Responsible AI Policy
The principles that govern how QAISG designs, evaluates, deploys, and uses artificial intelligence.
Purpose
Quantum AI Strategy Group LLC (“QAISG,” “we,” “us,” or “our”) develops and uses artificial intelligence technologies across software products, research, analysis, advisory services, and internal business operations.
This Responsible AI Policy defines the principles that govern how QAISG designs, evaluates, deploys, and uses AI.
Our objective is to use AI in ways that are secure, transparent, accountable, privacy-conscious, and appropriate to the context in which it is applied.
Our principles
QAISG’s approach to artificial intelligence is based on the following principles:
- Human accountability: AI may assist analysis and decision-making, but responsibility remains with people.
- Transparency: We seek to make the role of AI understandable where it materially affects a product, service, analysis, or customer outcome.
- Data minimization: AI systems should receive only the information reasonably necessary to perform the intended function.
- Security and privacy by design: AI capabilities are evaluated for security, privacy, confidentiality, and data-governance risks before and during use.
- Purpose limitation: Information provided for one purpose should not be repurposed for unrelated AI use without appropriate authorization.
- Governed use: AI tools and models should be used within defined technical, business, legal, and ethical boundaries.
- Evidence over assumption: Where possible, AI-supported conclusions should be grounded in available evidence and should not represent uncertainty as fact.
- Proportionality: The level of oversight, validation, and control should increase with the potential impact of the AI-enabled activity.
Human oversight and accountability
QAISG does not treat AI systems as independent decision authorities.
AI may assist with activities such as:
- Analysis.
- Classification.
- Summarization.
- Research.
- Reporting.
- Software development.
- Security and governance analysis.
- Identification of patterns or anomalies.
- Generation of recommendations or draft content.
Material business, security, compliance, legal, customer, or operational decisions remain subject to appropriate human judgment and accountability.
Where AI outputs may materially influence a decision, users are expected to consider the reliability, context, limitations, and supporting evidence associated with those outputs.
AI-generated and AI-assisted outputs
AI-generated or AI-assisted outputs may contain errors, omissions, incomplete information, or incorrect conclusions.
QAISG does not assume that an AI-generated output is accurate solely because it was produced by an advanced model.
Appropriate validation may include:
- Comparison against authoritative information.
- Review of underlying evidence.
- Human review.
- Technical testing.
- Independent verification.
- Use of deterministic controls where appropriate.
AI outputs should not be represented as verified facts, compliance determinations, legal conclusions, security findings, or authoritative decisions unless they have been appropriately validated.
Customer data and AI systems
QAISG applies data-minimization and purpose-limitation principles when customer information may interact with artificial-intelligence systems.
Customer information is not used to train publicly available AI models unless that use has been expressly disclosed and authorized.
Where third-party AI providers are used to support QAISG functionality, QAISG seeks to limit the information transmitted to what is reasonably necessary for the applicable function.
Product architectures should avoid transmitting sensitive customer information to AI services where the functionality can reasonably be delivered using metadata, derived values, anonymized information, deterministic processing, or other less sensitive data.
Product-specific documentation may provide additional information regarding how a particular QAISG service uses artificial intelligence.
Sensitive and confidential information
Employees, contractors, and other authorized users must exercise appropriate care before submitting confidential, proprietary, regulated, personal, or customer information to an AI system.
Information should not be provided to an AI service unless:
- Its use is necessary for an authorized business purpose.
- The AI service has been approved for that type of information.
- Appropriate contractual and security protections are in place.
- The information provided is limited to what is reasonably necessary.
- The use complies with applicable customer, legal, privacy, and contractual requirements.
Where possible, sensitive information should be removed, masked, generalized, or minimized before AI processing.
Internal use of AI
QAISG permits responsible use of approved AI tools for legitimate business purposes.
Examples may include:
- Research and analysis.
- Drafting and editing.
- Software development.
- Product design.
- Documentation.
- Threat and technology analysis.
- Business planning.
- Customer-support activities.
- Administrative tasks.
AI use does not remove the user’s responsibility for reviewing the resulting work.
Users remain responsible for the accuracy, appropriateness, security, confidentiality, and professional quality of work produced with AI assistance.
Software development and AI-assisted coding
AI-assisted software-development tools may be used to support QAISG engineering activities when appropriately governed.
Code generated or modified with AI assistance must be treated as untrusted until reviewed and validated.
Appropriate controls may include:
- Human code review.
- Automated testing.
- Security testing.
- Dependency review.
- Static or dynamic analysis.
- Verification of licensing or intellectual-property concerns where applicable.
- Validation before production deployment.
AI-generated code does not bypass QAISG’s normal software-development, testing, security, or deployment controls.
AI model and service selection
QAISG considers security, privacy, reliability, contractual protections, data-handling practices, and technical suitability when selecting AI models and providers.
Evaluation factors may include:
- Whether provider data is used for model training.
- Data-retention practices.
- Security controls.
- Privacy commitments.
- Hosting and processing locations.
- Contractual protections.
- Model capabilities and limitations.
- Availability and operational resilience.
- Suitability for the intended use case.
Different AI providers or models may be approved for different categories of information or business activity.
AI within QAISG products
AI functionality incorporated into QAISG products should be designed with appropriate governance controls.
Depending on the product and use case, these may include:
- Clear identification of AI-assisted functionality.
- Human review or approval.
- Deterministic validation.
- Audit trails.
- Role-based controls.
- Data minimization.
- Model or provider restrictions.
- Tenant isolation.
- Logging of relevant AI-assisted activity.
- Ability to disable or limit optional AI functionality.
- Separation of customer data from shared reference information.
The use of AI should not undermine the security, privacy, tenant isolation, or governance controls of the underlying platform.
Evidence, uncertainty, and explainability
QAISG seeks to distinguish observed facts from AI-generated interpretation.
Where an AI system is used to interpret security, governance, compliance, operational, or technology information, the resulting output should not imply a level of certainty that the available evidence does not support.
Where practical, users should be able to understand:
- What information contributed to an AI-assisted conclusion.
- Whether the result is deterministic or model-generated.
- Material assumptions or limitations.
- Whether additional human investigation is appropriate.
QAISG favors evidence-based reporting over unsupported inference.
Automated decisions
QAISG does not intend its AI systems to make autonomous high-impact decisions about individuals without appropriate human oversight and lawful authorization.
Where AI assists with decisions that may materially affect a person, organization, security posture, compliance determination, or customer environment, appropriate review and governance should be applied based on the nature and potential impact of the decision.
Fairness and appropriate use
QAISG seeks to avoid uses of AI that unlawfully discriminate against individuals or create inappropriate adverse consequences.
AI systems should not be used to make prohibited decisions based on protected characteristics or other information where such use would be unlawful or inconsistent with applicable policy.
Where an AI use case presents material fairness, bias, or individual-impact concerns, additional review should occur before deployment.
Security and adversarial risk
AI systems introduce security risks that may differ from traditional software systems.
QAISG considers risks such as:
- Prompt injection.
- Data leakage.
- Unauthorized model access.
- Malicious or manipulated inputs.
- Model or dependency compromise.
- Insecure AI-generated code.
- Excessive permissions granted to AI agents.
- Unauthorized tool execution.
- Supply-chain risks associated with models, libraries, and AI services.
Controls should be proportionate to the capabilities and potential impact of the applicable AI system.
AI agents and automated actions
AI systems capable of taking actions, invoking tools, modifying systems, or interacting with other services require additional safeguards.
Where agentic functionality is used, appropriate controls may include:
- Defined scopes and permissions.
- Least-privilege access.
- Human approval for material actions.
- Logging and traceability.
- Limits on external system access.
- Ability to stop, revoke, or contain automated activity.
- Testing before production use.
- Monitoring of agent-to-tool and agent-to-agent activity where appropriate.
The level of autonomy granted to an AI system should reflect the potential impact of its actions.
Legal and regulatory considerations
QAISG evaluates AI use in light of applicable laws, regulations, contractual requirements, industry standards, and customer obligations.
The regulatory environment for artificial intelligence continues to evolve.
QAISG will adapt its governance practices as appropriate to changes in applicable requirements and recognized AI-governance frameworks.
Compliance with a framework or regulation is not assumed solely because AI controls exist; applicability and compliance must be evaluated in context.
Training and awareness
Personnel who use AI in their work are expected to understand the limitations and risks associated with AI-assisted activities.
QAISG may provide guidance, training, technical controls, or approved-tool standards appropriate to the nature of the work being performed.
Users should understand that AI can generate plausible but incorrect information and should apply professional judgment appropriate to their role.
Reporting concerns
Security, privacy, ethical, or governance concerns involving AI should be reported promptly.
Concerns may include:
- Potential exposure of customer or confidential information.
- Unsafe or inappropriate AI behavior.
- Unauthorized AI use.
- Incorrect or misleading AI-generated findings.
- Security vulnerabilities involving AI functionality.
- Suspected violation of this policy.
Security-related concerns may be reported to security@qaisg.com.
Privacy-related concerns may be reported to privacy@qaisg.com.
Other legal or policy questions may be directed to legal@qaisg.com.
Governance and review
QAISG will periodically review its use of artificial intelligence, approved tools, providers, product capabilities, and associated risks.
AI governance practices may evolve as technologies, threats, regulations, customer expectations, and industry standards change.
This policy may be supplemented by product-specific requirements, internal procedures, technical standards, customer agreements, or additional governance documentation.
Changes to this policy
QAISG may update this Responsible AI Policy periodically as its products, technologies, business activities, or legal obligations evolve.
Material changes will be reflected in the “Last updated” date above.
Contact
Quantum AI Strategy Group LLC
Email: legal@qaisg.com
Website: qaisg.com