# AI policy: what software may do on our behalf

## Scope

Applies to every tool that generates, recommends or executes using AI, whether bought or built.

## Principles

1. A human is accountable for every action; an agent acts within limits set by that human.
2. No decision affecting a person's rights, pay or employment is automated without review.
3. Company data is shared with a model only under a contract that excludes training on it, unless approved by <role>.

## Autonomy levels and approvals

| Level | Example | Approval required |
| --- | --- | --- |
| Assistance (drafts, summaries) | Draft a supplier email | none |
| Copilot (recommendations) | Suggest a supplier for an event | user accepts |
| Action (single action) | Send an RFQ | user approves each action |
| Workflow (multi-step) | Run an event to award recommendation | owner approves the workflow, reviews the result |
| Autonomous (within rules) | Award under <threshold> | policy owner approves the rules, audit monthly |

## Records

Every action by an agent is logged with input, output, time and the account it acted for. Logs are retained for <period>.

## Review

Policy reviewed <interval>; incidents reported to <role> within <hours>.
