AI Principle 01
Our vision for responsible AI
Kool&Tech believes artificial intelligence should help people understand operations, improve processes, reduce repetitive work, and make better-informed decisions while preserving meaningful human control.
AI should augment professional judgment rather than obscure responsibility. The value of an AI-enabled system depends not only on model capability, but also on the quality of its data, purpose, boundaries, security, human oversight, and real-world use.
Our position: AI is a decision-support and productivity capability. People and organizations remain accountable for objectives, approvals, decisions, actions, and outcomes.
AI Principle 02
Core principles
Human accountabilityPeople remain responsible for requirements, review, approvals, decisions, and consequences.
TransparencyUsers should understand when AI materially contributes to an interaction, recommendation, score, or output.
Privacy and securityAI use should protect data, respect authorization, and operate within appropriate access boundaries.
FairnessAI use should consider the risk of unfair outcomes and seek to identify and reduce harmful bias.
Reliability and safetyAI-enabled functions should be evaluated for intended purpose, limitations, failures, and foreseeable misuse.
Inclusive useExperiences should consider diverse users, abilities, languages, contexts, and interaction methods.
AI Principle 03
Meaningful human oversight
Kool&Tech designs and configures AI-enabled solutions with oversight proportionate to the use, autonomy, information involved, and potential impact.
- Users should be able to understand relevant capabilities and limitations.
- Authorized people should be able to review, reject, edit, override, pause, or reverse outputs and actions where appropriate.
- Higher-impact functions should receive stronger review, approval, logging, and escalation controls.
- Users should be alert to automation bias and avoid relying on an output merely because it was generated by AI.
AI should not independently make irreversible or similarly significant decisions unless the use is expressly authorized and supported by appropriate safeguards.
AI Principle 04
Transparency and disclosure
Kool&Tech supports clear disclosure when users directly interact with an AI assistant, agent, chatbot, or avatar and when AI materially generates or manipulates content, where disclosure is required or contextually appropriate.
Disclosures may appear in an interface, report, workflow, output, metadata, documentation, service description, or accompanying notice. The level of detail should reflect the system's purpose, audience, impact, and legal requirements.
Transparency also means communicating material limitations, the need for human review, and the difference between an AI-generated suggestion and an approved business decision.
AI Principle 05
Responsible AI in KoolArchitect
KoolArchitect is envisioned as a business-process intelligence platform that may use AI to help users analyze processes, structure requirements, identify patterns, generate drafts, document workflows, highlight risks, recommend controls, and explore improvement opportunities.
KoolArchitect should support informed human decision-making rather than replace process owners, subject-matter experts, approvers, auditors, or accountable leaders.
1Transparent assistanceIdentify when AI materially contributes to analysis, documentation, or recommendations.
2Evidence-aware designDistinguish user-provided facts, system records, assumptions, and generated suggestions.
3Human approvalRequire authorized review before material process, control, governance, or implementation decisions.
4Safe automationLimit actions to approved tools, permissions, data, recipients, and operating boundaries.
5Traceable improvementSupport documentation, version awareness, review, and feedback where technically and commercially appropriate.
AI Principle 06
Data responsibility
Responsible AI begins with responsible data use. Inputs should be authorized, relevant, proportionate, and appropriate for the selected provider and purpose.
- Do not submit unnecessary confidential, regulated, personal, or privileged information.
- Use approved accounts, subscriptions, connectors, and data locations.
- Limit access according to business need and least privilege.
- Consider retention, deletion, transfer, and provider-improvement settings before deployment.
- Maintain appropriate records of instructions, permitted use, and data ownership.
Kool&Tech does not sell Customer data and does not use Customer Personal Data to train a publicly available foundation model unless the Customer expressly authorizes that use and applicable law permits it.
AI Principle 07
Privacy by design
AI-enabled processing is evaluated alongside the Kool&Tech Privacy Policy, Data Processing Addendum, Security & Trust Center, Subprocessor List, and applicable service agreement.
Depending on the use case, privacy considerations may include data minimization, purpose limitation, notice, consent, access control, international transfer, retention, deletion, data-subject rights, and impact assessments.
Customers remain responsible for establishing a lawful basis and identifying jurisdictional or sector-specific requirements for their use.
AI Principle 08
Security and resilience
AI systems introduce traditional security risks and AI-specific risks such as prompt injection, data leakage, malicious files, excessive agency, insecure output handling, unsafe tool use, model extraction, and adversarial manipulation.
Controls may include scoped access, approved connectors, secret protection, content safeguards, input and output validation, isolation, logging, monitoring, human approval, rate limits, and incident response, depending on scope and risk.
No system is represented as risk-free. Security measures must evolve with the system, threat environment, connected tools, and provider capabilities.
AI Principle 09
Fairness and harmful bias
AI systems may reflect limitations or bias in training data, prompts, labels, models, configuration, feedback, and deployment context.
Kool&Tech seeks to identify and reduce unfair or harmful outcomes through appropriate review, representative testing, contextual evaluation, feedback, and human judgment. Kool&Tech does not claim that an AI system is completely free of bias.
Protected characteristics and inferred sensitive traits should not be used for consequential decisions unless the use is lawful, necessary, documented, and supported by suitable safeguards.
AI Principle 10
Reliability, validation, and safety
AI behavior should be evaluated against its intended purpose, users, environments, languages, data, integrations, and foreseeable misuse.
- Outputs should be reviewed for accuracy, completeness, consistency, relevance, and unsupported claims.
- Testing should include ordinary use, edge cases, failure scenarios, and misuse appropriate to the service.
- Material changes to models, prompts, data, tools, workflows, or providers may require reevaluation.
- Safe fallback, exception handling, and recovery should be considered for automated functions.
Past performance does not guarantee future output quality.
AI Principle 11
Explainability and context
Users should receive enough information to understand the role AI played and to evaluate a recommendation or output in context, where technically feasible and appropriate.
Relevant context may include input sources, assumptions, confidence indicators, limitations, business rules, supporting evidence, data freshness, and the need for validation.
Not every model can provide a complete explanation of its internal reasoning. In those cases, system-level explanations, evidence, traceability, or reproducible business rules may be more useful than a purported explanation of model internals.
AI Principle 12
Responsible agents and automation
AI agents and automated workflows should operate only within defined objectives, approved permissions, permitted data, authorized tools, and clear escalation boundaries.
Higher-risk actions may require confirmation, segregation of duties, financial or operational thresholds, recipient validation, audit logs, rollback, and manual intervention.
An agent should not receive broader privileges than necessary merely for convenience. Connected actions must be tested before production use and monitored after material changes.
AI Principle 13
Professional and consequential use
AI-generated process maps, reports, assessments, forecasts, recommendations, scores, and documentation are informational aids. They do not independently constitute legal, tax, accounting, audit, medical, investment, insurance, employment, or other regulated professional advice.
For consequential decisions, users should involve qualified professionals and authorized decision-makers and preserve appropriate review, challenge, and appeal mechanisms.
AI Principle 14
Provider and model governance
Kool&Tech may use or integrate AI capabilities from Microsoft, Odoo, OpenAI, cloud platforms, or other documented providers depending on the engagement.
Provider selection may consider purpose, security, privacy, retention, data location, contractual protections, model behavior, reliability, support, compliance features, and Customer requirements.
Third-party providers operate under their own terms and may change models, features, locations, safeguards, and availability. Material providers that process Customer Personal Data on Kool&Tech's behalf should be addressed through the applicable DPA and Subprocessor List.
AI Principle 15
Governance and accountability
Responsible AI requires identifiable ownership. Depending on the service, governance may include a business owner, technical owner, data owner, risk reviewer, approver, user administrator, and escalation contact.
Accountability may be supported through documented purpose, approved use cases, access decisions, testing evidence, change control, incident handling, user guidance, review records, and contractual allocation of responsibility.
The Customer remains accountable for Customer-controlled deployment, personnel, decisions, configurations, data, and downstream use.
AI Principle 16
Monitoring, feedback, and incidents
AI-enabled services may be monitored for availability, failures, misuse, unsafe output, anomalous behavior, integration errors, excessive permissions, and feedback, within legal and contractual limits.
Users should report inaccurate, unsafe, unfair, misleading, unauthorized, or security-sensitive behavior. Material incidents may trigger restriction, rollback, provider escalation, workflow changes, additional testing, or suspension.
Monitoring cannot guarantee identification of every error or harmful outcome.
AI Principle 17
Inclusion and accessibility
AI-enabled experiences should consider different abilities, languages, technical knowledge, devices, and business contexts.
Where practical, users should have clear instructions, understandable controls, accessible interaction methods, and an alternative channel for important tasks. Inclusion does not mean every model performs equally across every language, domain, or population, so localized testing and human review may be necessary.
AI Principle 18
Efficiency and proportionality
Kool&Tech seeks to use AI where the expected business value is proportionate to cost, risk, complexity, data use, and operational impact.
Not every task requires a large model, autonomous agent, or continuous AI processing. Simpler rules, standard automation, analytics, or human workflows may be more reliable and maintainable for some use cases.
AI Principle 19
Customer and user responsibilities
Customers and users are responsible for:
- Selecting lawful and appropriate use cases.
- Providing authorized, accurate, and relevant inputs.
- Configuring permissions and approving connected tools.
- Training users and defining review requirements.
- Validating outputs before reliance, publication, or action.
- Maintaining required notices, consent, records, and governance.
- Reporting suspected data leakage, harmful behavior, unauthorized activity, or incidents.
AI Principle 20
Continuous improvement
AI technology, risk, user expectations, and regulation continue to evolve. Kool&Tech may refine product behavior, provider selection, testing, documentation, safeguards, disclosures, and governance as experience and requirements develop.
Feedback from Customers, users, providers, security researchers, and affected stakeholders may inform future improvements.
AI Principle 21
Relationship to other policies
This Responsible AI Statement expresses Kool&Tech's public principles and direction. Specific rights, obligations, limitations, data-processing terms, permitted uses, and project commitments are defined by the AI Use & Disclosure Policy, Privacy Policy, Data Processing Addendum, Acceptable Use Policy, Terms & Conditions, Security & Trust Center, applicable SOW, and other signed agreements.
If a specific agreement conflicts with this general statement, the legally applicable and more specific agreement controls.
AI Principle 22
Statement updates
Kool&Tech may update this Responsible AI Statement as KoolArchitect, services, providers, capabilities, standards, regulations, risks, and practices evolve.
The effective date identifies the current public version.