Ryniqo OÜ · Legal Pack
Legal · Responsible AI

Responsible AI Policy

RynIQ™ assists executive decision making. It never replaces it. This Policy sets out the principles, controls, and accountability arrangements under which we build, evaluate and operate AI components of the Platform, and how we align with the EU AI Act, ISO/IEC 42001:2023, and the NIST AI Risk Management Framework 1.0.

Version2.0EffectiveOn publication
SupersedesGoverning lawEstonia · EU
Section 01

Governing principles

  • Human oversight. A qualified human reviews every formal recommendation before it leaves Ryniqo.
  • No autonomous decisions. No AI output produces legal effects or similarly significant effects without human confirmation.
  • Evidence-based reasoning. Every recommendation traces to structured executive input, not to generative fluency.
  • Executive accountability. The customer's executives remain accountable for the decision. RynIQ provides structure, challenge and documentation.
  • Transparency. We publish what our AI does, what it does not do, and what its limitations are.
  • Data dignity. Customer content is not used to train foundation models.
  • Continuous improvement. We evaluate, log, and improve models against measurable criteria.
Section 02

Human oversight in the loop

The Snapshot is generated by AI and clearly labelled as preliminary. The Executive Decision Brief is produced only after a facilitated Executive Review and is reviewed by a qualified reviewer before delivery. Reviewers may reject or rewrite any part of an AI-drafted section.

Article 14 of the EU AI Act (human oversight of high-risk systems) is a design principle even for uses that are not classified as high-risk under Annex III.

Section 03

AI limitations

  • Models can be confidently wrong; that is why we require human review.
  • Models can reflect biases present in training data or in the inputs they receive.
  • Models cannot reason about facts outside their input, cannot verify claims, and cannot replace subject-matter expertise.
  • Model providers may change models without notice; we monitor and re-evaluate accordingly.
Section 04

Bias mitigation

Bias is addressed at three points: (a) input design — the Executive Decision Snapshot uses closed, comparable questions to reduce free-text bias; (b) processing — prompts and pipelines are versioned and reviewed; and (c) output review — reviewers are trained to challenge unsupported claims, over-confident language and pattern stereotypes.

We do not use protected attributes (as defined by Article 21 of the EU Charter of Fundamental Rights) as decision inputs.

Section 05

Transparency

Every AI-authored section of a Brief is labelled. Customers are told which parts of a deliverable are AI-drafted, which parts are written by a human reviewer, and how Decision Confidence™ is composed at a high level. See the AI Transparency Statement.

Section 06

Model evaluation

  • Pre-deployment: red-team prompts, hallucination checks, refusal-behaviour checks.
  • In production: sampling of Snapshots and Briefs against reviewer judgements.
  • Post-incident: root-cause analysis, prompt/model rollback where indicated.
  • Records of evaluations are retained for the life of the model version plus 24 months.
Section 07

Security of AI components

Prompt and response payloads travel encrypted. Model endpoints require authenticated calls with per-tenant scoping. We use providers contractually committed to zero-retention or short-retention terms, and we do not permit training on our data. Prompt injection and exfiltration risks are mitigated through input sanitisation and output validation.

Section 08

Prohibited use

  • Automated denial of employment, credit, housing, insurance, or public services.
  • Social scoring or biometric categorisation.
  • Any use prohibited under Article 5 of the EU AI Act.
  • Any use that would breach human rights, dignity or non-discrimination laws.
Section 09

Regulatory alignment

  • EU AI Act (Regulation (EU) 2024/1689): we design against Articles 13–15 (transparency, human oversight, accuracy and robustness), monitor Article 5 prohibitions, and track obligations for general-purpose AI models used upstream.
  • ISO/IEC 42001:2023: our AI management system is structured around the standard's plan-do-check-act cycle.
  • NIST AI RMF 1.0: we map controls to the Govern / Map / Measure / Manage functions.
  • GDPR Article 22: no solely automated decisions with legal or similarly significant effects.
Section 10

Accountability

The Founder is the accountable owner of this Policy. AI incidents (bias, hallucination causing customer harm, security compromise) are logged, reviewed, and reported to affected customers without undue delay. Contact security@ryniqo.com for security matters and privacy@ryniqo.com for privacy matters.