AI runs through almost everything we do: supervised agents in our engineering and research, AI features we build for clients, the UI4AI access layer, and our agent products. This policy sets out the commitments that apply to all of it. Our short version is the one on our About page: agents do volume, people carry consequence, and anything that matters has a name against it.
Scope
This policy applies to everyone who works for or with Rothian, to AI tools we use internally, to AI systems we design, build or operate for clients, and to our own AI products and published content.
Principles
1. Human accountability. Every AI system and every AI-assisted deliverable has a named human owner. AI can draft, analyse and act within limits; a person approves anything consequential and is accountable for the result.
2. Fit for purpose, proven by evaluation. We do not ship AI on the strength of a demo. Systems are evaluated against realistic cases and agreed thresholds before release, and monitored for drift and regressions afterwards.
3. Transparency. People should know when they are dealing with AI. We disclose AI interaction and AI-generated content where it matters to the reader or user, meet the transparency duties of the EU AI Act where they apply, and label AI-assisted Insights on our own site.
4. Privacy and confidentiality. Client and personal data is used only with a lawful basis and within the client’s instructions. We use AI services under terms that prevent our or our clients’ data being used to train models, and we never put client data into consumer AI tools.
5. Security. AI systems are threat-modelled and tested against prompt injection, data leakage and excessive agency, following the OWASP guidance for LLM applications. Agents get least-privilege access, their actions are logged, and high-impact actions need human approval.
6. Fairness. Where AI affects decisions about people — hiring, credit, access to services — we assess the risk of bias, test for it, and design in human review and a route to challenge the outcome.
7. Proportionate governance. We classify AI use cases by risk, apply heavier controls to higher-risk systems, and align our governance with ISO/IEC 42001 and applicable law, including the EU AI Act and UK data protection law.
8. Quality of what we write. AI-generated code passes the same review, testing and security gates as human-written code. AI-assisted content is fact-checked against its sources before publication, and every factual claim can be traced to one.
What we will not do
- Build systems intended to deceive people about whether they are dealing with a human.
- Build AI for practices prohibited under the EU AI Act, such as social scoring or manipulative techniques that cause harm.
- Deploy an autonomous agent with authority to take irreversible, high-impact actions without human approval.
- Represent AI-generated content as the personal work of a named individual who did not review it.
Our AI-assisted Insights
Some pieces in Insights are drafted with AI assistance each week. The model is directed to recent, credible external sources, which are always credited and linked. Each piece is labelled, and the analysis reflects Rothian’s positions. If you spot an error, tell us at info@rothian.com and we will correct it promptly.
Responsibility and review
A director is accountable for this policy. We maintain a register of AI tools and client AI systems we operate, review this policy every six months given the pace of change, and train our people on responsible AI use as part of induction and annually.