Cogrion develops and provides AI-enabled features intended to help customers operate, understand and improve data and infrastructure workflows. This Policy describes the principles Cogrion applies to those features and the responsibilities shared with customers. It does not guarantee that an AI output will be accurate, complete or suitable for a particular decision.
This Policy is a statement of general approach, not a warranty, service level, professional opinion or assumption of responsibility for Customer’s AI use. The MCSA, Order and AUP govern. Customer bears responsibility for selecting models, providing lawful inputs, validating outputs, maintaining human oversight and complying with laws and provider restrictions applicable to Customer.
1. Human accountability
AI assists people; it does not replace accountable human judgment. Customers should apply review and approval appropriate to the impact of an output, particularly before implementing code, changing production systems, taking security action or making decisions about individuals.
2. Lawful and authorised data use
Cogrion processes Customer inputs and outputs to provide the contracted Services and in accordance with the Agreement and DPA. Customer is responsible for having the rights and lawful basis required for data submitted to AI features and for configuring access appropriately.
3. Model training
Cogrion will not use Customer Data to train general-purpose models for other customers without Customer’s express permission. Where a third-party model provider processes prompts or outputs, the applicable provider and processing terms will be disclosed through the Agreement, Order or Documentation, as appropriate.
4. Security and privacy by design
- Apply access controls and data-handling measures appropriate to the deployment model.
- Limit collection and retention to what is reasonably necessary for the relevant function, security and contractual obligations.
- Use testing and monitoring appropriate to material AI risks and the maturity of the feature.
- Provide configuration, documentation or contractual controls that help customers manage data and model-provider choices where available.
5. Quality, transparency and limitations
AI outputs may be probabilistic, incomplete, biased or incorrect. Cogrion will provide reasonable information about the intended function and material limitations of generally available AI features. Customers must validate outputs for their use case, maintain appropriate testing and avoid treating generated content as professional, legal, medical, financial or safety advice.
6. Fairness and non-discrimination
Cogrion seeks to identify and mitigate material unfair bias in AI features within its control using risk-appropriate design, evaluation and review. Customers must not use the Services to discriminate unlawfully or to make high-impact decisions about individuals without lawful safeguards, meaningful human oversight and appropriate avenues for review.
7. Safety and misuse prevention
Cogrion may use technical and operational safeguards intended to reduce abusive, unsafe or unauthorised use. Customers and users must comply with the Acceptable Use Policy and must not bypass safety controls. Cogrion may restrict affected use when reasonably necessary to prevent imminent material harm or protect security, subject to the Agreement.
8. Customer responsibility
- Select appropriate models, settings, permissions and data for the intended use.
- Evaluate outputs for accuracy, security, intellectual-property, privacy and regulatory risk.
- Maintain human review and change controls before production action.
- Monitor deployed use and report suspected harmful, insecure or materially incorrect behaviour.
- Provide notices, explanations and appeal mechanisms where required for decisions affecting individuals.
Customer remains responsible for evaluating whether each selected AI model is appropriate and legally available for Customer’s location, industry, data and intended use. Cogrion does not control the availability, performance, terms, outputs or regulatory status of third-party models selected or accessed by Customer.
AI-generated outputs may be inaccurate, incomplete or unsuitable for a particular purpose. Customer is responsible for applying appropriate human review before relying on outputs or using them to make decisions.
9. Third-party models
AI features may interoperate with third-party models chosen by Cogrion or Customer. Model providers may have separate terms, territorial availability, sanctions and export-control restrictions, industry limitations, data-location rules, retention settings and technical limitations.
Customer is responsible for determining whether it and its authorised users may lawfully access and use a selected model in every relevant country, territory and regulated sector, and for obtaining and maintaining required provider accounts, licences, consents and governmental approvals. A model’s appearance in the Services, Documentation, AI Gateway or routing catalogue does not mean that Cogrion has determined that the model is lawful, available, licensed or suitable for Customer’s location, data or use case.
Where Customer supplies or selects the model-provider account, endpoint or credentials, the relationship with that provider is governed by Customer’s provider agreement. Cogrion does not control and is not responsible for the provider’s model, availability, output, policy enforcement or processing practices except to the extent expressly assumed by Cogrion in the applicable Order. Cogrion remains responsible for its own obligations under the Agreement and applicable law.
10. Reporting concerns
Suspected security vulnerabilities affecting the Cogrion platform may be reported toadmin@cogrion.com. Submission of a report does not create any entitlement to payment, reward or other compensation unless Cogrion has expressly agreed otherwise in writing.
Other concerns about harmful or inappropriate AI behaviour may be reported toadmin@cogrion.com. Reports should include enough information to reproduce and assess the issue without including unnecessary sensitive data.
11. Governance and updates
Cogrion will review this Policy periodically as technology, law and industry practice evolve. We may update it with a revised effective date. Contractual commitments for a current Order change only as permitted by the Agreement.