AI Usage & Model Governance Policy
How RYHA governs AI-assisted workflows, provider data treatment, human oversight, risk review, transparency, and customer controls.
This policy is a draft that requires review and approval by qualified legal counsel before public launch. It is provided for general information only and does not constitute legal advice. RYHA Technologies may update it from time to time, and only a formally approved published version should be treated as binding.
Purpose, Scope, and Permitted Use
The RYHA platform uses artificial intelligence to support software research, planning, design, development, testing, and operations workflows. This draft applies to model selection, prompts, retrieved context, tools, generated output, evaluations, approval controls, monitoring, and third-party AI providers. Features must be reviewed for intended use, affected people, data sensitivity, foreseeable misuse, applicable restrictions, and customer configuration before production enablement.
Customer Data and Provider Treatment
RYHA does not intentionally use customer project content to train a RYHA-owned foundation model or sell that content. Requests can be sent to the AI provider selected for a configured capability, so provider retention, abuse monitoring, location, secondary use, and model-training treatment depend on the applicable product, account settings, region, and contract. The approved Subprocessor Notice and customer agreement must identify actual recipients and terms before production customer content is sent.
EU AI Act Role and Risk Review
RYHA’s role under the EU AI Act can differ by feature and customer use. RYHA may need analysis as a provider or deployer, while a customer-configured use can create separate customer obligations. This draft does not classify the platform, every feature, or every customer deployment as prohibited, high-risk, limited-risk, or minimal-risk. Before an EU-facing feature is enabled, the approved review must assess intended purpose, prohibited-practice restrictions, whether a listed high-risk use is involved, fundamental-rights and safety impacts, documentation and logging, human oversight, accuracy and cybersecurity, provider instructions, post-market monitoring, and incident duties. European Commission materials state that the AI Act’s transparency rules are scheduled to apply from 2 August 2026. Whether a particular interaction, synthetic output, or public-interest text triggers an Article 50 disclosure depends on the system, output, role, context, and then-current law and guidance. Product notices must be ready for the applicable date without making an unverified role or risk classification.
Risk Controls, Human Oversight, Transparency, and Contact
AI-generated output can contain mistakes, insecure code, unsupported claims, bias, or unsuitable recommendations. Customers must review outputs, test deliverables, verify licences and sources where relevant, and obtain required professional, regulatory, security, accessibility, and production approvals. Major financial, irreversible, and production actions use explicit approval controls in covered workflows; lower-risk automation can proceed only within configured policy and permissions. The approved governance process should document feature-level role and risk assessment, evaluation criteria, known limitations, misuse testing where appropriate, incident escalation, change review, monitoring, and rollback or disablement. RYHA should provide clear information about AI-assisted interactions and material limitations and label covered synthetic content when required. Consent or another approved basis must be used where applicable. The final policy must define reporting, human review, and challenge routes without implying they apply universally. Questions can be sent to privacy@ryha.dev.