Legal
AI Use Schedule
The optional AI feature boundary, actual inputs and prohibited uses.
- Audience
- Customers, authorised AI administrators and users
- Version
- AI-2026-08-29-DISABLED-V1
- Effective date
- 2026-08-29
Optional and separately controlled
AI is disabled for the first-pilot service and no Customer Data is sent to OpenAI. A later signed Order may enable a named AI feature only after an authorised Customer signatory accepts the then-current AI Use Schedule and Votegrain records the exact provider, input classes, retention, transfer and server-side feature policy.
AI does not determine the deterministic result, guide voter choice or choose a winning option.
Actual input boundary
- Authoring format-compliance check: saved initiative title/description, option labels/descriptions/links/custom fields, and organisation initiative/option standards. It is false to say this feature receives only post-vote aggregates.
- Post-result insight, where enabled and verified: purpose-bound released aggregates and sanitised labels/grounding keys; no raw ballots or identities by design.
- Organisation interpretation, where enabled and verified: validated deterministic aggregates and neutralised labels; no ballot identity and no culture/personality/cause diagnosis.
Human responsibility and prohibited use
If AI is enabled under a later Order, output may be inaccurate or unavailable. The Customer must arrange authorised human review before relying on it; an output is an interpretation or drafting aid, not an authoritative result or professional advice.
- Do not use AI to solicit voter preference, rank options, predict the winner or steer a participant.
- Do not infer sensitive characteristics or make a prohibited high-impact individual decision.
- Do not send special-category, criminal-offence, health, financial-account, government-identifier, legally privileged, highly confidential or unnecessary personal data. This is a contractual restriction, not automatic data-type detection.
Provider, retention and transfers
For a UK Customer, the published OpenAI Services Agreement identifies OpenAI OpCo, LLC as the API contracting entity. OpenAI's published API controls state that API data is not used to train models by default and default abuse-monitoring logs may contain customer content for up to 30 days. Approved Modified Abuse Monitoring or Zero Data Retention can change that posture. An API option such as `store: false` is not by itself proof of Zero Data Retention, regional processing or no restricted transfer.
Any AI-enabled Order must record the connected API project, endpoint, regional-control status, provider DPA, subprocessors and transfer safeguard. UK regional storage is not described as UK-only processing unless the connected project and endpoint evidence support that exact promise.
The Order must say whether AI is disabled or name each enabled feature. A provider, model, material input class, retention mode or residency change requires the DPA change process and, where legally or contractually required, fresh customer acceptance before the changed scope is enabled.
AI evidence to record
- Customer, Order, authorised administrator and enabled feature/policy version.
- AI Schedule version, effective date, canonical URL and content hash accepted by the Customer.
- Provider entity, API project/region, endpoint, model policy, abuse-monitoring/ZDR state and `store` setting.
- Purpose and permitted input classes; prohibited-data reminder displayed at the point of use.
- Request/result status and bounded audit reference without copying unnecessary prompt or output content into logs.
- Human review owner and route for reporting or correcting an unsuitable output.