We build AI agents for other businesses, so we hold our own work to the standard we recommend to clients. This statement describes how we design, disclose, supervise and secure AI systems.
1. AI on this website
The agent demonstrations on this Site are scripted simulations that show typical agent behavior. They do not send your input to an AI model. Forms on this Site are reviewed by people, not by an automated decision system.
2. Disclosure by design
Agents we deploy identify themselves as AI at the start of an interaction, and generated content can be labeled as such. This supports clients' transparency duties, including those under Article 50 of the EU AI Act, which have applied since August 2, 2026.
3. Human oversight
- Every agent has a defined escalation path to a human, and people can ask for a human at any time.
- Actions with financial, legal or similarly significant effects require human approval unless the client explicitly decides otherwise after a risk review.
4. Security of AI systems
- Least-privilege access: agents can only reach the tools and data their task requires.
- Testing before launch against prompt injection, data leakage, unsafe tool use and jailbreaks.
- Logging of agent actions for audit, with monitoring for abuse and anomalies after launch.
5. Data use
Client data is not used to train models for anyone else. Details are in our Privacy Policy.
6. Frameworks we align with
Our practices draw on the NIST AI Risk Management Framework, ISO/IEC 42001 (AI management systems) and the EU AI Act. Alignment is not a certification unless we state otherwise in writing.
7. Questions or concerns
Contact info@kdscybersecurity.com. We review every AI-related concern.