Skip to main content

Exprodo Software AI Governance Policy

1. Purpose and scope

This policy sets out how Exprodo governs its use of artificial intelligence. It covers all AI systems used by Exprodo staff in the course of their work.

Exprodo is a UK-based software company. We use AI only as a deployer as our use is currently limited to third-party AI tools used internally to support our work. We do not develop AI systems, and we do not embed AI into the products we supply to customers. This policy reflects that position and will be updated if it changes.

The policy is structured around four areas: our position on prohibited AI practices (§3), transparency (§4), AI literacy (§5), and how we maintain an inventory of our AI use (§2). It is informed by the EU AI Act (Regulation (EU) 2024/1689) as a benchmark of good practice, while recognising, as set out below, that our current AI use falls outside that Act's scope.

2. AI inventory and our regulatory position

Exprodo maintains an inventory of every AI system in use across the company. This is stored at assets.exprodo.com. For each use we record its purpose, the data involved, where the output goes, whether output is human-reviewed, our role, and a risk and scope assessment. This is the foundation of our pre-deployment check.

The inventory is the foundation of this policy: every position below is derived from it, and it serves as our evidence of how we govern AI.

Our current position, based on that inventory:

  • All current AI use is internal. In every case, a human reviews and takes ownership of the AI output before it is used or before anything reaches a customer. What reaches our customers is our own work product, not the raw output of an AI system.
  • On that basis, our current AI use falls outside the scope of the EU AI Act. The Act reaches a non-EU company where the output of an AI system is used in the Union (Article 2(1)(c)); because our AI output is human-owned internal material and does not reach customers as AI output, that condition is not met.
  • None of our AI use is high-risk, and none involves making or influencing consequential decisions about individuals.

The literacy and transparency measures in this policy are therefore adopted as voluntary good practice, not because the Act obliges them. We choose to hold ourselves to this standard as a matter of trust and positioning.

Keeping this current. The inventory is reviewed at least annually, and whenever a new or materially changed AI use is introduced. Any new or changed AI use is assessed for prohibited practices, risk, and scope before it goes live. Responsibility for watching for changes in AI use and triggering an off-cycle review sits with the policy owner named above.

3. Prohibited AI practices

Our AI use comprises internal-productivity tasks including assistance with documents, code, and analysis. None of this usage falls within any prohibited category. Should any future AI use approach a prohibited practice, it would not be deployed. This position is reviewed under §2.

Purpose

This statement records Exprodo's position against Article 5 of the EU AI Act (Regulation (EU) 2024/1689), which lists AI practices that are prohibited outright within the European Union. It forms part of Exprodo's documented approach to AI governance.

Our position

As of the date above, Exprodo does not engage in any of the AI practices prohibited under Article 5(1) of the EU AI Act. We use AI only as an internal deployer, to support business and development tasks. We do not develop, place on the market, or deploy AI systems for any of the prohibited purposes set out below.

Assessment against Article 5(1)

We have reviewed each of the eight prohibited practices and confirmed none applies to our AI use:

Art. 5(1) Prohibited practice Applies to Exprodo?
(a) Harmful subliminal, manipulative or deceptive techniques that materially distort behaviour and cause significant harm No
(b) Exploitation of vulnerabilities (age, disability, social/economic situation) causing significant harm No
(c) Social scoring leading to detrimental or disproportionate treatment No
(d) Predicting criminal offending based solely on profiling or personality traits No
(e) Untargeted scraping of facial images to build facial-recognition databases No
(f) Inferring emotions in the workplace or in education institutions No
(g) Biometric categorisation to infer protected characteristics No
(h) 'Real-time' remote biometric identification in public spaces for law enforcement No

Maintaining this position

This position is reviewed at least annually and whenever Exprodo introduces a new or materially changed AI use. Any new AI use is assessed against Article 5 before it goes live. Should any future use approach a prohibited practice, it would not be deployed.

This statement reflects Exprodo's good-faith assessment of its own AI use against Article 5 of the EU AI Act. There is currently no third-party means of ensuring compliance. It is not legal advice. It will be updated as our AI use evolves.

Note for our customers in education and research: practice (f) on 'emotion inference in workplace and education settings' is the prohibition closest to your sector. We confirm we operate no such system, and our review process is designed to keep this true as our products evolve.

4. Transparency

The EU AI Act (Article 50) places transparency duties on certain AI uses. For example, telling people when they are interacting with an AI system, or labelling AI-generated content that could be mistaken for human-made or authentic material.

Having reviewed our inventory against these duties, no Article 50 transparency obligations are currently triggered, because:

  • We operate no AI system that interacts directly with customers or members of the public (no customer-facing chatbots or AI agents).
  • We generate no AI content that is published or sent to others as if human-made or authentic; AI assists internal drafting and code, all of which is reviewed and owned by a member of staff before use.

As good practice, Exprodo nonetheless commits that:

  • If we ever introduce an AI system that interacts directly with customers or the public, we will clearly disclose that they are dealing with AI and update our policy documentation and inventory accordingly.
  • If we ever publish or supply AI-generated content externally, we will label it appropriately.
  • These commitments are checked as part of the pre-deployment assessment in §2.

5. AI literacy

Exprodo expects staff who use AI in their work to do so with a basic, practical understanding of how these tools behave and where their limits lie. This reflects the principle in Article 4 of the EU AI Act, adopted here as good practice.

This is delivered through a short **AI Use Guidance Note** (below), which all staff who use AI read and acknowledge **annually**. The acknowledgement record is kept alongside the AI inventory. The level of understanding expected is proportionate to our use (internal-productivity tools, human-reviewed output) and is intentionally light. It will be revisited if our AI use becomes more significant or higher-risk.

AI Use Guidance Note

We use AI tools (such as Claude, Microsoft Copilot, and Gemini) to help us work more effectively. They're genuinely useful but remain tools, not colleagues, and using them well means understanding a few things about how they behave.

  1. AI output is a draft, not an answer. Everything an AI tool produces must be reviewed by you before it's used. AI can be confidently wrong as it can invent facts, miscalculate, produce code that looks right but isn't, and misread what you asked. You are responsible for what you do with its output, exactly as if you'd written it yourself.

  2. Be careful what you put in. Assume anything you type into an AI tool may be processed outside Exprodo. Don't paste in confidential customer data, personal data, credentials, or anything sensitive unless you know the specific tool is approved for it and configured to protect it. If in doubt, leave it out or ask.

  3. Use approved tools, signed in correctly. Use the AI tools Exprodo has approved, signed in with your Exprodo work account where applicable (this is what keeps our data protected, for example, it's what stops Microsoft Copilot using our content to train its models). Don't route work through personal AI accounts.

  4. Nothing reaches a customer unreviewed. AI can help you draft a reply, write configuration, or analyse a problem. However, a person should always review and own the result before it goes to a customer. We never send AI output straight to customers.

  5. Tell someone if your use changes. If you start using a new AI tool, or using an existing one in a meaningfully new way, especially anything that might involve customer data or customer-facing output, let [the policy owner] know, so it can be added to our inventory and checked. This is how we stay on top of our AI use.

  6. If something feels off, flag it. If AI is wrong, biased, inappropriate, or produces surprising output, please raise it. It helps us use these tools safely.

6. Review

This policy and its inventory are reviewed at least every 12 months, and sooner if Exprodo's AI use materially changes. For any queries please email This email address is being protected from spambots. You need JavaScript enabled to view it..

This policy reflects Exprodo's good-faith approach to governing its own AI use. It is not legal advice. It will be updated as our AI use evolves.