Skip to content

Legal

AI usage policy

  • Home
  • Legal
  • AI usage policy

Last updated 5 September 2026

Why this policy exists

Most AI procurement questions come down to one sentence nobody can produce: which model saw what, and where did it run? This policy is our standing answer, and a version of it goes into every contract that involves AI.

What we name in every contract

  1. The models used, by name and version, and which part of the workflow each one handles.
  2. Where each model runs, and which jurisdiction that puts the processing in.
  3. What a human reviews before anything is published, sent, posted or filed.
  4. How you are told when an AI system produced an output that reaches your customers.

Autonomy

Agents start in a human review queue: they draft, a person approves. Autonomy expands only when the agent clears a score agreed in advance on an evaluation set of 50–200 real examples drawn from your own records. Autonomy can be withdrawn the same way, and is, when scores drop.

Every agent has prohibited actions, spend limits and escalation triggers defined before it runs. Typical prohibitions include quoting prices, making legal or clinical determinations, issuing refunds above a threshold, and contacting anyone who has opted out.

Data

Client data is used to run and improve the client's own agents and for nothing else. We do not use client data to train models for other clients, and we do not permit our model providers to train on it — enterprise API terms with training disabled are the default.

Where data residency is required, retrieval and personal data stay in region on Azure UAE or AWS UAE/Bahrain, and any frontier model is used only over redacted content. The split is written into the contract.

Our own use of AI

We use AI in our own work: drafting, research, code assistance and analysis. Anything that reaches a client or a client's customer is reviewed by the person whose name is on it. We do not publish generated content without a human editor, and we do not present generated work as hand-made.

What we will not do

  • Build an agent that makes a decision about a person without a route to a human.
  • Ship an agent without an evaluation set.
  • Deploy a model we cannot name in the contract.
  • Use a client's data to benefit another client.
  • Build something whose value we cannot estimate, however interesting it is.

What an agent is not

An agent we build is a tool that carries out a defined task under defined limits. It is not a professional adviser, and its output is not legal, financial, medical, regulatory or tax advice, however confidently it is phrased.

Language models produce plausible text. Plausible is not the same as correct. Every agent we deploy is scoped, evaluated and bounded on that assumption, which is why a human sits in the loop until the evaluation scores say otherwise — and why some decisions never leave the loop at all.

Accuracy, and who is responsible for it

We are responsible for building an agent that meets the specification and the evaluation threshold agreed before it goes live, and for the guardrails around it.

The client remains responsible for what their business publishes, sends or decides. Where an agent drafts and a person approves, the approval is the point at which responsibility passes. Where an agent has earned autonomy on a defined task, the scope of that autonomy is recorded in writing and reviewed at every quarterly review.

We do not warrant that any AI output will be accurate, complete or fit for a particular purpose, and we exclude liability for decisions taken on the basis of an output that was not reviewed as the engagement required.

Ownership of what an agent produces

Prompts, agent configurations, evaluation sets, integration code and the outputs an agent generates for you are yours, on the terms in the client agreement.

The legal position on copyright in machine-generated material is unsettled in both the UK and the UAE, and differs between them. We do not warrant that any AI-generated output is protectable, original, or free of third-party rights. Where output will be published, used commercially or relied on, it must be reviewed by a person, and we will say so in the statement of work.

Model providers

We contract with model providers on enterprise terms with training on customer data disabled by default, and we pass the relevant obligations through to the client agreement.

Providers change their models, terms, availability and pricing. Where a change materially affects an agent we run for you, we will tell you, set out the options and agree the response before acting. We are not liable for a provider's own outage, deprecation or price change.

Raising a concern

If you think an agent we built has behaved badly, email hello@1ree.com. We will pull its autonomy back to draft-only while we look, which usually takes hours rather than days because the logs make it answerable.


Questions about anything on this page: hello@1ree.com.

back top