Responsible AI

AI Policy

How we design, build, and deploy agentic systems – and what clients and their end users can expect from them.

Last updated August 19, 2026

Nablon AI builds agentic systems for organizations operating in Banking, MedTech, RCPG, and Industrial sectors – environments where an AI system’s decisions and actions carry real consequences for real people. This policy sets out how we design, build, and deploy AI, and what our clients and their end users can expect from systems we build.

It applies to three things: the agentic systems we build and deliver to clients, the internal tools and AI systems we use to run Nablon itself, and the conduct we expect from every Nablon employee and contractor when using AI in their work.

1.Human Oversight and Accountability

Agentic systems we build operate with a defined boundary of autonomy agreed with the client – they are not given open-ended authority to act without appropriate checkpoints. High-consequence actions (financial transactions, medical-adjacent recommendations, irreversible operations) require human review or approval before execution, unless a client has explicitly accepted a different risk posture in writing.

Every agentic system we deliver has an identified accountable owner on the client side and a clear escalation path back to Nablon.

2.Transparency

People interacting with an AI system we have built are told they are interacting with AI – not left to assume otherwise. Where our systems generate content that could be mistaken for human-created work, that content is marked as AI-generated in a way a user can actually detect, in line with the EU AI Act’s Article 50 transparency obligations and equivalent requirements in other jurisdictions our clients operate in.

We disclose, in plain language, what an agentic system is allowed to do, what data it can access, and what it cannot do.

3.Fairness and Non-Discrimination

Systems that inform decisions about people – creditworthiness, eligibility, risk scoring, treatment recommendations, hiring – are tested for disparate impact across relevant groups before deployment, and re-tested when the underlying model, data, or use case changes materially.

We do not knowingly build systems designed to circumvent fair-lending, anti-discrimination, or equivalent sector-specific regulation, and we raise concerns with clients when a requested capability appears to create that risk.

4.Data Privacy and Minimization

Client data is used only for the purpose it was provided for. We do not use one client’s data to train or fine-tune models used for another client without explicit written consent. Agentic systems are scoped to access the minimum data needed to perform their function, not broad standing access by default.

This principle extends to how Nablon manages its own employee and contractor access to systems internally – the same data-minimization standard we ask of our AI systems, we hold ourselves to operationally.

5.Security and Robustness

Agentic systems are tested for adversarial inputs, prompt injection, and unsafe tool-use before going into production, not just for functional correctness. Systems with access to sensitive data or consequential actions undergo a security review appropriate to that risk level before deployment.

We maintain incident response procedures for AI systems we operate or manage, including a path to disable or roll back an agentic system quickly if it behaves unexpectedly.

6.Reliability, Testing, and Known Limitations

We do not represent an AI system as more capable or more certain than it is. Every system we deliver comes with a documented statement of known limitations, tested operating conditions, and the conditions under which it should not be relied upon without human review.

7.Regulatory Alignment

We track and design against the regulatory frameworks relevant to where our clients operate and the sectors they are in, including:

  • EU AI Act – risk-based obligations for AI systems placed on or affecting the EU market, including the Article 50 transparency rules in effect since 2 August 2026. Scope is triggered by whether a system’s output reaches an end user located in the EU, not by where Nablon or the client is headquartered, and is checked per engagement at scoping stage.
  • Sector-specific expectations for AI and model risk in banking, including model risk management guidance from banking regulators in the markets we serve.
  • Healthcare and MedTech AI/ML guidance, such as the FDA framework for AI/ML-based software as a medical device, where our systems touch health-adjacent decisions.
  • Applicable data protection law, including GDPR and equivalents, governing any personal data our systems process.

This list is not exhaustive. We revisit it per active client vertical at each review, and whenever a new client vertical is onboarded.

8.Governance

Responsible AI review is part of how we scope and deliver engagements, not a separate check performed after the fact. It runs across four stages.

8.1Engagement Scoping

We identify the risk level of the proposed system – data sensitivity, decision consequence, autonomy level – before the statement of work is finalized. This includes a check on whether the system’s output could reach an EU-located end user, which triggers EU AI Act Article 50 disclosure requirements.

8.2Build

We apply the principles above in proportion to that risk level. Higher-risk systems get more testing, more human-in-the-loop design, and more explicit client sign-off on autonomy boundaries.

8.3Pre-Deployment Review

A named reviewer, independent of the build team, signs off before a system with meaningful autonomy or data access goes live.

8.4Post-Deployment

Every delivered system has defined monitoring and a channel for the client or its end users to flag concerns, with a committed response time.

9.Raising a Concern

Clients, users, or Nablon employees who believe a system we have built is behaving unfairly, unsafely, or contrary to this policy can raise it with us directly.

We aim to acknowledge within two business days. Anything indicating an active safety or data risk is escalated immediately under our incident response procedure.

hello@nablon.ai

10.Review Cadence

This policy is reviewed at least every 12 months, or sooner if relevant regulation changes materially – as it currently is under the EU AI Act’s phased rollout – or if a significant incident indicates a gap in our approach. The "Last updated" date at the top reflects the most recent revision.