANGER-branded AI system built using third-party models or components;
- an integrator of third-party AI technologies;
- a processor acting on a Customer's instructions for Customer-controlled data;
- or a controller for WEBDANGER's own AI-related processing purposes.
The role is assessed per feature rather than assumed globally.
4. Third-party model providers
WEBDANGER may use third-party artificial-intelligence models or model-routing services.
Potential providers may include, where actually activated:
- OpenRouter;
- OpenAI;
- Anthropic;
- Google;
- Meta;
- Mistral;
- DeepSeek;
- Qwen/Alibaba-related providers;
- or other model providers available through approved WEBDANGER integrations.
A provider appearing in this Notice as a possible provider is not represented as active unless the relevant production feature actually uses it.
5. OpenRouter
WEBDANGER may use OpenRouter as a routing layer that provides access to multiple AI model providers.
Where OpenRouter is active, an AI request may be routed:
WEBDANGER → OpenRouter → selected downstream model/provider
The downstream provider may vary according to:
- requested capability;
- privacy requirements;
- security requirements;
- model availability;
- performance;
- region;
- cost;
- customer configuration;
- or other technical criteria.
6. WEBDANGER is not currently represented as a GPAI model developer
Unless WEBDANGER expressly announces otherwise, WEBDANGER does not represent itself as the developer or provider of its own general-purpose/foundation AI model.
Using, routing or integrating third-party general-purpose models does not by itself mean that boxbank s.r.o. developed the underlying foundation model.
If WEBDANGER later trains, substantially modifies or places its own general-purpose AI model on the market, this Notice and the applicable compliance framework will be updated.
WHEN YOU INTERACT WITH AI
7. AI interaction disclosure
Where an AI system is intended to interact directly with a natural person and applicable law requires disclosure, WEBDANGER provides a clear indication that the user is interacting with AI.
For example, a public chatbot may be identified as:
WEBDANGER AI Assistant
or with an equivalent clear AI label.
The disclosure is provided no later than the first interaction where required.
8. AI is not presented as a human where that would be misleading
WEBDANGER does not intentionally design ordinary AI interfaces to deceive users into believing they are communicating with a human employee where they are actually communicating with an AI system.
Where a conversation is transferred to a human, the interface may indicate that transition.
9. AI-assisted human support
A human support representative may use AI to:
- draft responses;
- summarise a ticket;
- translate;
- search internal knowledge;
- classify issues;
- or troubleshoot.
The presence of AI assistance does not necessarily mean the response is produced solely by AI.
DATA SENT TO AI
10. Data that may be processed
Depending on the feature, an AI request may contain:
- user prompts;
- chat messages;
- project instructions;
- selected source-code fragments;
- project files;
- documents;
- images;
- screenshots;
- support context;
- technical logs;
- public webpage information;
- or other information needed for the requested feature.
WEBDANGER seeks to limit AI input to information reasonably relevant to the requested task.
11. Customer data
Customer content is not automatically treated as training data merely because an AI tool processes it.
Processing a Customer prompt or file to perform a requested task is different from using that information to train a general model.
WEBDANGER does not intentionally use Customer confidential content to train a WEBDANGER general-purpose model unless a separate lawful and contractual basis is established and the Customer is appropriately informed.
12. Sensitive data
Users should not submit:
- passwords;
- API secrets;
- private keys;
- payment-card security codes;
- root credentials;
- access tokens;
- authentication cookies;
- or other secrets
to ordinary AI prompts unless the specific secure workflow is designed and authorised for that purpose.
WEBDANGER seeks to prevent unnecessary secret transmission to third-party AI providers.
13. Special-category personal data
Users should not intentionally submit special-category or highly sensitive personal data to a general AI feature unless:
- the feature is expressly intended for that processing;
- an appropriate legal basis exists;
- applicable Customer/controller instructions permit it;
- and required safeguards are in place.
AI PRIVACY ROUTING
14. Privacy profiles
WEBDANGER may apply different privacy profiles to AI requests.
A production implementation may distinguish, for example:
Standard
For public/non-sensitive information.
Customer Confidential
For Customer project data requiring stronger provider controls.
Restricted
For data that should not be transmitted to ordinary external AI providers without explicit approval.
The exact names may vary.
15. Zero-data-retention and no-training preferences
For confidential Customer/personal-data workflows, WEBDANGER may prefer or require providers/settings offering:
- zero-data-retention (“ZDR”) where available;
- no model training on submitted data;
- limited logging;
- contractual data-protection terms;
- and appropriate processing locations or transfer safeguards.
A ZDR label supplied by a provider does not eliminate all processing: transient processing and metadata necessary to route, secure or bill the request may still occur.
16. OpenRouter data settings
OpenRouter currently provides privacy/data-policy controls that can be used to restrict provider selection and data-handling characteristics.
According to OpenRouter's current documentation as of this Notice's review date, OpenRouter does not store prompt or response content unless the account opts into applicable input/output logging or OpenRouter-use settings. OpenRouter does retain request metadata such as token counts and latency. Its documentation also describes limited anonymous prompt categorisation performed under a zero-data-retention model policy.
Where WEBDANGER sends Customer or personal data through OpenRouter, routing is configured according to the sensitivity and requirements of the relevant production feature.
Downstream providers may have different retention, training and privacy practices, so the OpenRouter layer is not treated as the only privacy consideration.
17. Prompt logging
WEBDANGER does not need to retain every AI prompt indefinitely.
Where prompt logging is used, retention depends on purposes such as:
- user conversation history;
- service delivery;
- security;
- debugging;
- legal evidence;
- abuse investigation;
- or an explicit Customer feature.
Prompt logging should be disabled or minimised where the purpose does not justify retention.
AI OUTPUT
18. AI output can be wrong
Artificial-intelligence output may be:
- inaccurate;
- incomplete;
- outdated;
- misleading;
- inconsistent;
- insecure;
- biased;
- non-unique;
- or fabricated (“hallucinated”).
Users should evaluate important output before relying on it.
19. No guarantee of factual accuracy
AI-generated answers, code, summaries, recommendations, translations or classifications are not guaranteed to be correct merely because they are produced by an advanced model.
WEBDANGER may use:
- automated checks;
- deterministic tests;
- external validation;
- or human review
to reduce error, but errors remain possible.
20. Code generated with AI
AI-generated code may contain:
- bugs;
- vulnerabilities;
- insecure dependencies;
- licensing issues;
- compatibility problems;
- or incorrect assumptions.
Where WEBDANGER is contractually responsible for production Project delivery, AI-generated code is subject to engineering review and testing appropriate to the scope and risk before final handover or production deployment.
21. Security findings
AI-assisted security output is not a guarantee that:
- a target is secure;
- every vulnerability has been found;
- a detected issue is exploitable;
- or a finding is not a false positive.
Active security testing remains governed by the Acceptable Use & Abuse Policy.
22. Professional decisions
Unless a Service expressly states otherwise, ordinary WEBDANGER AI output is not intended as a substitute for qualified:
- legal advice;
- tax advice;
- accounting advice;
- medical diagnosis;
- regulated financial advice;
- or another licensed professional service.
HUMAN REVIEW
23. Human review
WEBDANGER may use human review where appropriate to:
- verify AI output;
- approve Project deliverables;
- assess high-impact decisions;
- investigate abuse;
- resolve disputes;
- correct errors;
- or improve safety.
The degree of human review depends on the feature and risk.
24. Customer deliverables
AI may assist WEBDANGER with:
- code;
- design;
- copy;
- translation;
- QA;
- debugging;
- planning;
- documentation;
- and research.
Where WEBDANGER is contractually responsible for a final Customer deliverable, use of AI does not automatically remove WEBDANGER's contractual responsibilities.
ARTICLE 50 TRANSPARENCY
25. EU AI Act transparency
Where Regulation (EU) 2024/1689 (AI Act), as amended, applies, WEBDANGER follows the transparency obligations relevant to its role.
Article 50 transparency obligations apply from 2 August 2026.
Information required under Article 50 is provided to the natural persons concerned in a clear and distinguishable manner, no later than the time of the first relevant interaction or exposure, and in conformity with applicable accessibility requirements.
25A. Limited transition for pre-existing generative AI systems
The 2026 amendment to the AI Act provides a limited transition for AI systems that were placed on the market or put into service before 2 August 2026, and only for the Article 50(2) machine-readable marking/detection obligation.
Providers of those pre-existing systems must take the necessary steps to comply with Article 50(2) by 2 December 2026.
This transition does not create a general grace period for the other Article 50 transparency obligations.
AI-generated or manipulated content already generated and made available before 2 August 2026 is not required to be labelled retroactively under that rule, although voluntary transparency may still be appropriate.
26. AI interaction labels
For AI systems intended to interact directly with natural persons, a provider may be required to design the system so that the person is informed that they are interacting with AI unless that is obvious in the circumstances.
WEBDANGER uses clear AI identification for relevant public-facing AI interfaces.
27. Machine-readable marking of synthetic content
Where WEBDANGER is the provider of an AI system that generates synthetic audio, image, video or text content and Article 50(2) applies, the system is designed so that relevant output is marked in a machine-readable format and is detectable as artificially generated or manipulated, subject to the statutory scope and exceptions.
The technical marking method may depend on available standards, model/provider functionality and applicable implementation guidance.
28. Assistive editing exception
Article 50's machine-readable marking obligation does not apply to the extent the AI system performs an assistive function for standard editing or does not substantially alter the input data or its semantics, subject to the conditions in the AI Act.
WEBDANGER therefore does not label every minor spelling correction as synthetic media merely because AI-assisted editing was used.
DEEPFAKES AND SYNTHETIC MEDIA
29. Deepfakes
For this Notice, a “deepfake” follows the applicable AI Act concept: AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
Where WEBDANGER deploys an AI system to generate or manipulate content constituting a deepfake within Article 50, WEBDANGER discloses that the content has been artificially generated or manipulated where required.
30. Creative and artistic works
For evidently artistic, creative, satirical, fictional or analogous works, AI Act transparency may be provided in an appropriate manner that discloses the existence of generated/manipulated content without unnecessarily impairing the display or enjoyment of the work.
31. No deceptive authenticity claim
WEBDANGER does not intentionally present a synthetic depiction as authentic real-world evidence where doing so would be deceptive or unlawful.
A label may use wording such as:
- AI-generated;
- AI-created;
- AI-enhanced;
- synthetically generated;
- or artificially manipulated,
depending on context.
PUBLIC-INTEREST TEXT
32. AI-generated public-interest text
Where WEBDANGER deploys AI to generate or manipulate text published for the purpose of informing the public on matters of public interest, WEBDANGER discloses the artificial generation/manipulation where Article 50 requires it.
33. Human editorial review
The Article 50 disclosure rule for public-interest text contains an exception where:
- the AI-generated content undergoes human review or editorial control; and
- a natural or legal person holds editorial responsibility for publication.
Where WEBDANGER relies on this exception, the human/editorial review must be real rather than nominal.
EMOTION RECOGNITION AND BIOMETRICS
34. Emotion recognition
WEBDANGER does not currently intend ordinary Services to use AI-based emotion recognition on users or Customers.
If such a feature is introduced, it must undergo a separate legal review before launch.
35. Biometric categorisation
WEBDANGER does not currently intend ordinary Services to categorise individuals using biometric data for sensitive or behavioural classification.
If introduced, the feature must undergo a separate AI Act, GDPR and security review.
36. Transparency if introduced
Where an emotion-recognition or biometric-categorisation system is lawfully deployed and Article 50 applies, exposed natural persons are informed about operation of the system as required.
Any personal-data processing associated with such a system must also comply independently with applicable data-protection law, including the GDPR where applicable.
PROHIBITED AND HIGH-RISK USE
37. Prohibited AI practices
WEBDANGER does not permit AI features to be intentionally designed or used for prohibited AI practices under applicable law.
Relevant prohibitions can include certain:
- manipulative or deceptive techniques causing legally relevant harm;
- exploitation of vulnerabilities;
- social scoring;
- predictive criminal-risk practices;
- facial-image scraping;
- emotion recognition in specified workplace/education contexts;
- sensitive biometric categorisation;
- unlawful real-time remote biometric identification;
- and other practices listed in Article 5 AI Act.
38. Non-consensual intimate content and synthetic CSAM
The 2026 AI Omnibus adds prohibitions concerning certain AI systems used to generate or manipulate:
- realistic non-consensual sexually explicit/intimate material involving identifiable natural persons; and
- child sexual abuse material as defined by the applicable EU framework.
The new prohibition introduced by Regulation (EU) 2026/1744 applies from 2 December 2026.
WEBDANGER designs its AI roadmap to avoid enabling prohibited “nudification”, non-consensual intimate generation or synthetic child sexual abuse material.
39. Safety controls before December 2026
WEBDANGER does not wait until the statutory application date to treat these uses as acceptable.
The Acceptable Use & Abuse Policy may prohibit harmful sexual exploitation uses earlier on contractual, safety and other legal grounds.
40. High-risk AI
WEBDANGER does not currently intend its standard AI Services to make final determinations in high-risk areas such as:
- employment selection or termination;
- worker evaluation;
- education admission or grading;
- credit eligibility;
- essential-service eligibility;
- insurance risk/eligibility;
- medical diagnosis;
- migration/asylum;
- law-enforcement decision-making;
- criminal-risk assessment;
- or comparable legally significant decisions.
Any future feature involving such use requires a separate AI Act classification and launch review.
41. High-risk implementation timelines
Following Regulation (EU) 2026/1744:
- relevant Annex III high-risk rules have an extended application date of 2 December 2027;
- high-risk AI systems embedded in regulated Annex I products have an extended application date of 2 August 2028.
These extensions do not postpone obligations already applicable to other AI uses, including prohibited practices, AI literacy, GPAI obligations and Article 50 transparency.
AUTOMATED DECISION-MAKING
42. Significant decisions about people
WEBDANGER does not intend ordinary AI features to make solely automated decisions about individuals that produce legal or similarly significant effects without the safeguards required by applicable law.
43. Fraud and security systems
WEBDANGER and external providers may use automated tools to:
- detect fraud;
- identify abuse;
- score suspicious traffic;
- protect accounts;
- prioritise security events;
- or assess payment risk.
Where such processing becomes legally significant automated decision-making, the applicable Privacy Policy and statutory safeguards apply.
AI LITERACY
44. AI literacy
WEBDANGER supports AI literacy for staff and other persons using AI systems on its behalf.
Article 4 AI Act applies to providers and deployers and requires measures supporting development of AI literacy appropriate to:
- technical knowledge;
- experience;
- education/training;
- context of use;
- and persons/groups affected by the AI system.
45. AI literacy does not require one universal certification
The AI Act does not require every person to hold the same formal AI certificate.
Training and guidance should be proportionate to the person's role and the AI systems they use.
COPYRIGHT AND INTELLECTUAL PROPERTY
46. AI does not guarantee originality
AI-generated output may resemble or overlap with existing material.
WEBDANGER does not guarantee that every generated output is:
- unique;
- registrable;
- free of third-party rights;
- or suitable for unrestricted commercial use.
47. Customer-supplied materials
Customers remain responsible for having appropriate rights to material they submit for AI processing, including:
- images;
- video;
- audio;
- trademarks;
- source code;
- text;
- datasets;
- and confidential information.
48. Third-party model terms
AI output may also be subject to:
- model-provider terms;
- open-source licences;
- API restrictions;
- content policies;
- or other third-party conditions.
Applicable Customer Project terms may address ownership/licensing separately.
SECURITY
49. Prompt injection and untrusted content
AI systems can be vulnerable to:
- prompt injection;
- malicious instructions in files/webpages;
- data exfiltration attempts;
- tool misuse;
- indirect prompt injection;
- or unsafe autonomous actions.
WEBDANGER may use controls such as:
- content separation;
- tool permissions;
- allowlists;
- confirmation gates;
- sandboxing;
- restricted credentials;
- and human review.
50. Least privilege
WEBDANGER configures AI-agent access according to least-privilege principles appropriate to the task and environment.
A coding agent does not need unrestricted production infrastructure access merely because it can write code.
51. Destructive actions
High-impact actions such as:
- deleting production data;
- moving money;
- transferring domains;
- changing DNS;
- exposing secrets;
- deleting backups;
- sending bulk messages;
- or terminating accounts
are not intended to be performed autonomously without appropriate authorisation and controls.
52. Secrets
WEBDANGER aims to detect and prevent transmission of secrets into external AI prompts where possible.
Relevant secrets include:
- API keys;
- private keys;
- access tokens;
- root credentials;
- passwords;
- payment secrets;
- Cloudflare tokens;
- registrar credentials;
- and database credentials.
AI AGENTS
53. AI agents
WEBDANGER may use AI agents capable of performing multi-step tasks.
An agent may:
- reason over project context;
- call tools;
- create files;
- run tests;
- communicate with permitted APIs;
- or perform workflow steps.
AI-agent permissions are constrained by the relevant environment and account permissions.
54. Tool use
An AI model's ability to request an action does not itself authorise that action.
Tool execution remains subject, as applicable, to:
- authentication;
- role permissions;
- scope;
- policy;
- rate limits;
- confirmation where appropriate;
- and audit logging.
55. Agent auditability
For important AI-agent operations, WEBDANGER may retain audit information such as:
- user/account;
- feature;
- model/provider;
- tool invoked;
- action;
- target;
- timestamp;
- result;
- and approval state.
Audit data is retained according to the Privacy Policy and relevant security/legal needs.
MODEL AND PROVIDER CHANGES
56. Dynamic model routing
AI providers and models may change over time.
WEBDANGER may change the selected provider/model to improve:
- reliability;
- safety;
- cost;
- quality;
- latency;
- privacy;
- or availability.
57. Material changes
Where a provider/model change materially affects privacy, legal rights or Customer contractual commitments, WEBDANGER updates relevant disclosures and obtains any additional approval or contractual amendment required.
58. Customer model controls
Some Services may allow Customers to select:
- model;
- provider;
- privacy profile;
- region;
- retention preference;
- or other AI settings.
Availability depends on the product.
AI RECORDS
59. AI processing records
Where appropriate, WEBDANGER may maintain records of AI processing containing information such as:
- feature;
- provider;
- model identifier;
- request timestamp;
- privacy profile;
- retention/logging mode;
- output status;
- safety event;
- and human review status.
60. Minimum necessary logging
WEBDANGER does not need to store full prompts/outputs merely to maintain an audit record.
Where possible, metadata may be used instead of unnecessary content retention.
CUSTOMER CONTROL
61. Optional AI features
Where an AI feature is optional, WEBDANGER may provide controls to:
- enable/disable it;
- choose a model;
- choose privacy settings;
- delete history;
- or manage data retention.
The exact controls depend on the Service.
62. AI history deletion
Deleting an AI conversation from the Customer interface may remove it from active WEBDANGER systems but may not immediately delete:
- security logs;
- backups;
- legally retained records;
- or downstream-provider records governed by their own lawful retention obligations.
The Privacy Policy describes applicable retention principles.
AI-GENERATED MEDIA PROVENANCE
63. Provenance
Where required or technically appropriate, WEBDANGER may preserve or add provenance information for AI-generated content.
This may include:
- machine-readable metadata;
- content credentials;
- cryptographic provenance;
- watermarking;
- model/provider metadata;
- or another standard.
64. Do not strip required marks
Where a machine-readable AI-origin marking is legally required, WEBDANGER does not intentionally strip or disable that required marking merely to make synthetic content appear human-authored or authentic.
65. Visible labels and machine-readable marks are different
A visible “AI-generated” label and a machine-readable provenance mark serve different functions.
Where law requires both or where one applies to the provider and another to the deployer, WEBDANGER treats them separately.
PUBLICATION AND EDITORIAL CONTROL
66. Public-interest publication
For AI-assisted articles concerning public-interest matters, WEBDANGER may apply:
- source review;
- factual verification;
- human editorial control;
- named or organisational editorial responsibility;
- correction processes;
- and provenance/AI disclosure where required.
67. Marketing copy
Ordinary AI-assisted marketing copy is not automatically treated as public-interest journalism.
However, advertising remains subject to consumer, advertising and unfair-commercial-practices law.
INTERNATIONAL USERS
68. Regional rules
Different jurisdictions regulate AI differently.
WEBDANGER may therefore apply:
- local AI disclosures;
- local data restrictions;
- local automated-decision rights;
- model availability restrictions;
- or regional feature limitations.
A language option does not mean every AI feature has been launched in every country.
COMPLAINTS AND QUESTIONS
69. Questions and complaints about AI
Questions or complaints about WEBDANGER's use of AI may be sent to:
contact@webdanger.com
Where a query is primarily a personal-data rights request, the Privacy Policy process applies.
Where a query concerns abusive AI use, the Acceptable Use & Abuse Policy process applies.
Nothing in this Notice limits a person's statutory right under Article 85 of the EU AI Act, where applicable, to lodge a complaint with the relevant market-surveillance authority if that person has grounds to consider that the AI Act has been infringed.
CHANGES
70. Changes to this Notice
WEBDANGER may update this Notice when:
- AI law changes;
- models/providers change;
- new AI Services are launched;
- processing changes;
- safety controls change;
- or new transparency requirements apply.
The current revision date appears at the top.
APPENDIX A — TYPICAL AI FEATURE MATRIX
| Feature | Typical WEBDANGER role | Typical data | Main controls |
|---|---|---|---|
| Public AI chat | Provider/integrator/deployer depending design | Prompt, session, optional account context | AI label, privacy routing, abuse controls |
| Customer dashboard assistant | Provider/integrator | Prompt, Customer context | Account controls, provider restrictions, logging |
| Website builder | Provider/integrator | Brief, content, assets | Human review, IP checks, project controls |
| Coding agent | Deployer/integrator | Source code, project context | Sandbox, least privilege, secret redaction |
| Document analysis | Deployer/integrator/processor | Customer documents | Confidential privacy profile, retention limits |
| Translation | Deployer/integrator | Text/documents | Confidentiality, output review |
| AI support | Deployer | Ticket/support context | Human escalation, no secret leakage |
| Security analysis | Deployer/integrator | Technical data | Authorised targets only, AUP, validation |
| Image/media generation | Provider/integrator/deployer | Prompt/assets | Provenance, deepfake rules, safety controls |
| Internal development | Deployer | Code/internal documentation | Access control, no secret leakage |
APPENDIX B — STANDARD USER DISCLOSURE
Example for a public chat:
AI Assistant
You are interacting with an AI-powered assistant. AI responses can be inaccurate. Do not provide passwords, private keys or other secrets. Your messages may be processed by approved AI providers as described in our Data & AI Transparency Notice and Privacy Policy.
APPENDIX C — AI OUTPUT LABEL EXAMPLES
Depending on context:
AI-generated
Created with AI
AI-enhanced
Artificially generated or manipulated
AI-assisted draft reviewed by WEBDANGER
Labels must not be used deceptively or in a way that understates legally required disclosure.
APPENDIX D — INTERNAL RISK CATEGORIES
LOW
Examples:
- spelling;
- translation of non-sensitive text;
- code autocomplete in sandbox;
- internal summarisation.
MODERATE
Examples:
- Customer project drafting;
- support assistant;
- generated marketing material;
- file/document analysis.
HIGH
Examples:
- security-agent tool use;
- production code deployment;
- processing confidential Customer datasets;
- autonomous external actions.
PROHIBITED / SEPARATE LEGAL GATE
Examples:
- Article 5 prohibited practices;
- non-consensual intimate generation;
- synthetic CSAM;
- significant employment/credit/insurance/health decisions;
- biometric/emotion features;
- high-risk AI use without classification and compliance review.
Effective / review date: 29 August 2026