AI when it helps. People when they matter.
We build automation and use AI where it genuinely improves a process. We do not believe every problem needs AI, and we do not believe important decisions should disappear into a black box. These principles guide the systems we design and operate.
Sometimes AI is the right tool. Sometimes a straightforward automation, integration or better process will do the job more reliably. We use AI because it improves the outcome, not because it is fashionable.
AI can read, extract, compare, summarise and recommend. Where something requires judgement, approval or accountability, we design the workflow so that an appropriate person remains involved. The more significant the consequence, the more important that control becomes.
Client information is used to deliver the service we have been asked to provide. We do not sell it. We do not use client data to train our own general-purpose AI models. Where we use third-party AI services, we use approved business services and configure them so that client information is not used to train their general-purpose models where the relevant service permits and contractually supports this.
An AI model does not need access to everything simply because it needs access to something. We design workflows to send only the information reasonably required to perform the relevant task.
AI can be wrong. We do not pretend otherwise. We design workflows around that reality, using controls such as validation, approval steps, logging and human review where appropriate to the risk.
We do not intentionally disguise the use of AI where knowing about it is important to the person using or affected by a process. Where AI materially contributes to an important decision or outcome, we aim to make its role understandable and provide appropriate human oversight.
AI is not an exception to our security standards.
Information sent to AI services is handled as part of the same controlled environment as the rest of the workflow, with appropriate access controls, encryption and monitoring.
Where we use large language models, we use paid business or enterprise-grade API services with contractual or service-level protections designed so that customer data is not used to train the provider’s general-purpose models.
Technology providers may supply the models. DDX remains responsible for how we design and operate the solutions we provide. We assess the tools we use, review how they handle information and change our approach when the technology, risks or regulations change.
Questions about how we use AI can be sent to info@ddx-consulting.com.