Pillars, golden rules and the data sensitivity matrix that governs every approved tool.
Every customer-facing AI output is reviewed by a qualified human before it ships.
We never send PII, financial records, or proprietary code to public models.
If AI helped produce it, we say so — internally and to customers.
Every employee dedicates 1 hour per week to AI literacy. Tracked, not policed.
| Tier | Examples | Allowed tools |
|---|---|---|
Tier 0 · Public | Marketing copy, public blog drafts, press releases | Any approved tool |
Tier 1 · Internal | Internal docs, meeting notes, project plans | Enterprise ChatGPT, Copilot, Claude Enterprise |
Tier 2 · Confidential | Strategy docs, financials, unreleased products | Self-hosted only (Acme GPT, on-prem Llama) |
Tier 3 · Restricted | Customer PII, contracts, source code, M&A | Self-hosted + DPO approval required |
EU AI Act risk classification is mapped automatically per tool. Tier 3 changes require DPO sign-off.