Artificial Intelligence Policy
AI Usage Policy
Core Principle
AI suggests, you decide. ShelfGRC uses artificial intelligence to assist and enhance your GRC workflows, but you always maintain full control and final decision-making authority.
Last updated: 24 September 2026
1. Introduction
This AI Usage Policy explains how ShelfGRC uses artificial intelligence (AI) and machine learning (ML) technologies, what data is used to power AI features, how AI-generated content is handled, and your rights and controls over AI functionality.
This policy should be read in conjunction with our Terms and Conditions and Privacy Policy.
2. Our AI Philosophy: Propose-Only Workflow
2.1 Human-in-the-Loop Approach
ShelfGRC is built on a "propose-only" AI workflow, also known as "human-in-the-loop" (HITL). This means:
- AI Proposes: Our AI systems analyze your data and generate suggestions, recommendations, and draft content
- You Decide: All AI-generated proposals require explicit human review and approval before being implemented
- No Automatic Actions: AI never makes final decisions or takes actions on your behalf without your approval
- Full Transparency: All AI-generated content is clearly labeled and includes citations or reasoning where applicable
2.2 Why Propose-Only?
Governance, risk, and compliance decisions have significant business and legal implications. While AI can accelerate analysis and provide valuable insights, human judgment, context, and accountability are essential. Our propose-only approach ensures:
- You retain full control and responsibility for GRC decisions
- AI serves as an intelligent assistant, not a replacement for human expertise
- Compliance with regulatory requirements for human oversight
- Accountability and auditability of all decisions
3. How We Use AI in ShelfGRC
3.1 AI-Powered Features
ShelfGRC does not use AI to create, identify, or generate new risks, controls, policies, obligations, incidents, or other register entries on its own initiative, and AI never decides a rating, status, or classification for you. Proposals come from manual entry (which the assistant's Fill Form can pre-populate for you to edit), a reviewed bulk import (with AI-suggested column mappings), or a converted incident submission; the backend-only features below would let AI draft one from a document, control or risk. Every proposal is reviewed and approved by a person before it changes a register (maker-checker). AI's role is limited to the following, narrower features:
Chat Assistant
- Answers your questions about your own tenant's data (risks, controls, evidence, policies, obligations, incidents), citing the records it draws on
- Read-only: the chat assistant never creates, edits, or deletes a register entry
- Scoped to the data you are already permitted to see
Data Import Assistance
- When you upload a CSV or spreadsheet, AI suggests which source column maps to which ShelfGRC field
- You review and can override every suggested mapping before anything is imported
- Nothing is created until you submit the import; the import then goes to the Proposals queue like any other change
Report Narrative
- AI can draft narrative summary text for executive and board reports, based only on your tenant's own data
- Draft narrative is for your review before you share or export a report; it does not write back to any register
Backend-Only Features (Not Offered in the Product Today)
The following four capabilities exist in our backend but are not offered in the product today — no part of the ShelfGRC interface calls any of them. We disclose them because they are functioning API endpoints, not because you can use them yet. If we offer any of them in future, each will follow the same propose-only rule as every other AI feature: AI drafts a proposal, and a person reviews and approves it before it changes a register.
- Document Extraction: would read the text of a document you upload and propose facts, entities, and other register content drawn from it, limited to documents that are Public and Non-privileged
- Control Mapping: would map a control to compliance standard requirements (e.g. ISO 27001, SOC 2) and identify coverage gaps
- Compliance Suggestions: would analyze your organisation's profile (location, industry, operations) and suggest relevant obligations for your review
- Risk Triage: would suggest a severity, category, or tags for a risk
3.2 AI Technologies We Use
ShelfGRC uses Anthropic (Claude) for every AI-generated feature described above — chat responses, import-mapping suggestions, report narrative, and the four backend-only features (document extraction, control mapping, compliance suggestions, and risk triage). We do not use OpenAI, Google, or other third-party language model providers, and we do not use custom-trained machine learning models — risk, control, and severity ratings in ShelfGRC are calculated using deterministic, tenant-configurable scoring rules, not AI or ML predictions. Separately, vector embeddings that power search and retrieval for the chat assistant are computed by Amazon Bedrock (Titan) in the same region as your data (see our Privacy Policy for what that region is, including for a customer whose selected region is not yet enabled), and are scoped and filtered to what you are permitted to see.
4. Data Used for AI Processing
4.1 Your Customer Data
To provide AI-powered features, we process your Customer Data, including:
- Risk assessments and risk register entries
- Control descriptions and effectiveness data
- Evidence documents and metadata
- Compliance obligations and framework mappings
- Incident reports and response actions
- Organizational context (industry, size, jurisdiction)
4.2 Data Isolation and Privacy
Important: Your Customer Data is processed in isolation and is never used to train AI models that serve other customers. Specifically:
- Your data remains within your tenant boundary (multi-tenant isolation)
- AI processing is performed on a per-tenant basis
- We do not create shared AI models trained on multiple customers' data
- Your data is not shared with other ShelfGRC users
4.3 Third-Party AI Providers
We use two third-party AI providers to power the features described in Section 3: Anthropic (language generation — chat, drafting, and suggestions) and Amazon Bedrock (vector embeddings that power search and retrieval). When using these services:
- We send only the minimum necessary data to generate AI responses. Records the assistant retrieves on your behalf — to answer a question, draft narrative, or search your tenant's data — are limited to Public, Non-privileged, and unrestricted records, regardless of your own access level, and relevant record content may include the names of record owners. This limit applies to what the assistant retrieves, not to everything you can cause it to see: text you type into the assistant, spreadsheet sample rows you upload for import mapping, and the title and record ID of a record you already have open in an edit form can be sent to the AI provider regardless of that record's own classification
- We use enterprise agreements with data processing addendums (DPAs)
- We configure providers to not use your data for training their models
- Data is transmitted securely using encryption (TLS 1.3)
- Apart from the inputs listed above, we do not send personally identifiable information (PII) beyond what is necessary for the specific AI task (for example, an owner name on a record the assistant is answering a question about)
5. AI Accuracy and Limitations
5.1 AI Is Not Perfect
While our AI systems are designed to be helpful and accurate, they have limitations:
- Errors and Inaccuracies: AI-generated content may contain factual errors, outdated information, or incorrect recommendations
- Hallucinations: AI may generate plausible-sounding but incorrect or fabricated information
- Bias: AI models may reflect biases present in training data
- Context Limitations: AI may not fully understand your unique business context or nuanced requirements
- Regulatory Changes: AI recommendations may not reflect the latest regulatory updates
5.2 Your Responsibility to Review
You are solely responsible for reviewing, validating, and approving all AI-generated content before using it. This includes:
- Verifying the accuracy of AI suggestions
- Ensuring compliance with applicable laws and regulations
- Adapting AI recommendations to your specific context
- Consulting with legal, compliance, or other professional advisors as needed
5.3 No Liability for AI Errors
As stated in our Terms and Conditions, we are not liable for decisions made based on AI-generated content. AI proposals are advisory only and do not constitute professional advice.
6. Transparency and Explainability
6.1 Nothing From AI Reaches You Unlabeled
AI-suggested content is never applied silently:
- During a bulk import, AI-suggested column mappings are shown to you, field by field, before the import is submitted, and you can review and override every one
- AI-drafted report narrative is clearly presented as a draft for your review before you share or export it
- The chat assistant's answers cite the specific records they draw from, so you can verify the source
6.2 No Confidence Scores
ShelfGRC does not attach a confidence score or numeric certainty rating to any AI suggestion. You evaluate an AI-suggested import mapping or a draft report narrative the same way you would evaluate any other suggestion — by checking it yourself before you rely on it.
6.3 Audit Trail
Every proposal — whether from a manual entry, a bulk import with AI-suggested mappings, a converted incident report, or one of the backend-only features — is logged in an audit trail, including:
- Who created it and when
- Who reviewed it, and their decision (approve, reject, or edit), with any reason given
- Any modification made before it was applied
7. Your Control Over AI Features
7.1 Your Options
- Review before it counts: nothing from AI reaches a live register or a shared report without your review — every AI-suggested import mapping and every AI-drafted report narrative is shown to you first
- Proposal Review: approve, reject, or edit any proposal, whether it came from a manual entry or a bulk import with AI-suggested mappings
- Feedback: report an AI suggestion that was wrong or unhelpful (see Section 11)
7.2 Data Deletion
If you delete Customer Data from ShelfGRC, it is also removed from AI processing pipelines. See our Privacy Policy for data retention details.
8. AI Model Training and Improvement
We do not use your Customer Data, in aggregate or otherwise, to train or fine-tune any AI model. We track AI usage — token counts, cost, and rate limits — on a per-tenant basis to operate the Service and enforce the usage limits described in your subscription plan. This operational data is not used to improve AI suggestions and is never shared across tenants (see Section 4.2).
9. AI Security and Safety
9.1 Prompt Injection Protection
We implement safeguards to prevent malicious manipulation of AI systems, including:
- Input validation and sanitization
- Prompt injection detection
- Output filtering and safety checks
9.2 Content Moderation
AI-generated content is filtered to prevent:
- Harmful, offensive, or inappropriate content
- Disclosure of sensitive information
- Generation of malicious code or instructions
9.3 Monitoring and Incident Response
We monitor AI systems for anomalies, errors, and security issues. If we detect a problem affecting AI accuracy or safety, we will:
- Investigate and remediate the issue promptly
- Notify affected users if necessary
- Implement corrective measures to prevent recurrence
10. Compliance with AI Regulations
We are committed to compliance with emerging AI regulations, including:
- EU AI Act: Classification of AI systems and compliance with transparency and risk management requirements
- NIST AI Risk Management Framework: Alignment with trustworthy AI principles (valid, reliable, safe, secure, resilient, accountable, transparent, explainable, privacy-enhanced, fair)
- Australian AI Ethics Principles: Human-centered values, fairness, privacy protection, reliability, transparency, contestability, accountability
11. Feedback and Reporting Issues
11.1 Report AI Errors
If you encounter AI-generated content that is:
- Factually incorrect or misleading
- Biased or discriminatory
- Inappropriate or harmful
- Not functioning as expected
Please report it to us at contact@shelflabs.io. Include details about the issue and, if possible, a screenshot or description of the AI output.
11.2 Continuous Improvement
Your feedback helps us improve AI accuracy, safety, and usefulness. We review all feedback and use it to refine our AI systems.
12. Changes to This AI Usage Policy
We may update this AI Usage Policy as we introduce new AI features or in response to regulatory changes. We will notify you of material changes via email or in-app notification at least 30 days before changes take effect.
Current as at 24 September 2026
13. Contact Us
If you have questions, concerns, or feedback about our use of AI, please contact us:
Related Legal Documents