AI Policy

Responsible AI & Automation

AI is a tool, not a goal. This page explains when we use AI in workflows, which boundaries we apply and how responsibility is divided between Manuless and the client.

Version 1.0 Established: 27 June 2026 Based on EU AI Act principles
Section 1

Our starting point

AI is used in a Manuless workflow only when it has a demonstrable function that a human cannot reasonably perform as quickly or consistently. Think of summarising a longer text, extracting structured information from a free-text field, or categorising incoming messages.

AI for the sake of AI does not exist in our workflows. If rule-based logic is sufficient, we do not use an AI node. If a simple database lookup will do, we do not call a language model. The decision to use AI is always justifiable based on the client's functional need.

AI applications in workflows delivered by Manuless are assessed against the principles of the EU AI Act. We do not claim official certification. We describe how we apply the regulation as a design framework.


Section 2

When AI is and is not used

The EU AI Act explicitly prohibits a number of AI applications. Manuless does not build workflows that conflict with these prohibitions, regardless of what a client requests. We also apply our own boundaries that go further than the statutory minimum requirements.

We do build
  • Summarising incoming messages or forms
  • Extracting structured data from unstructured text
  • Categorising and prioritising tasks or leads
  • Generating draft texts for human review
  • Supporting the preparation of human decisions
  • Flagging anomalies or points of attention in a process
We do not build
  • Systems that score or rank individuals based on social behaviour or personal characteristics
  • Real-time biometric identification in public spaces
  • Automated decisions with legally binding consequences without human intervention
  • Profiling based on race, religion, political views, sexual orientation or comparable characteristics
  • Systems that use subliminal techniques to influence behaviour
  • AI-driven AML or Wwft reports without human review

Section 3

Human oversight

For every workflow containing an AI action, we assess whether the output of that action leads directly to a follow-up step, or whether a human must first review it. That assessment is documented in the process design document and is non-negotiable for decisions that affect clients, employees or third parties.

In practice, AI output in most workflows is treated as a draft or signal, not as a final outcome. The person managing the process always has the final say before anything is sent, saved or forwarded to an external party.

  • Draft emails generated by AI are submitted for approval, not sent automatically
  • Categorisation by AI is presented as a suggestion, not as an established fact
  • Signals that may indicate unusual situations (for example in a Wwft context) are always forwarded to a human reviewer
  • Scores or rankings generated by AI are labelled as indicative

Section 4

Data minimisation in AI processing

External AI services (such as Claude by Anthropic, or models by OpenAI or Google) receive only the data that is functionally necessary for the specific task. Full personal data (name, address, national ID number, financial data) are not passed on unless strictly required for the task and the client has explicitly chosen to include them.

In practice this means:

  • A summarisation task receives the text of a message, not the full client record
  • A categorisation task receives the subject or message body, not the sender's email address or phone number
  • Sensitive or special categories of personal data are removed from the data stream or pseudonymised as early as possible in the workflow

Which AI service is used in a workflow is always documented in the process design document. The client ultimately decides which provider is used. Manuless advises, but does not impose anything.

Sub-processors: When a workflow calls third-party AI services, those parties are sub-processors within the meaning of the GDPR. This is discussed and documented per engagement in the service agreement.


Section 5

Division of responsibility

The EU AI Act distinguishes between the provider of an AI system and the party that deploys it within their own organisation (the deployer). For Manuless workflows this division is as follows:

Situation Manuless's role Client's role
Use of Claude, GPT or comparable model via API in a workflow Integrator: Manuless builds the integration and determines which data the AI receives Deployer: the client deploys the system within their own organisation
After delivery: the workflow runs in the client's environment No active role. Manuless has no access to the running system. Fully responsible for use, configuration and compliance with applicable laws and regulations
Changes made by the client after delivery No responsibility for modified configurations Bears full responsibility for changes and their consequences

Manuless designs with attention to the principles of the EU AI Act, but cannot guarantee that a workflow will remain compliant in all future situations and with all future usage instructions from the client. That responsibility rests with the client as deployer.


Section 6

Transparency about AI use

Every process design document describes whether and where AI is used, which model or service is deployed and what the AI action does precisely. The client always knows what is in the workflow. No AI steps are hidden in technical details that the client cannot read.

The manual included with every delivery contains an explanation of any AI actions: what they do, which data they receive and how the client can modify or disable that step if needed.

Do you have questions about AI use in a specific process, or would you like a workflow reviewed against the AI principles Manuless applies? Book an intake call. We will discuss your situation in concrete terms.