Digital Consulting Plus uses and develops solutions that may incorporate artificial intelligence (“AI”). This Policy establishes public principles to guide the responsible design, deployment, and use of AI within DCP services, products, and processes. This Policy complements our Terms and Conditions, Privacy Policy, and project-specific agreements.
This Policy may apply to:
- internal assistants used by DCP team members;
- AI features incorporated into client software solutions;
- automations and workflows powered by AI models;
- assisted classification, summarization, or analytical tasks;
- synthetic content generation;
- conversational agents and copilots;
- retrieval-augmented generation (RAG) and assisted search;
- AI solutions integrated into proprietary DCP products;
- utilization of third-party foundational and specialized models.
AI supports our teams; final decisions remain human whenever the nature or impact of the decision requires it. DCP strives not to unthinkingly delegate to an AI system decisions that have a material impact on fundamental rights, physical safety, legal contracting, access to services, employment, health, credit, or other sensitive domains. Where a use case entails significant consequences, an appropriate level of human review and accountable oversight must be defined.
DCP strives to provide clear notice when an individual interacts directly with an AI system in contexts where this is not reasonably obvious or where applicable legislation mandates disclosure. When DCP generates synthetic media or automated content that requires identification or labeling under applicable regulations, appropriate technical markers and disclosure notices will be implemented.
AI systems can generate errors, overlook essential context, output inaccurate data, or produce plausible-sounding yet factually incorrect responses (hallucinations). Consequently:
- outputs must be validated prior to reliance for material decisions;
- DCP never presents AI systems as infallible sources of truth;
- users and operators must verify critical data before acting upon it;
- solutions must incorporate verification safeguards proportionate to the identified risk.
DCP enforces data minimization principles, limiting information provided to AI models to what is strictly necessary for the authorized purpose. Trade secrets, authentication credentials, highly sensitive data, or unnecessary personal data must not be intentionally entered into AI systems that have not undergone security evaluation and authorization for such processing. Personal data processing via AI remains strictly subject to our Privacy Policy, client contracts, and applicable privacy laws.
DCP may leverage third-party foundation models, hosted inference endpoints, and specialized AI infrastructure. Prior to onboarding an external provider in a material enterprise context, DCP strives to evaluate relevant parameters, including:
- terms of service and licensing;
- privacy commitments and data protection practices;
- data processing agreements and security certifications;
- enterprise governance controls and data segregation;
- security posture and incident handling;
- data retention schedules and telemetry policies;
- geographical location and international data transfer safeguards;
- the ability to opt out of or disable model training using client or organizational data, whenever available and required.
Users of AI solutions must respect copyrights, trademarks, trade secrets, software licenses, and other third-party intellectual property rights. DCP does not guarantee that every AI-generated output is unique or eligible for exclusive legal protection. Where AI-generated materials are utilized in public or commercial contexts, prior human review and validation is strongly recommended.
DCP strives to prevent the use of AI systems to perpetuate unlawful discrimination, systemic bias, or arbitrary disparate treatment based on protected personal characteristics. Deployments involving profiling, automated classification of natural persons, or decisions with legal or similarly significant effects require heightened evaluation and review before release into production.
AI implementations must account for emerging security risks, including: prompt injection attacks, secret exposure, unauthorized data extraction, automated tool abuse, unintended remote execution, generation of dangerous content, and over-reliance on unverified automated outputs. Tool invocation capabilities, database access levels, and autonomous actions must be constrained in accordance with necessity and threat models.
Connecting an AI model to external tools, transactional systems, databases, or autonomous actions must adhere to the principle of least privilege. Where an autonomous action can generate material financial, operational, or legal consequences, DCP strives to incorporate robust safeguards such as: explicit human-in-the-loop approval, strict allowlists, granular scope boundaries, immutable audit logs, deterministic validation layers, and automated rollback mechanisms where technically feasible.
It is strictly prohibited to utilize AI solutions provided or developed by DCP to:
- commit crimes, facilitate fraudulent schemes, or engage in deceptive conduct;
- conduct phishing, social engineering, impersonation, or identity theft;
- gain unauthorized access to digital systems, networks, or databases;
- deliberately generate, distribute, or optimize malicious software (malware);
- infringe upon third-party intellectual property or privacy rights;
- harass, defame, discriminate against, or unlawfully stalk individuals;
- manipulate individuals in a deceptive manner intended or likely to cause significant physical, psychological, or financial harm;
- bypass, disable, or tamper with security controls and guardrails;
- process personal data without a lawful legal basis;
- conduct activities expressly prohibited by applicable laws and regulations.
DCP does not automatically treat an AI solution as suitable for high-impact or safety-critical domains merely because it can be technically executed. Prior to implementing AI in areas such as employment screening, critical infrastructure management, credit evaluation, biometric identification, academic evaluation, healthcare diagnostics, physical security, or other heavily regulated sectors, a dedicated risk assessment, legal review, and tailored control framework must be conducted.
DCP strives to ensure that individuals operating AI systems on behalf of the company possess sufficient skills and competence to comprehend: functional capabilities, technical limitations, systemic risks, underlying data sources, human review obligations, and escalation workflows.
Where risk profiles or contractual commitments warrant it, DCP may maintain operational logs regarding: the specific models or systems deployed, versioning and upstream providers, relevant system prompts and configurations, operational data sources, actions executed by autonomous tools, human approvals recorded, and any reported anomalies and security incidents.
DCP may periodically review deployed AI systems to detect: upstream provider modifications, model drift or quality degradation, emerging technical vulnerabilities, evolving statutory requirements, operational incidents, and architectural optimization opportunities.
When DCP implements or configures an AI solution for a client, the client remains solely responsible for: operating the system strictly within the agreed contractual scope, supplying data that has been lawfully obtained, provisioning authorized user access, enforcing internal governance controls, complying with sector-specific legal obligations, validating outputs prior to business reliance, and enforcing prohibitions against improper use.
Specific statutory obligations vary according to jurisdiction, DCP's operational role, model typology, and business use cases. For solutions deployed or accessed within the European Union, DCP will evaluate, as applicable, the requirements established under the European Union Artificial Intelligence Act (EU AI Act), including AI literacy standards, transparency obligations, and rules applicable to synthetic media and designated risk tiers. The existence of this Policy does not imply that every DCP solution is classified as high-risk or that all statutory provisions apply automatically across all implementations.
Users, clients, and interested parties may report unexpected model behavior, safety concerns, potential biases, or security vulnerabilities by contacting info@digitalconsultingplus.com with the suggested subject line: “Responsible AI / IA responsable”.
DCP reserves the right to update this Policy periodically to reflect technological advances, regulatory changes, and evolving industry standards.
