Responsible AI

Last updated: August 2026

This page sets out how we build and use AI: the commitments we make to clients, the work we decline, and the limits we are honest about. It applies to every engagement and to Nova, the assistant on this site.

1. Our position

AI is a tool, not a strategy. Most of the value in an AI project comes from choosing the right problem, and a fair share of our work is telling a client which of their ideas AI will not solve well. We would rather lose the sale than deliver a system that quietly does its job badly. Every engagement starts from the business problem and the people doing the work, not from the technology.

2. A person is accountable, always

Every system we deliver is handed over to a named owner on the client side, so it is always clear who is answerable for what it does. We design AI to recommend, draft and triage rather than to make final decisions about people. Where a system would touch someone's employment, money, health, safety or access to a service, we build a human review step into it and recommend that it stays in place — and if the client's process cannot support that, we say so before we build rather than after. What happens after handover is the client's call. What we control is that the system is designed to be reviewable and that the recommendation was made plainly.

3. What we will not build

Being specific is more useful than being principled, so here is the actual list. We decline:

  • systems that monitor employees' behaviour, keystrokes, sentiment or productivity for surveillance
  • emotion recognition, or inference of health, sexuality, religion, race or political opinion from faces, voices or behaviour
  • automated hiring, firing, credit, insurance or tenancy decisions taken without human review
  • bots that claim or imply they are human
  • collection of personal data by scraping, or any use of personal data the person it belongs to would be surprised by
  • interfaces designed to pressure, mislead, or make it hard for someone to say no

The list is not exhaustive. Where a request sits close to a line we raise it and talk it through, rather than quietly deciding on your behalf.

4. Your data stays yours

We work with the minimum client data an engagement needs, and where it is practical we build inside your own accounts and tenancies so your data stays under your control. We do not use client data or client documents to train models, and we do not reuse one client's material for another. Where a project needs a third-party AI provider, we tell you which provider it is and where the processing happens before anything is sent, and point you to that provider's own terms so you can check their retention rules directly. Personal information is handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles — the detail is in our privacy policy.

5. We are honest about accuracy

Language models are confidently wrong sometimes, and no amount of engineering removes that. We do not quote accuracy figures we have not measured on your data. Instead we design for the failure: systems cite their sources so an answer can be checked, low-confidence cases escalate to a person instead of guessing, and we agree with you in advance what the system does when it does not know. Before handover we test against your real edge cases, not a demo script.

6. People should know when it is AI

Anyone talking to a system we built is told that it is a system, in plain language, early. AI-generated drafts that go out under a person's name remain that person's responsibility to check. We advise clients to disclose material AI use to their own customers, and we hold ourselves to the same standard on this site.

7. Nova, the assistant on this site

Nova answers questions about our services using a language model over our own published material. It introduces itself as an assistant. It can be wrong, and its answers are general information rather than professional advice. It does not make decisions, take payments, or touch account access. Conversations are stored against a pseudonymous session identifier. We have configured our model routing so that a request is never sent to a provider that trains on it, and the models behind Nova are served by Google. What we cannot promise is that nothing is retained at all, so we still ask you not to enter confidential or identifying information — section 4 of our privacy policy has the detail. What Nova cannot answer, a person reads.

8. The standards we work to

We align our practice with Australia's AI Ethics Principles and the Australian Government's Voluntary AI Safety Standard, and with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where a client operates under a sector regulator or an internal AI policy, we work to theirs as well. We hold no AI certification and do not claim one — we would rather describe what we actually do and let you check it.

9. Tell us if we get it wrong

If something we built or run behaves in a way that seems unfair, misleading or unsafe, we want to hear about it. Write to hello@naghmehelahi.com.au with enough detail to identify which system and what happened. We are a small team, so we cannot promise to investigate every report, but we read what arrives and aim to reply to substantive ones within ten business days. Where a concern turns out to be well founded we will tell you what we are changing; where we disagree we will say so and why. Security vulnerabilities have their own channel and a faster commitment — see /.well-known/security.txt.

Read our privacy policy