AI Use Policy
Cyber Op Source uses artificial intelligence as an assistive capability where it can improve efficiency, consistency, accessibility, or analysis while preserving appropriate human responsibility. This policy describes the principles used for AI-enabled Compliance OS features and related Cyber Op Source work.Permitted uses
AI may be used to assist with activities such as:- drafting and editing,
- summarization,
- stakeholder interview assistance,
- evidence guidance,
- document and policy navigation,
- analysis support,
- coding and software-development assistance,
- documentation creation,
- communications or media preparation,
- operational workflow assistance.
Human oversight
AI does not replace accountable human review for material cybersecurity, compliance, governance, legal, or client decisions. Cyber Op Source personnel remain responsible for the professional work they deliver. Client decision-makers remain responsible for approvals and governance actions assigned to them.Data minimization
Users and staff should provide AI systems only the information reasonably needed for the task. Passwords, private keys, authentication tokens, recovery secrets, and unrelated sensitive information should not be intentionally submitted.Authorized information
AI-enabled features should operate within the user’s authorized context. A client-facing AI assistant should not be used as a mechanism to expose unrestricted internal assessment data or information belonging to another client.Accuracy and verification
AI can produce incomplete, incorrect, outdated, or misleading output. Material output should be checked against authoritative sources such as:- approved policies,
- original evidence,
- assessment records,
- applicable standards,
- contractual requirements,
- qualified human judgment.
Transparency
Where AI materially participates in a workflow, Cyber Op Source aims to describe the purpose of the feature in a way that allows users to understand that they are receiving AI-assisted output.Model and provider controls
The specific AI service, model, retention setting, and data-handling control may depend on the approved tool, use case, client agreement, and technical configuration. Cyber Op Source should select AI services consistent with its security, privacy, contractual, and client obligations.Prohibited or inappropriate use
AI should not be used to:- fabricate evidence,
- impersonate an authorized decision-maker,
- conceal known inaccuracies,
- bypass client or engagement authorization,
- make an unreviewed final risk-acceptance decision,
- generate or store secrets in documentation,
- represent an assessment conclusion as verified when it has not been reviewed.
Continuous improvement
AI capabilities and risks evolve quickly. Cyber Op Source may update this policy and its technical controls as services, regulations, client requirements, and security practices change.This policy is designed as a public-facing Compliance OS documentation baseline. It should be reviewed alongside the final Cyber Op Source website AI Policy, Privacy Policy, Terms, and engagement-specific commitments before production publication.