AI use policy
FourWinds Digital · Version 1.1 · 10 September 2026 Owner: Oscar Cobbe · Review due: 2 December 2026
1. Why the review date is early
Two obligations land on 2 December 2026: the new Article 5 prohibitions on generating non-consensual intimate imagery and child sexual abuse material, and the end of the grace period for machine-readable marking of synthetic content on systems that were already on the market. This document is reviewed before then, not annually.
2. What we are under the AI Act
Two roles at once, with different duties:
- Deployer. Using Claude, ChatGPT, Copilot or Gemini in delivery work. This applies from day one and has no size exemption.
- Provider. Shipping a client-facing AI feature under our own name or trademark makes us the provider of that system.
We are not a distributor or a reseller. We do not sell, resell or administer vendor seats, and the section on that is section 10, which records why the role was dropped rather than deleting it silently.
We keep a register of every AI system we touch, the role claimed for each and why. That register is what makes the rest of this document auditable, and it is what a client's procurement team asks for.
3. AI literacy
Article 4 was rewritten on 27 July 2026 by Regulation (EU) 2026/1744. It now requires us to take measures to support the development of AI literacy, and adds expressly that the obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
The previous wording required us to ensure a sufficient level. That is a duty of effort now, not of result, and any template drafted before late July 2026 overstates it.
It binds providers and deployers, covering staff and other people operating AI systems on our behalf, which reaches contractors and freelancers.
There is no fine attached. Article 4 appears nowhere in Article 99. It is enforced through compliance notices, and commercially through client due diligence. We keep a dated training log because that is the deliverable a client asks to see, not because a penalty is coming.
Market surveillance authorities began supervising this on 3 August 2026.
4. What we will not build
Article 5 prohibitions have applied since 2 February 2025 and carry the top tier: €35 million or 7% of worldwide turnover. For an SME the cap is the lower of the two, which is real relief and not immunity.
Four are reachable from ordinary agency work. These are hard stops and none of them is a matter of judgement on a given project:
Emotion inference in the workplace or in education. This is the one most likely to arrive without anyone naming it. A support dashboard that scores "customer frustration", an HR tool reading sentiment in employee messages, an interview tool scoring a candidate's affect. Not high-risk and regulated. Banned. The exception is narrow and medical or safety related. If a brief asks for it, the answer is no, and the reason is given in writing.
Social scoring. A customer or tenant score that imports data from unrelated contexts and produces detrimental or disproportionate treatment. Unlike earlier drafts of the Act, this is not limited to public bodies. Ordinary fraud and credit scoring on relevant, in-context data is fine. The line is the unrelated data and the disproportionate outcome.
Manipulation and exploiting vulnerability. Conversion optimisation that crosses into materially distorting behaviour and causing significant harm, particularly where it targets age, disability or economic situation. Ordinary persuasion and advertising are expressly not caught.
Untargeted scraping of facial images to build or expand a facial recognition database.
From 2 December 2026, generating non-consensual intimate imagery or child sexual abuse material. Note the shape of the provider limb: it bites where such generation is a reasonably foreseeable and reproducible outcome and the system lacks adequate safeguards. If we ship any image generation feature, safeguards must be demonstrable, not a line in the terms of use.
5. When a build makes us a provider
Articles 16, 25 and 26 apply only to high-risk systems, and those were deferred to 2 December 2027 for Annex III and 2 August 2028 for Annex I. So today this is a constraint on what we agree to build, not a live filing duty. It becomes one on those dates for anything already running.
Three routes turn us into the provider of a high-risk system:
- Rebranding. Putting our name on a high-risk system already on the market, unless the contract allocates otherwise. That carve-out is the single most valuable clause available to us and goes in every white-label agreement.
- Substantial modification. A change not foreseen in the original conformity assessment that affects compliance or the assessed purpose.
- Changing the purpose, including of a general-purpose system, so that it becomes high-risk.
The realistic trigger is the third, and it is a business decision rather than a technical one. Running candidate CVs through a general chatbot to screen them converts a general tool into a high-risk employment system and makes us its provider. Any build of that shape needs sign-off before work starts.
Fine-tuning does not make us a provider of a model. The Commission's indicative threshold is training compute exceeding one third of the original model's. Nothing we do with prompts, retrieval or light fine-tuning approaches that. Commentary claiming otherwise conflates the model rules with the system rules.
6. Telling people they are talking to a machine
Article 50 has applied since 2 August 2026. It was not deferred. It sits in the €15 million or 3% tier. As with the Article 5 tier in section 4, Article 99(6) takes whichever of the two is lower for an SME.
- A system that interacts directly with people must make clear it is AI, unless that is obvious. "Obvious" is read narrowly.
- Synthetic audio, image, video or text must be marked in a machine-readable format. Systems already on the market before 2 August 2026 have until 2 December 2026.
- Deepfakes must be disclosed.
- AI-generated text published to inform the public on matters of public interest must be labelled, unless it had human review with a named person holding editorial responsibility. Spell-check does not count as human review.
Who counts as the provider of a chatbot we build for a client is genuinely contested. It turns on whose name it is put into service under, and the Commission's guidelines resolve it by telling the supply chain to allocate it contractually. So every client contract shipping an AI feature states in terms who is provider, who is deployer, and who owns the disclosure and the content marking. We do not rely on the default, because there isn't a reliable one.
Our own marketing writing is mostly outside "public interest matters". Anything touching health, politics, justice, environment or economic developments is not, and gets a named human reviewer, which discharges the obligation cheaply.
7. Automated decisions about people
Any feature that automatically scores, triages, ranks, approves or rejects people engages Article 22 GDPR, and the AI Act's high-risk deferral does not defer it. Article 22 applies now.
Two decisions shape how we build:
- A credit-style score is itself the decision where a third party draws strongly on it. The party generating the score can be the controller, not merely a processor. If we productise a scoring engine across clients, that is us.
- "Meaningful information about the logic" means the procedures and principles actually applied to that decision, in plain language. Neither a formula nor a description of every step satisfies it. The endorsed benchmark is counterfactual: what change in the inputs would have changed the result. Trade secrets do not defeat the right. The material goes to the regulator or the court to balance.
Practically, three things are build requirements rather than policy requirements:
- Retain the per-decision inputs and their contribution, or the explanation cannot be produced later.
- Build the human intervention route. If it is not in the software, the client cannot comply.
- Log override rates. A human reviewer who never changes the outcome is evidence that the decision was solely automated after all.
8. Putting client data into an AI tool
There are four separate exposures here and addressing only one is inadequate.
- Sub-processor authorisation. When we hold client data as a processor, pasting it into an AI tool makes that vendor a sub-processor. That needs the client's written authorisation and back-to-back terms. Using a personal account on client data is an unauthorised sub-processor engagement, not merely bad practice.
- Lawful basis and transparency. The client's privacy notice and record of processing must actually mention AI processing.
- Transfers, where the tier offers no EU processing.
- Confidentiality beyond data protection. Client NDAs, and trade secret status. Information only qualifies as a trade secret if reasonable steps were taken to keep it secret. An enforced AI policy is evidence of reasonable steps; its absence can help defeat the claim, for our own IP and for our clients'.
The rule. Approved tier, signed agreement, and client authorisation where the data is theirs. Anything else is prohibited. No client personal data goes into any consumer or personal-account tier, ever.
Neither the EDPB nor the DPC has published a document squarely on staff pasting client data into chatbots. This section is reasoned from Article 28 and the DPC's July 2024 AI guidance rather than from a citable rule, and is labelled as such.
9. Approved and prohibited tools
The rule names products and tiers, not brands, because the same vendor sells both a processor tier and a consumer tier and the difference is invisible in the interface.
| Approved | Prohibited |
|---|---|
| Claude for Work (Team or Enterprise), Claude API | Any personal Claude account, free or Pro |
| ChatGPT Business, Team, Enterprise, Edu, OpenAI API | Any personal ChatGPT account |
| Microsoft Copilot signed in with the work account | Consumer Copilot, signed-out Copilot, personal-account Copilot |
| Gemini within Google Workspace | Personal Gemini |
Three specifics that catch people:
- Rating a Claude conversation with thumbs up or down pulls the whole conversation into a five-year store. Do not rate a conversation containing client material.
- Microsoft acts as an independent controller for web-grounded queries, not as our processor, and web search sits outside the EU Data Boundary.
- Vendor marketing and vendor contracts differ, and terms move faster than anything else in this document. Each is re-checked before onboarding and at every review.
10. Reselling seats: closed, and how
This was an open item and is now closed, and the history is kept here rather than deleted, because a policy that quietly loses a section reads as though the exposure was never there.
What it said. OpenAI's terms prohibit reselling or leasing account access and transferring API keys, Anthropic's commercial terms bar reselling the services except as expressly approved, and this policy recorded that FourWinds sold managed AI seats against those terms. That was a live contractual exposure with a named owner and a due date.
What changed. The seat product was withdrawn on 2 September 2026. The whole category was deleted from the catalogue, the terms of service were re-versioned to strip the clause that described us administering seats, and the clients who had accepted the old terms were asked again. No client holds a vendor seat through us and none can buy one: the only rows in the seats table are our own platform products.
Where that leaves us. We do not resell, lease or administer any vendor's seats or API keys. A client buys the licence from the vendor on their own account, we make nothing on the choice, and section 9's approved and prohibited tiers are advice about what they should buy rather than a description of anything we sell. If we ever move onto an authorised reseller or partner arrangement, the exposure comes back and this section is rewritten before the first seat is sold, not after.
11. Records we keep
The AI system register. The training log. Screening notes and any DPIA. Vendor due diligence and signed agreements. The contract clauses allocating Article 50 roles. Override rates on any automated decision feature.
12. When something goes wrong
Pasting the wrong material into an AI tool is an incident. If it involved personal data it is a personal data breach and the 72-hour clock starts. Go to the Breach response plan. This is a cross-reference, not an implication.
13. Enforcement in Ireland
Ireland uses a distributed model of roughly 15 sectoral authorities, with a national AI Office as the single point of contact, established 31 July
- For an agency with no specialist sectoral regulator, the Competition
and Consumer Protection Commission is the likely market surveillance authority, and the Data Protection Commission covers the data protection side.
Note that the Irish adjudication machinery is not fully commenced: the Data Protection Commission and Coimisiún na Meán are excluded from the commenced definition of applicable market surveillance authority, pending a further order. Further Irish legislation was flagged for autumn 2026.