1. Purpose and Scope
This policy defines how CivAll governs artificial intelligence and machine learning ("AI") capabilities embedded in the CivAll Platform and CivAll products delivered to customers. It applies to all CivAll employees and contractors involved in developing, operating, or introducing AI capabilities.
2. Governance and Accountability
Accountability for AI governance follows the same structure as CivAll's broader security program, formalized in the CivAll Security & Privacy Roles and Responsibilities Policy:
- The Chief Executive Officer, acting as Security Delegate, owns this policy and approves the adoption of any AI capability in CivAll products. CivAll is supported by a third-party vCISO advisory engagement.
- The Head of Development is responsible for the technical implementation and operation of AI capabilities in the platform, including vendor configuration, data flows, and monitoring, and maintains the AI Capability Disclosure described in Section 6.
This policy is reviewed at least annually and whenever an AI capability is introduced into, materially changed in, or retired from the platform.
3. Principles
- Human control. AI assists the people who use the platform; it does not act for them. Capabilities that generate content present their output to an authorized user as an editable draft, labeled as AI-generated where it appears, and never publish or send anything without a human action. Capabilities that analyze content produce labels or scores for the user's information and take no action on their own. Customers control which AI capabilities are enabled for their organization: content-generating capabilities can be turned off for an organization, and analytic capabilities offered as add-ons are enabled only at the customer's request.
- No decisions about individuals. The platform's AI capabilities make no automated decisions with legal or similarly significant effect on any person. They are not used to identify individuals, to infer protected characteristics, to profile members of the public who communicate with a customer, or to make eligibility, enforcement, or law-enforcement decisions.
- No model training on customer data. Customer data is not used to train AI or machine learning models, by CivAll or by CivAll's AI infrastructure providers.
- Data protection first. AI processing occurs within CivAll's secured cloud environment and inherits the same encryption, access control, and monitoring as the rest of the platform.
- Transparency. AI capabilities are labeled in the product where their output appears, described in CivAll's product documentation, disclosed to customers contractually, and detailed for customers in the AI Capability Disclosure described in Section 6.
- Vendor accountability. Any provider of AI capability is evaluated and monitored under CivAll's Vendor Management Policy before use.
4. AI in the CivAll Platform
CivAll's AI capabilities run on foundation models hosted by Amazon Web Services and invoked through AWS Bedrock from CivAll's own U.S.-based AWS environment. This design has three properties relevant to customer security review:
- Data stays within the AWS boundary. Inference is performed by the AWS-managed Bedrock service, invoked from resources in CivAll's own AWS account; customer data is not transmitted to external or consumer AI services by the platform.
- No training on customer content. AWS Bedrock does not use customer content to train or improve models, and content submitted for inference is not shared with third-party model providers.
- Standard platform protections apply. Data processed by AI features is encrypted in transit (TLS) and at rest (AWS KMS), and access is controlled by the same least-privilege network and IAM controls as the rest of the platform.
As of the last-updated date, AI in the CivAll Platform is limited to the following capabilities:
- Semantic search. Matches search queries to platform content by meaning as well as by keyword. Produces no content.
- Image description drafts (CivSocial). Drafts a short description of an image the user has uploaded, to support accessibility. The draft is labeled, fully editable, and published only by the customer.
- Inbox sentiment analysis (CivSocial, optional add-on). Labels the tone of inbound messages so that a customer's team can prioritize its own inbox. Descriptive only; takes no action.
The platform makes no automated decisions with legal or similarly significant effect on individuals. AI is not used for law-enforcement decision-making, biometric identification, or the surveillance of individuals.
5. Contractual Commitments to Customers
CivAll's AI commitments are not statements of intent; they are binding terms of CivAll's customer agreements, including the published CivAll Terms of Service. Those terms require human review of AI-generated content before publication, prohibit the use of Customer Data or Citizen Data to train artificial intelligence or machine learning models, and leave the customer in control of content created with AI assistance.
6. Customer Disclosure
Content that a customer publishes with the assistance of an AI capability is the customer's content. CivAll labels AI output inside the product at the point it appears so that authorized users know its origin, and does not attach AI markers to content the customer chooses to publish. Customers that do not wish to use an AI capability can have it turned off for their organization.
CivAll maintains an AI Capability Disclosure describing each AI capability in the platform: its purpose, the data it processes, where inference occurs, the human controls around its output, and confirmation that it makes no automated decisions about individuals. The disclosure is written to support customers' own AI governance, vendor-management, and inventory obligations. It is available to customers and prospective customers on request through the CivAll Trust Center, under the confidentiality terms of the requesting organization's agreement with CivAll.
7. Introducing or Changing AI Capabilities
Before any AI capability is introduced into the platform, or the model behind an existing capability is changed, CivAll requires:
- Vendor and model review. The AI provider and model are evaluated under the Vendor Management Policy, including the provider's data-use, retention, and training practices. Providers that train on customer data are not eligible to process customer data.
- Data-flow review. The Head of Development documents what data classes the capability processes, where inference occurs, and how the data is protected, consistent with the Data Classification and Data Protection policies.
- Human-control design. Capabilities that generate content must present output to an authorized user as an editable, labeled draft and must not publish without a human action. Capabilities that analyze content must be limited to informational output and must not act on it.
- CEO approval and disclosure. The CEO approves the capability. The AI Capability Disclosure, this policy, product documentation, and, where applicable, the Terms of Service and sub-processor list are updated before general availability.
8. Security Foundation
AI governance operates on top of CivAll's information security program, which is aligned with SOC 2 Type II: annual third-party penetration testing, continuous compliance monitoring, encryption in transit and at rest, least-privilege access with quarterly access reviews, and a documented Incident Response Plan. AI features receive no exemption from these controls.
9. Standards and Regulatory Monitoring
CivAll monitors developing AI governance standards and regulation, including the NIST AI Risk Management Framework, ISO/IEC 42001, and state and federal legislation governing the use of AI by public-sector bodies and their vendors, and will evolve this policy as those standards mature and as the platform's AI capabilities grow.
Reviewed at least annually and upon introduction or material change of any AI capability. This policy is supported by the Security & Privacy Roles and Responsibilities Policy, Vendor Management Policy, Data Classification Policy, Data Protection Policy, and Incident Response Plan.