Policy // AI governance
AI Policy
How ChatGPT, Codex, and OpenCode support software and content work without transferring decision responsibility to a model.
Public operational document · Version 1.0 · 2 August 2026
Scope
Zero Softworks uses AI tools to create code, images, text, and automations when they provide a concrete benefit. This policy defines decision criteria, controls, and recognised limits.
It covers internal work and client projects. It does not replace a legal assessment, DPIA, risk classification, or project-specific agreement.
Main tools and providers
The main services are ChatGPT and Codex by OpenAI. ChatGPT supports reasoning, assisted research, drafting, and design; Codex supports development, review, and code transformation.
OpenCode is the orchestration and interaction tool used for technical work. In this configuration it connects to Codex: OpenCode should not automatically be understood as an additional model provider. The actual flow depends on the account, configuration, and enabled services.
Provider terms, processing regions, retention, model-improvement use, and privacy settings can change. Project-data settings and applicable terms are checked before use.
Operating principles
- Human oversightAI output is not approval, a decision, or a final delivery. A competent person reviews code, images, text, configurations, and automations before use.
- MinimisationA prompt contains only necessary data. Secrets, credentials, tokens, private keys, and unnecessary personal data are excluded.
- TraceabilityFor relevant work, the tool, output type, reviews, and human decisions are recorded when proportionate.
- ProportionalitySimple rules, deterministic software, or human work take priority when they are more suitable, controllable, or safe.
- ChallengeA person can ask for clarification, review, or correction of an AI-produced or AI-assisted result.
Data and confidentiality
ChatGPT, Codex, and OpenCode are not used as a project archive. Confidential data, client documents, health or financial information, credentials, and unnecessary personal data must not be sent to AI services without authorisation, verified configuration, and a documented need.
When required, the assessment covers anonymisation, pseudonymisation, synthetic data, dedicated environments, access controls, retention, and processing agreements. If controls are insufficient, the use case is reduced, moved, or rejected.
Data sent to OpenAI or processed through connected tools is also subject to the relevant service terms and policies. This page does not promise that an external provider will never retain or transfer data.
Code, images, and content
AI-generated or modified code is treated as a proposal to review. Checks cover correctness, dependencies, licences, security, tests, performance, and project compatibility.
AI-generated or assisted images and text are checked for errors, undue similarity, trademarks, recognisable people, copyright, unverified claims, and commercial use. No output is published merely because it looks convincing.
When AI origin or manipulation matters to the context, it is disclosed to the client or public with an appropriate note, label, or description.
AI Act and risk classification
The European AI Act applies different obligations depending on role, sector, purpose, audience, and risk. A project is not considered automatically compliant simply because it uses a general-purpose model.
Before introducing automation, Zero Softworks assesses whether it acts as deployer, provider, integrator, or developer of a component. The review also checks prohibited practices, transparency duties, high-risk systems, and other applicable obligations.
We do not intentionally adopt subliminal manipulation, exploitation of vulnerabilities, social scoring, or biometric categorisation to infer sensitive traits. Systems making irreversible decisions about people without human control and a specific assessment are excluded.
Projects for regulated sectors, recruitment, essential services, credit, education, health, or safety require assessment with the client and specialist advice where necessary.
Security and incident handling
Prompts must not contain secrets. Outputs are treated as untrusted input: they may include vulnerable code, malicious instructions, invented data, or manipulative content.
Exposed secrets, unauthorised data use, dangerous output, licence violations, or unexpected behaviour should be reported promptly.
Responsibility and review
The client remains responsible for purposes, data, authorisations, and decisions in its context. Zero Softworks remains responsible for the activities it controls, promised reviews, and communication of known limits.
This policy is reviewed when main providers, processing methods, service scope, or the regulatory framework change. Current version: 2 August 2026.
Questions and reports
Use the contact form for questions about this policy, a project, or a possible incident.
Open the contact form