Legal
Responsible AI policy.
The standards we hold ourselves to when we use AI in our own work.
ADL-RAI-001 · Version 1.1 · Reviewed 2 August 2026 · All policies and statements
| Policy reference | ADL-RAI-001, formerly HCSL-RAI-001 before the company's change of name on 23 July 2026 |
|---|---|
| Version | 1.1 |
| Status | Active |
| Effective date | June 2026, reviewed 2 August 2026 |
| Applies to | All personnel of Adliora Limited and any contractors acting on its behalf |
| Policy owner | Saqib Khan, Founder and Director |
| Review cycle | Annual, or following any material change in AI tools or regulatory guidance |
1. Purpose
Adliora Limited is an AI consultancy and strategy firm. Artificial intelligence tools are central to how we work, and how we advise clients on working. That dual position, as both a practitioner and an adviser, means our own conduct in using AI is not an internal matter only. It is part of the service we sell and part of the professional credibility on which that service depends.
This Policy sets out the standards we apply to AI use across the firm. It defines which AI tools we use and for what purposes, where we draw boundaries, how we protect client information when AI tools are engaged, and what our position is on the reliability and ownership of AI-generated content. Every person working for or with Adliora must read, understand, and follow this Policy.
2. Scope
This Policy applies to all employees, directors, consultants, and contractors of Adliora Limited, regardless of seniority or location. It applies whenever an AI tool is used in connection with any work carried out for or on behalf of Adliora, whether that work involves client delivery, business development, internal administration, marketing, or research.
This Policy sits alongside the Adliora Data Protection Policy and the Record of Processing Activities. Where AI use involves the processing of personal data, both this Policy and the Data Protection Policy apply. In the event of any inconsistency, the more protective provision governs.
3. Definitions
In this Policy, the following terms carry the meanings set out below.
| Term | Meaning |
|---|---|
| AI Tool | Any software or service that uses machine learning, large language model, generative AI, or similar automated reasoning technology to produce, summarise, translate, classify, or otherwise process content. This includes but is not limited to large language model assistants, AI-assisted research tools, automated drafting tools, and AI-integrated productivity platforms. |
| AI-Generated Output | Any content, analysis, document, code, or recommendation produced in whole or in material part by an AI Tool, regardless of the extent to which a human has subsequently reviewed or edited it. |
| Client Data | Any information, whether personal data or otherwise, provided by or relating to a client, including information about the client's business, personnel, strategy, operations, or legal and regulatory position. |
| Approved AI Tool | An AI Tool that has been assessed and approved under clause 8 of this Policy for use in Adliora work. |
| Restricted Use Case | A category of work identified in clause 6 as requiring elevated caution or specific authorisation before an AI Tool is engaged. |
| Prohibited Use Case | A category of work identified in clause 6 as one in which AI Tools must not be used. |
4. How Adliora Uses AI Tools in Delivery Work
4.1 General principle
We use AI Tools to make our work better, faster, and more rigorous. We do not use AI Tools to replace professional judgement. Every output produced with AI assistance is reviewed, assessed, and owned by a qualified human before it reaches a client or is relied upon in any professional context.
4.2 Approved uses in client delivery
Adliora uses Approved AI Tools across the following categories of delivery work.
- Research and market analysis, including the rapid synthesis of publicly available information to support strategic recommendations.
- Drafting and document production, including the preparation of reports, policies, frameworks, and written advice, subject to full human review before issue.
- Process mapping and workflow analysis, including the use of AI Tools to identify inefficiency patterns and model alternative process designs.
- Gap analysis and compliance assessment, including comparison of a client's documented practices against relevant legal, regulatory, or industry standards.
- Training and educational content production, including the preparation of written materials, presentations, and e-learning content for client staff.
- Proposal preparation and business development collateral, including the drafting of scope documents and service proposals for prospective clients.
In every case, the AI Tool is a supporting instrument. The consultant responsible for the engagement retains full accountability for the quality, accuracy, and appropriateness of anything delivered to the client.
4.3 Internal uses
AI Tools are also used internally for tasks including the drafting of internal policies and procedures, the preparation of meeting notes and action logs, the management of scheduling and administrative correspondence, and the production of marketing and social media content. The same review obligation applies: no AI-generated internal document is finalised or distributed without human review.
5. Transparency with Clients
5.1 Disclosure
We will tell clients, in our standard Client Engagement Letter and in response to any direct inquiry, that we use AI Tools as part of our service delivery. We will not represent AI-generated content as the product of exclusively human effort.
5.2 Client instruction to restrict AI use
A client may instruct us in writing to restrict or prohibit the use of AI Tools in their engagement. We will honour that instruction. Where a restriction materially affects our ability to deliver the agreed scope within the agreed fee, we will notify the client and agree a revised approach before proceeding. The instruction to restrict AI use must be recorded in the engagement file and communicated to all personnel working on the matter.
5.3 AI-generated outputs in deliverables
Where a deliverable contains material that originated as AI-generated content and has been reviewed and edited by a consultant, that deliverable is treated as the professional output of Adliora. We do not disclose which individual sentences or paragraphs originated in an AI Tool. We do disclose, at an engagement level, that AI Tools were used in the production process.
6. Boundaries: Restricted and Prohibited Uses
6.1 Prohibited uses
The following uses of AI Tools are prohibited without exception.
- Inputting any client personal data, including names, contact details, financial information, health information, or legal matter details, into any AI Tool that is not an Approved AI Tool with a contractual data processing agreement in place.
- Inputting any client confidential information, including commercially sensitive strategy, unpublished financial information, or information subject to legal professional privilege, into any AI Tool whose data retention and training practices have not been reviewed and approved.
- Delivering AI-generated content to a client without human review, regardless of time pressure or the apparent routine nature of the task.
- Using AI Tools to generate legal advice intended to be relied upon as a substitute for qualified legal counsel. Adliora does not practise law. Where our advisory work touches legal questions, we refer clients to qualified solicitors and do not use AI Tools to substitute for that referral.
- Using AI Tools to fabricate, misrepresent, or impersonate any individual, organisation, or document.
- Using AI Tools to generate content that is discriminatory, defamatory, or in breach of any applicable law.
6.2 Restricted uses requiring senior approval
The following categories of work require prior approval from the Director before an AI Tool is engaged.
- Any engagement where the client is in the legal sector and the subject matter involves client-confidential legal matter information or information relating to third parties in litigation or regulatory proceedings.
- Any work involving the processing of special category personal data as defined under the UK General Data Protection Regulation, including health, criminal records, biometric, or political information.
- Any engagement where the AI Tool is to be used to produce a compliance or regulatory assessment that will be submitted to a regulator or relied upon in legal proceedings.
- Any engagement where the client has signalled, formally or informally, that they have concerns about AI use or data handling.
6.3 The legal sector
Legal sector clients operate under heightened duties of confidentiality, professional privilege, and regulatory oversight governed by the Solicitors Regulation Authority, the Bar Standards Board, the Chartered Institute of Legal Executives, and other applicable regulatory bodies. When working with legal sector clients, we treat all matter-related information as presumptively privileged until we have confirmed otherwise. We apply this Policy with corresponding strictness and do not use AI Tools to process any information that a legal professional would be required to treat as confidential without the express written consent of the client and a confirmed assessment that the AI Tool meets the data security standards required.
7. Protecting Client Data When AI Tools Are Used
7.1 Pre-use assessment
Before an AI Tool is used in connection with any client engagement, the responsible consultant must confirm that the tool is on the Approved AI Tools list maintained by the Policy Owner. If it is not on that list, the tool must be assessed under clause 8 before use. Use of an unapproved tool in a client engagement is a breach of this Policy.
7.2 Data minimisation
When using an AI Tool in connection with client work, personnel must apply the principle of data minimisation. This means providing only the information that is necessary for the specific task. Client names, personal details, and identifying information should be removed or anonymised before input into an AI Tool wherever it is practicable to do so without compromising the quality of the output. Where anonymisation is not practicable, the responsible consultant must document the reason and confirm that the tool has been approved for identifiable data processing.
7.3 AI Tools that retain or train on data
Adliora will not use any AI Tool that, by default, retains input data for the purpose of training its underlying models, in connection with client data, unless the client has given explicit informed consent and the relevant data processing terms have been reviewed and approved. Where an AI Tool offers a setting or configuration that disables training on user inputs, that setting must be activated before client data is processed.
7.4 Third-party AI processors
Where an AI Tool provider processes data on our behalf, that provider must be treated as a data processor under the UK General Data Protection Regulation. A Data Processing Agreement meeting the requirements of Article 28 UK GDPR must be in place before client personal data is processed. The AI Tool must be included in the Adliora Record of Processing Activities. Personnel must not use consumer-grade versions of AI tools, which typically do not offer data processing agreements, for any purpose involving client personal data.
7.5 International transfers
Many AI Tool providers operate infrastructure in the United States or other non-UK jurisdictions. Any transfer of client personal data to such a provider constitutes an international transfer under the UK GDPR and must be covered by an appropriate transfer mechanism. Approved AI Tools are assessed for transfer compliance as part of the approval process under clause 8. Personnel must not route client data through any AI service where the international transfer position has not been confirmed.
7.6 Breach or suspected breach
If a member of personnel suspects that client data has been processed through an unapproved AI Tool, or that an AI Tool has retained or transmitted client data in a manner not contemplated by this Policy, they must notify the Policy Owner immediately. The incident must be assessed under the Adliora Data Protection Policy and, where it constitutes a personal data breach, reported to the Information Commissioner's Office within 72 hours of confirmation.
8. AI Tool Selection and Approval
8.1 Assessment criteria
Before any AI Tool is added to the Approved AI Tools list, it must be assessed against the following criteria.
| Assessment area | Minimum requirement |
|---|---|
| Data retention | The provider must offer a configuration option that prevents input data from being used to train models, or must confirm by contract that it does not retain or train on customer inputs. |
| Data processing terms | A Data Processing Agreement compliant with Article 28 UK GDPR must be available and must be executed before use involving personal data. |
| International transfers | The international transfer basis must be identified. For US providers this will typically be the UK Extension to the EU-US Data Privacy Framework (UK-US Data Bridge) or UK-approved Standard Contractual Clauses. The basis must be confirmed and recorded. |
| Security standards | The provider should hold recognised security certifications (ISO 27001 or SOC 2 Type II as a minimum) or provide equivalent documented evidence of security controls. |
| Output reliability | The tool's known limitations, including tendencies to produce inaccurate, fabricated, or biased output, must be understood and factored into the review obligations applied to its outputs. |
| Contractual standing | The tool's terms of service must be reviewed to confirm compatibility with Adliora's obligations to its clients, including any confidentiality or intellectual property obligations. |
8.2 Approved AI Tools register
The Policy Owner maintains a register of Approved AI Tools. The register records the tool name, version or tier used, the assessment date, the data processing agreement reference, the approved use categories, and any restrictions on use. The register is reviewed when this Policy is reviewed and whenever a new tool is proposed or an existing tool materially changes its terms or functionality.
8.3 New tools and changes
Any member of personnel wishing to use an AI Tool that is not on the Approved AI Tools register must submit a request to the Policy Owner before use. The request must identify the tool, the intended use, the data involved, and the reason the request is being made. The Policy Owner will complete the assessment within five working days or, where the matter is time-critical, as soon as practicable. Use of an unapproved tool is not permitted pending assessment, regardless of the urgency of the underlying work.
9. AI-Generated Outputs: Our Position
9.1 Accuracy and reliability
AI Tools, including the most sophisticated large language models currently available, produce inaccurate output. They fabricate citations, misstate legal and regulatory requirements, confuse dates, figures, and names, and present confident-sounding assertions that are simply wrong. Adliora does not treat AI-generated content as reliable until a qualified human has reviewed it against primary sources or professional knowledge. The frequency and seriousness of AI errors varies by tool and by task type, and personnel must calibrate their review accordingly: a higher-risk task demands a more thorough review.
9.2 Human review obligation
No AI-generated output may leave the firm, whether in a client deliverable, a proposal, an email, or any other communication, without being read, assessed, and approved by a person with the competence to evaluate it. The review obligation is not satisfied by a superficial read. The reviewer must satisfy themselves that the content is accurate, that any claims are supportable, that any references or citations have been verified, and that the output is consistent with the professional standards expected of Adliora.
9.3 Intellectual property
The intellectual property position on AI-generated content is unsettled in the United Kingdom and internationally. Adliora does not make representations to clients about the intellectual property ownership of content generated with AI tool assistance beyond what is expressly agreed in the applicable services agreement. Personnel must not input any content owned by a third party into an AI Tool in a manner that would constitute an infringement of that third party's intellectual property rights. Where a client provides us with its own proprietary materials for use in our work, those materials must be handled in accordance with the confidentiality provisions of the applicable services agreement.
9.4 Professional accountability
Adliora takes professional accountability for every output it delivers, whether or not AI Tools were used in its production. The involvement of an AI Tool in producing a deliverable does not reduce, qualify, or displace our contractual or professional obligations to the client. A consultant who delivers inaccurate or damaging work on the basis that it was produced by an AI Tool will be held to the same standard as if they had produced it personally.
10. Human Oversight and the Role of Judgement
AI Tools do not understand context in the way that experienced professionals do. They do not exercise professional judgement. They are not subject to the professional obligations, regulatory duties, or ethical commitments that apply to Adliora and its people. Our use of AI is always in the context of professional engagements where those obligations apply, and we do not allow AI Tools to substitute for the application of professional judgement.
This means, in practice, that a consultant working on a client engagement does not simply prompt an AI Tool and pass the output to the client. The consultant uses the tool to accelerate or enhance their own work, reviews the output critically and thoroughly, applies their professional knowledge to identify errors and gaps, and issues the final product as their own professional work product for which they are fully responsible. The AI Tool is an instrument, not an author.
11. Staff Responsibilities
11.1 All personnel
Every person working for or with Adliora is responsible for reading this Policy before using any AI Tool in connection with Adliora work, for using only Approved AI Tools, for applying the data minimisation principle, for reviewing all AI-generated content before use or delivery, and for reporting any suspected policy breach or data incident to the Policy Owner immediately.
11.2 The Director and senior consultants
The Director, and any senior consultants engaged by the firm, are responsible for ensuring that personnel and subcontractors under their supervision understand and follow this Policy, for authorising Restricted Use Cases under clause 6.2, and for escalating any situation where AI use raises concerns that this Policy does not squarely address.
11.3 The Policy Owner
The Policy Owner is responsible for maintaining the Approved AI Tools register, conducting and recording tool assessments, responding to new tool requests under clause 8.3, reviewing and updating this Policy at each review cycle, and acting as the first point of contact for any question or concern about AI use within the firm.
12. Compliance and Consequences
Compliance with this Policy is a condition of working for and with Adliora. A breach of this Policy, including but not limited to the use of a prohibited or unapproved AI Tool with client data, the delivery of unreviewed AI-generated content to a client, or the failure to report a data incident, will be treated as a serious disciplinary matter. Where a breach causes or risks causing loss or damage to a client, Adliora will assess its obligations to that client and may be required to notify the client of the breach.
Contractors and subcontractors are required to comply with this Policy as a term of their engagement with Adliora. Adliora reserves the right to terminate an engagement with any contractor who breaches this Policy.
13. Monitoring and Review
The AI environment changes rapidly. New tools emerge, regulatory guidance develops, and the capabilities and risks of existing tools change. This Policy will be reviewed at least annually and will also be reviewed promptly following any of the following events: a material change in the AI Tools used by the firm; new or updated guidance from the Information Commissioner's Office, the AI Safety Institute, or any other relevant regulatory body; a significant AI-related incident within the firm; or a significant change in the firm's client sectors or delivery model.
The review will assess whether the Approved AI Tools list remains current, whether the boundaries in clause 6 remain appropriate, whether the data protection controls in clause 7 reflect current best practice, and whether any developments in law or regulation require amendment to the Policy.
Updated versions of this Policy will be issued with a new version number and effective date and communicated to all personnel before the effective date.
14. Related Documents
| Document | Reference |
|---|---|
| Data Protection Policy | ADL-DP-001 |
| Privacy Policy (website) | ADL-PP-001 |
| Cookie Policy (website) | ADL-CK-001 |
| Record of Processing Activities | ADL-ROPA-001 |
| Client Engagement Letter and Terms of Business | ADL-TOB-001 |
| Consultancy Services Agreement | ADL-CSA-001 |
15. Approval and Version History
| Version | Changes | Approved by | Date |
|---|---|---|---|
| 1.0 | Initial issue, under the company's former name Heracles CS Limited | Saqib Khan, Director | June 2026 |
| 1.1 | Change of company name to Adliora Ltd recorded, document references moved to the ADL series, and role titles aligned to the firm's current structure of a sole founder and director | Saqib Khan, Director | 2 August 2026 |
This Policy has been approved by the Director of Adliora Limited and takes effect from the date shown in the document header above.