How AI features are supplied, what they can and cannot be relied on for, what must never be fed into them, and where a human has to stay in the loop.
Version PUBLIC_2026_08_v1 · Effective 20 August 2026
1. Definitions
- —AI Feature means any feature using machine learning, a large language model, generative AI, classification model, automated agent or similar system.
- —AI Input means prompts, instructions, content, Client Data or other information supplied to an AI Feature.
- —AI Output means text, images, recommendations, classifications, actions or other material produced by an AI Feature.
- —Model Provider means the third-party provider of the underlying model or AI API.
2. Scope
2.1 Only AI Features described in the Order Form or SOW are supported. The Client may not repurpose an AI Feature for a materially different high-risk use without written review.
2.2 Model Providers are Third-Party Services. Their terms, model behaviour, rate limits, pricing and availability may change.
3. Accuracy and human oversight
3.1 AI Outputs are probabilistic. They may contain factual errors, fabricated content, bias, unsafe suggestions or inappropriate responses.
3.2 The Client shall implement human review appropriate to the consequence of the use case. AI Output must not be treated as guaranteed professional advice.
3.3 Unless a specifically reviewed Enterprise SOW states otherwise, an AI Feature must not be the sole decision-maker for employment, credit, insurance, healthcare, legal rights, essential services, immigration, law enforcement, education admission or assessment, biometric identification, safety-critical operation or another decision having legal or similarly significant effects on an individual.
4. Prohibited and restricted data
4.1 The Client must not submit special-category data, criminal-conviction data, secret credentials, full payment-card data or other highly sensitive information to an AI Feature unless the SOW expressly permits the category and the required data-protection and security review has been completed.
4.2 The Client must not use an AI Feature for unlawful discrimination, deception, impersonation, malware, credential theft, prohibited surveillance or other unlawful purposes.
5. Transparency
5.1 Where an AI system directly interacts with a natural person, the Client System should clearly disclose that the person is interacting with AI unless the applicable law plainly does not require it and the context is obvious.
5.2 If the Client deploys the AI Feature into the EU/EEA or another jurisdiction with AI-specific transparency obligations, the Client must identify that deployment territory. Nullshift shall implement technical notices or marking features expressly included in the SOW, but the Client remains responsible for deciding the legal disclosures required for its business and content.
5.3 AI-generated public-interest content, synthetic media, deepfakes or other regulated generated content requires a separate compliance review before deployment.
6. Automated decision-making and profiling
If an AI Feature processes personal data to make or support a significant decision about a person, the parties shall assess the applicable data-protection safeguards, lawful basis, transparency, human intervention and contestability requirements before live use. Special-category data requires heightened review.
7. Model-provider data use
7.1 Nullshift shall configure Model Provider options in accordance with the SOW and available provider controls. Nullshift will not intentionally use Client Data to train a general-purpose Nullshift model without express written agreement.
7.2 The Model Provider's applicable API or business terms govern its own handling of data. Where it acts as a subprocessor, it is subject to the DPA subprocessor process.
8. Prompt injection, actions and tools
8.1 AI agents that can send emails, access databases, make bookings, call APIs or take other actions must be designed with permissions, validation and human confirmation proportionate to the risk.
8.2 No technical control can eliminate prompt-injection or model-manipulation risk. The Client must not grant an agent broader credentials or financial authority than reasonably necessary.
8.3 High-impact irreversible actions should require explicit confirmation unless a reviewed SOW defines a safe autonomous workflow.
9. Intellectual property and outputs
9.1 Rights in AI Inputs remain with the party that owns them. The Client grants necessary licences for processing.
9.2 Rights in AI Outputs may depend on applicable law and Model Provider terms. Nullshift does not warrant that AI Output is unique, non-infringing or capable of exclusive ownership.
9.3 The Client must review AI Output before commercial publication where infringement, defamation, accuracy or brand risk is material.
10. Model changes and suspension
Nullshift may replace or update a model where reasonably necessary for availability, security, cost, provider deprecation or performance, provided material agreed functionality is not intentionally reduced without notice. Nullshift may suspend unsafe or unlawful AI use immediately.
11. Usage and cost
AI usage is subject to the Pricing, Scale and Usage Schedule. The Client may request a spend cap or agreed usage limit. Where technically available, Nullshift implements alerts before material overage.
Nullshift Development Ltd, trading as Nullshift · company number 17284213 · registered office 66 Paul Street, London, England, United Kingdom, EC2A 4NA · not VAT registered · ICO ZC214743