Skip to main content

AI Use

Compliance OS may use AI-enabled features to assist users and Cyber Op Source professionals with tasks such as guided interviews, information organization, evidence guidance, document navigation, policy questions, and drafting support.

What AI is used for

Depending on the application and engagement, AI may assist with:
  • asking contextual interview follow-up questions,
  • summarizing or organizing participant responses,
  • helping users understand an evidence request,
  • identifying relevant material in authorized client-facing documents,
  • drafting explanatory text for human review,
  • supporting analysis performed by Cyber Op Source professionals.

What AI is not

AI output is not treated as an independent certification that a control is effective, that an organization is compliant, or that a risk should be accepted. AI should not be the final authority for:
  • formal assessment conclusions,
  • finding approval,
  • risk acceptance,
  • treatment approval,
  • risk closure,
  • legal conclusions,
  • client executive decisions.

Authorized context

AI-enabled client features should operate only on the information and context authorized for the user and workflow. For document or policy assistance, the system should favor authorized client-visible material rather than unrestricted internal assessment records.

Human review

Material AI output that affects assessment work, client deliverables, or governance should be subject to appropriate human review. See Human Oversight.

Sensitive information

Do not intentionally submit credentials, secrets, private keys, or unrelated highly sensitive data to an AI-enabled feature. Specific model providers, data handling, and retention controls may vary by service and contractual configuration. Engagement-specific commitments are governed by the applicable agreement.