Skip to content
Legal

Responsible AI and Technology

North is an AI-Native Growth Office, so how we use AI is not a footnote. This page sets out the principles we work to, including the parts that are inconvenient to admit.

Effective
August 4, 2026
Last updated
August 4, 2026
Operated by
Ayush Malik

Why this page exists

Plenty of businesses now say they use AI. Far fewer say how, on what, with whose data, and who checks the output. Those are the questions a serious client should ask, so we answer them here rather than waiting to be asked.

We don't just sell generic services. We diagnose businesses and build growth systems that actually work. AI is one instrument in that, not the point of it.

AI is a tool, not a decision-maker

We use AI where it does something useful: accelerating research, drafting, summarising, structuring information, analysing patterns in data, and building systems that handle work that used to need a person for every instance.

We do not use it to replace judgment about a business. A diagnosis is a claim about where a company is losing value, and that claim needs a person who has looked at the business and is willing to be accountable for it.

In plain English

If AI is the fastest way to get you a better answer, we use it. If it is not, we do not use it just because it is the fashion.

Human review stays in the loop

AI-generated material is reviewed by a person before it is used for anything that matters: a diagnosis, a recommendation, a proposal, a piece of code going into production, a message sent under a client's name, or a number a decision will be based on.

Where we build automated systems for a client, we design a review point into them. The right question is not whether a system can run unattended, but what it should escalate and to whom.

Client context matters

The same tool is appropriate in one business and reckless in another. Regulated sectors, sensitive customer data, safety-related processes and contractual restrictions all change what is sensible.

We ask about those constraints before we design around them, and we would rather recommend a duller system that fits than an impressive one that does not.

Confidential information

We handle client information carefully and share it internally only with the people doing the work.

We do not knowingly submit confidential client information to public AI models for training, and we do not knowingly use one client's confidential information to build something for another. Where a tool's terms would allow content to be used for training, we configure it otherwise where that option exists, or we do not put confidential material into it.

Minimising unnecessary exposure

We try to work with the least sensitive information that will do the job. In practice that means:

  • Using samples, extracts and anonymised or aggregated data where they are enough
  • Removing identifiers that the task does not need
  • Keeping access to systems and accounts limited to what the work requires, and handing it back when the work is done
  • Preferring tools where data handling is documented over tools where it is not
  • Asking before introducing a new tool into a client environment

Third-party AI providers

We use AI services operated by other companies, and we may change providers as the field moves. Each provider has its own terms, data practices and retention behaviour, and those terms govern what happens inside their systems.

We choose providers with that in mind, but we do not control them and we cannot give assurances on their behalf. Where a specific provider matters to an engagement, we will name it as part of that engagement.

What AI systems get wrong

AI systems produce outputs that can be inaccurate, incomplete, biased, outdated, or confidently wrong. They can misread context, invent detail, and reproduce patterns present in their training data.

This is not a reason to avoid them. It is a reason to build around them properly: constrained inputs, review points, monitoring after deployment, and a clear answer to what happens when the system is wrong.

Where responsibility sits

Clients remain responsible for their own operational, legal, financial, regulatory and employment decisions. We can build a system, explain what it does and what it cannot do, and recommend a course of action. We cannot take on responsibility for decisions made inside your business.

Where a system we build will influence decisions about people, money or compliance, we will say so plainly and expect the business to apply its own oversight.

Disclosure

Where AI use is material to an engagement, we disclose it: what is automated, what is reviewed, what data is involved, and which categories of tool are used. If you would prefer a piece of work to be done without AI assistance, say so and we will tell you what that changes in cost and timeline.

Questions

This statement describes how Ayush Malik, working under the name North, approaches AI in client work. It is not a contract, and specific obligations for an engagement live in the agreement for that engagement.