Skip to main content

Effective July 2026

AI Disclosure Statement

BuiltAI uses AI as a controlled assistant inside human-reviewed workflows. This statement summarises how AI is used, what data classification applies, and the boundaries we maintain.

1. Where AI runs

AI features run only inside governed, human-reviewed workflows: the public document-critique flow at /prove (which processes only the document a visitor chooses to submit) and the Plant Room workspace, where drafts are produced for a named reviewer to approve before anything is issued. There is no free-form public AI chatbot, and no AI output leaves a workflow without human review.

2. Drafts, not decisions

All AI outputs are labelled as drafts and require human review before they leave the platform. They cannot bypass QA1, QA2 or client approval gates.

3. Data classification

Inputs to AI are classified Green, Amber or Red. Red-classified data is never processed by AI in the MVP. Amber data triggers a source-backed review requirement before output is used. See Governance for the full rules.

4. DPIA template

Procurement teams typically require a Data Protection Impact Assessment before deploying AI workflows. We publish a BuiltAI-specific DPIA starter at /governance/dpia covering engagement context, data flows, lawful basis, risks, mitigations, data subject rights and sign-off - sized for SME procurement, not a substitute for legal advice.

5. Audit logging

Every AI action - task type, input documents, classification, prompt template, model used, output reference and human review status - is logged for audit. Attempted Red-data processing is also logged.

6. What AI does not do

  • It does not provide legal advice.
  • It does not certify engineering design.
  • It does not provide statutory health and safety approval.
  • It does not autonomously triage service desk tickets in production.
  • It does not auto-issue proposals, SOWs, RAMS or board reports.