AI Usage Policy
Version History
v1.0- Date: 2026-02-26
- Summary: Initial version
Version Explanation
Document versions are identified using the format v{major}.{minor}. Full version history of the document is available by selecting a different version above.
Major Version
The major version number will be incremented where there is a significant or substantive change to the document. This includes, but is not limited to:
- The addition or removal of a clause.
- A change to the substance or requirements of a clause resulting from an updated process, regulation, or other material change.
A new major version will also reset the minor version to 0.
Minor Version
The minor version number will be incremented where changes are made to improve the clarity, readability or understanding of the document without changing its substantive meaning or scope. This includes, but is not limited to:
- Rewording a clause to clarify what it applies to or how it applies.
- Adding examples to further explain the application or interpretation of a clause.
- Making other editorial or explanatory changes that do not alter the substantive requirements of the document.
Acceptance
Acceptance of a document is based on the major version number and is tied to the applicable contract or Statement of Work (“SoW”).
A minor version update made during an active contract or SoW will automatically apply and does not require additional acceptance, provided that the changes do not alter the substantive scope or requirements of the document.
A new major version will require acceptance under any subsequent contract or SoW. An existing contract or SoW will continue to be governed by the major version accepted at the time of agreement, unless otherwise agreed by the parties.
Accordingly, minor version updates may be made during the term of an active contract or SoW without requiring re-acceptance. A new major version will require acceptance as part of any subsequent contract or SoW.
Who
417 Tech Ltd (“we”, “us”, “our”) is a company registered in England and Wales under company number 17118754, with registered office at:
417 Tech Ltd Sparkhouse Rope Walk Lincoln England LN6 7DQ
You can contact us by post at the above address, or by any of the following other contact methods:
Phone: +44 (0) 333 44 44 417 Email: contact (at) 417-tech (dot) com
What
This policy provides information publicly and internally about the stance that we take towards Artificial Intelligence (AI), and how we define acceptable use of AI within the company.
AI is a tool, not an employee.
Whilst there are use-cases that can enable quick turnaround of a task, or immediate access to complex information, AI cannot be trusted to provide consistently reliable information. Additionally, the companies operating many AI tools cannot be trusted with personal, confidential, or sensitive company data.
Human accountability, professional judgement, and verified research always take precedence over AI-generated output.
Research Before AI Usage
Employees are expected to conduct independent research before reaching for an AI tool. This requirement exists for two key reasons:
1. Environmental Impact
AI systems, particularly Large Language Models (LLMs), require significant computational resources and energy consumption. The environmental impact of large-scale AI infrastructure is substantial. As a responsible technology company, we expect employees to consider whether:
- A traditional search engine query would be sufficient
- Existing internal documentation already contains the answer
- Vendor documentation provides the required information
- A colleague can provide authoritative guidance
AI should not be the first resort when solving a problem.
2. Information Reliability
AI systems are “probabilistic text generators”. They do not “know” information in the way a human expert does. They can:
- Fabricate references
- Present incorrect information confidently
- Provide outdated guidance
- Misinterpret technical nuance
Employees are accountable for the accuracy of their work. AI does not transfer or reduce that responsibility.
Use of Publicly Available AI Systems
Publicly available AI systems (including publicly hosted LLMs, chat-based AI tools, and consumer voice assistants) may only be used for generic, non-sensitive queries.
Permitted examples include:
- General knowledge questions
- High-level explanations of public concepts
- Brainstorming non-confidential ideas
- Assistance with generic formatting or grammar
The following restrictions apply:
- AI-generated information must not be relied upon as authoritative.
- AI outputs must always be independently verified through trusted and reputable sources.
- No personal, confidential, customer, infrastructure, security, financial, or proprietary information may be entered into any publicly available AI system.
- AI-generated responses must not be copied directly into company documentation or customer deliverables without review, validation, and rewriting by our employees.
Public AI tools are treated as untrusted third-party systems.
Use of Internally Available AI Systems
Internally hosted AI systems may be used for more specific, contextual queries than public tools, provided that:
- The system has been approved by management.
- The data remains within infrastructure controlled by us.
- The use complies with data protection and confidentiality requirements.
However, the same limitations apply:
- AI outputs must not be treated as authoritative.
- All information must be independently validated.
- Employees remain fully accountable for decisions and outcomes.
Internal availability does not equate to reliability.
Prohibited Uses of AI
AI tools may not be used for any task relating directly or indirectly to a customer job. AI is not an employee and may not perform work on behalf of us. This prohibition includes, but is not limited to:
- Software development or code generation for customer systems
- Network scanning, configuration analysis, or infrastructure assessment
- Security analysis or penetration testing assistance
- Creation of customer documentation or change records
- Generation of diagrams, topology maps, or architecture designs
- Image generation for customer use
- Drafting proposals, reports, or deliverables
- Incident response guidance applied to live systems
- Automated decision-making affecting customer infrastructure
All customer work must be performed by qualified employees using trusted tools and validated processes.
Data Protection and Confidentiality
Under no circumstances may AI systems (public or internal) be provided with:
- Customer names or identifying information
- IP addresses, network diagrams, or system configurations
- Access credentials, keys, tokens, or passwords
- Financial information
- Internal business strategy
- Legal documentation
- Unreleased product or service information
Entering such data into an AI system may constitute a breach of confidentiality agreements, data protection laws, and contractual obligations.
Accountability
Employees remain fully responsible for:
- The accuracy of their work
- The protection of customer and company data
- Compliance with legal, contractual, and regulatory obligations
Use of AI does not reduce professional responsibility. Failure to comply with this policy may result in disciplinary action.
Policy Review
This policy will be reviewed periodically to reflect:
- Changes in AI technology
- Regulatory developments
- Environmental considerations
- Internal risk assessments