Regurai AI Policy
Version: 1.0 | Last updated: 13 June 2026
1. Regurai Public AI Policy
(Trust-Focused, Human Readable, Marketing Safe)
1.1 What Regurai is
Regurai is an Enterprise AI Governance and Operational Intelligence platform designed for regulated organisations operating in complex, high-assurance environments.
We help organisations govern, deploy, and scale artificial intelligence with confidence, control, and accountability—transforming governance from a compliance obligation into a strategic capability.
Our platform brings together:
- AI governance
- Compliance automation
- Operational risk intelligence
- Audit-grade oversight
into one integrated control environment.
1.2 How AI is used in Regurai
Regurai uses AI in limited, controlled ways to support governance workflows.
AI Assistant (Regur)
Regur is an AI assistant that:
- explains governance and compliance concepts
- supports training and onboarding
- helps users understand regulatory frameworks
It does not:
- make legal, financial, or regulatory decisions
- access live production systems or customer transactions
- replace human judgement
All responses are advisory and must be verified by authorised users.
Customer-connected AI systems
Customers may connect their own AI models to Regurai to:
- monitor decisions
- track risk signals
- support governance and audit workflows
Regurai does not control these models. The customer is responsible for:
- lawful use
- model accuracy
- decision-making outcomes
Regurai provides oversight tools, not automated decision authority.
1.3 Human oversight
All meaningful decisions must involve human review.
Regurai does not replace human judgement in:
- compliance decisions
- risk decisions
- regulatory reporting
- operational approvals
AI outputs are always subject to review by authorised personnel.
1.4 Data protection and privacy
We follow strict data protection principles:
- data minimisation — only required data is processed
- encryption in transit and at rest
- tenant isolation — no cross-customer access
- role-based access controls
Regurai does not sell personal data or use it for advertising.
1.5 Transparency and limitations
AI systems may:
- produce incorrect or incomplete outputs
- reflect limitations in underlying data
- require human verification before use
Regurai is designed to support decision-making — not replace it.
1.6 User rights
Depending on applicable law, individuals may:
- access their data
- request correction or deletion
- object to certain processing
- request human review of decisions
Requests can be submitted via the relevant organisation using Regurai.
1.7 Updates
This policy is reviewed regularly and may change as the platform evolves.
2. Regurai Legal AI Governance Policy
(Operational, Compliance, Audit, Procurement Version)
2.1 System classification
Regurai is an AI governance and operational intelligence system supporting regulated decision environments.
It is classified as:
- Limited-risk AI system (Regur Assistant)
- High-assurance governance support system (customer decision monitoring)
- Operational risk intelligence platform (anomaly and audit workflows)
Regurai does not operate fully autonomous decision-making systems with legal or similarly significant effects.
2.2 System architecture and AI components
2.2.1 Regur Assistant
- Provider: Google Gemini (via AI Gateway)
- Purpose: informational support only
- Restrictions:
- no live system access
- no decision authority
- no autonomous action capability
2.2.2 Customer AI Integration Layer
Regurai ingests:
- model outputs
- decision logs
- risk scores
- audit metadata
Regurai does not:
- validate model correctness
- override customer models
- determine legal basis for processing
2.2.3 Anomaly & risk intelligence
Outputs are:
- probabilistic indicators
- advisory signals only
- subject to mandatory human review before action
2.3 Data protection roles
Controller / Processor model
- Customer = Data Controller (default for operational data)
- Regurai = Data Processor (for customer data processing)
- Regurai = Independent Controller (for platform security and account data)
All processing is governed by a Data Processing Agreement (DPA).
2.4 Prohibited AI use
Regurai prohibits use of its platform for:
- fully automated legal or financial decisions without human oversight
- behavioural manipulation or social scoring
- unlawful profiling or discrimination
- biometric inference without lawful basis
- covert inference of sensitive attributes
2.5 Human oversight requirements
All high-impact workflows must include:
- documented human reviewer
- ability to override AI output
- recorded rationale for decisions
- segregation of duties
AI outputs are advisory and must not be used as sole decision basis.
2.6 Model governance framework
All AI systems must be recorded in a Model Governance Register including:
- model name and version
- provider (e.g. Google Gemini)
- purpose and intended use
- risk classification
- data categories processed
- approval status
- monitoring owner
- audit history
No model may be deployed without governance approval.
2.7 Data handling and retention
Data is:
- encrypted in transit and at rest
- logically isolated per tenant
- access-controlled via RBAC
Retention periods:
- defined per deployment contract
- enforced via retention policies and deletion workflows
No default retention period is implied unless contractually agreed.
2.8 Incident management
Regurai maintains a formal AI incident response framework.
Incident types
- data breach
- model failure or drift
- unsafe or incorrect AI output
- prompt injection or exploitation
- cross-tenant data leakage
Response process
- detection
- containment
- investigation
- notification (where required)
- remediation and rollback
Regulatory notification timelines apply where legally required.
2.9 Monitoring and assurance
Regurai monitors:
- model performance drift
- override rates
- fairness indicators (where applicable)
- system latency and availability
- security guardrail events
Material changes require re-approval before deployment.
2.10 Compliance mapping
This policy supports alignment with:
- UK GDPR & Data Protection Act 2018
- EU AI Act (risk-based classification approach)
- ISO 27001 (information security controls)
- ISO 42001 (AI management system principles)
- NIST AI Risk Management Framework
- UK ICO AI guidance
This is not a certification statement.
2.11 Governance accountability
Roles
- Product Owner: responsible for system design and intended use
- Security Owner: responsible for security controls and monitoring
- Data Protection Officer: responsible for privacy compliance
- Customer Owner: responsible for model usage and decisions
- Human Reviewer: responsible for all consequential decisions
2.12 Policy enforcement
- All AI systems must be approved before deployment
- All changes require re-assessment
- Policy is version-controlled and auditable
- Non-compliant use must be suspended immediately
