AI Client Policy
As an innovation-driven consultancy, new technologies like AI are adopted where they genuinely help. But like any new technology I bring into client work, special attention is paid to keeping risk surfaces to a minimum — from a privacy, security, and ethical standpoint. This policy sets out how AI is used across client engagements, and what clients can expect and control.
(For how AI is used in our own marketing and communications, see the AI Content Policy.)
Definitions
- Sensitive information — any client data that is confidential, regulated, or would cause harm if exposed: PII, credentials, proprietary business logic, financial data, and similar.
- Local / privately-hosted model — an AI model run on infrastructure not shared with or accessible by third-party cloud providers, used specifically to keep sensitive information out of external systems.
- Opt-out — a client's election, made at the start of an engagement, to exclude some or all of their codebase or data from AI-assisted work.
LLM-Driven Software Engineering
AI is used at gabe.digital to support software engineering. To keep security and privacy intact while maintaining quality and velocity:
- Only cloud providers with a strong privacy track record and clear privacy policy are used, and only where hosted in US, AU, CA, NZ, SG, or EU territories.
- Sensitive information is never used with cloud providers. Where AI must be applied to sensitive information, local or privately-hosted models are used, with additional scrutiny to ensure no logging or data leakage.
- The best-suited model for a given task is used, rather than defaulting to a single provider. Which models are in use on an engagement is disclosed on request.
Client Opt-Out & Bring-Your-Own Provider
- Clients may opt out specific parts of their codebase from AI-assisted work, or opt out entirely.
- Opt-out must be specified at the start of the engagement, and may increase billing, since work that would otherwise be AI-assisted shifts to fully manual effort.
- Clients may instead bring their own LLM provider (e.g., an enterprise account they already hold and trust). This is accepted, and can offset or avoid the additional billing that a full opt-out would otherwise incur.
IP & Ownership
- All AI-assisted work product belongs to the client, under the same IP terms as the rest of the engagement. AI involvement in producing a deliverable does not change who owns it.
- Client code, data, or content is never used to train, fine-tune, or otherwise improve any AI model, shared or otherwise.
Human Accountability
- A human remains accountable for every deliverable, regardless of how much AI assisted in producing it.
- AI may scaffold or suggest code, but all code is reviewed, tested, and understood by a human before it ships or reaches a client repository.
Generated Content & Good-Faith Use
- All solutions and advice provided are for good-faith, transparent use. Solutions must not mislead, misrepresent, vilify, slander, or otherwise constitute criminal or ethical negligence.
- Where AI-generated content is fully automated, or has the potential to mislead a viewer without specialist knowledge of the subject matter, a suitable disclaimer of its AI generation will be insisted upon.
- gabe.digital reserves the right to terminate a consulting agreement if this policy is not agreed to, or is broken.
Agentic Systems
Where engagements involve building or deploying AI agents:
- Agents are scoped to the minimum permissions needed for their task.
- Consequential or irreversible actions — sending communications, spending money, modifying production data — require a human checkpoint.
- Sufficient logging is kept to reconstruct what an agent did, and why, if something goes wrong.
- A retainer is highly recommended for any client running agentic systems in production, to ensure ongoing compliance and monitoring as the system, its dependencies, and its risk profile evolve over time.
Incident Response
If something goes wrong — a hallucinated output ships, a model mishandles data, an agent takes an unintended action — the response is:
- Immediate remediation.
- Prompt client notification.
- A root-cause review to prevent recurrence.
Vendor & Policy Changes
- If the AI vendor or model provider used on an engagement changes, and it's relevant to that engagement, the client is notified.
- Clients with their own AI governance requirements may specify stricter terms in their engagement agreement, which supersede the defaults in this policy. The same applies to a client's choice to bring their own LLM provider.
Auditing
AI tool input and output on client engagements are audited on a frequent basis, with particular attention to:
- Hallucinations and fact distortion in generated content or code
- Sensitive information mishandling, even where guardrails are in place
- Permission scope creep in agentic systems