← Back to home

How we use AI

AI Use Policy · Last updated September 29, 2026

We help organizations prove their AI controls are real, not just written down. So we hold ourselves to the same test. These are the rules for every AI system The Agility Doctor runs, and each one is backed by a control we can show you on request. How we handle diagnostic data specifically is covered in How we handle your data.

Our rules

  1. A person approves everything that leaves. No AI output reaches a client, and nothing is posted or sent under our name, until a person has reviewed and approved it. Diagnostic reports stay drafts until signed off, and the system that would let them skip review is locked behind a second switch that we monitor.
  2. We never train AI on client data. Not our own models and not anyone else’s. We use AI models through commercial services whose terms do not allow our data or yours to be used for training.
  3. AI only sees the data it needs. Diagnostics work from your answers and computed delivery metrics. Raw tracker exports never reach our servers, and ticket text, comments and assignee names are never kept.
  4. Every AI system is on a register. For each one we record its purpose, the data it uses, the model behind it, the person who approves its output, the ways it is known to fail, and a risk tier. A system is added before it goes live, not after.
  5. Controls are checked by machines, not memory. Automated checks run every hour, every day and before every release of this site. Planted test cases prove each control still works. If one stops working, for example a report going out without sign-off or client data kept past its limit, we are alerted within the hour and a broken release does not ship.
  6. No AI makes decisions about people. We do not use AI to make or recommend decisions about hiring, performance, pay, credit or anything else with a significant effect on an individual.
  7. We tell you where AI is involved. This page lists every place we use it. If that changes, this page changes first.

Where we use AI

Diagnostic report draftingHigh risk

Data: Your diagnostic answers and computed delivery metrics. Client confidential.

Oversight: A person reviews and approves every report before you see it. Data deleted 12 months after delivery, or within 7 days on request.

Marketing draftsLimited risk

Data: Our own brand material and public information. No client data.

Oversight: A person reviews every post before it is published.

Buyer and market researchLimited risk

Data: Public business information: company news, open roles, industry events, and the names and roles of people who publicly represent their companies.

Oversight: A person approves every contact. The AI never messages, emails or connects with anyone on its own. Ask us and we will remove anything we hold about you.

Security and governance operationsHigh risk

Data: Our own systems and configuration, which include the client data above.

Oversight: An AI agent audits our systems and proposes fixes. Changes that touch client data need a person’s approval first. Every change is logged with a way to roll it back.

Risk tiers follow the impact on people if the system gets something wrong. High risk systems get the strictest oversight and are checked every hour.

Models and providers

Our AI systems run on Claude models from Anthropic, used through Anthropic’s commercial service. Its terms do not allow our inputs or outputs to be used to train their models. Any new model or provider is added to our register and to this page before we use it with client data.

Risks we manage

  • Wrong or overconfident output. AI can state things with more certainty than the data supports. A person checks every output before it is used.
  • Hidden instructions in data. Text inside documents or web pages can try to steer an AI. Our AI outputs stay drafts until approved, so nothing it is tricked into producing can act on its own.
  • Data kept too long or seen by the wrong people. Retention limits, deletion on request and access rules are enforced in our systems, and monitored.

If something goes wrong

If an AI system mishandles client data or sends something that should not have been sent, we stop that system, fix the cause, and tell any affected client within 72 hours of confirming what happened.

Standards and review

This policy and our AI register are structured around ISO/IEC 42001 and the NIST AI Risk Management Framework. We are not certified against either, and we say so plainly. We review this policy at least every six months and whenever we add or change an AI system. Read how we assessed our own AI.

Questions

For a copy of our AI register, evidence of any control on this page, or to ask about data we hold, email transformation@theagilitydoctor.com.

The Agility Doctor

AI Use Policy, version 1.0