Responsible AI

AUDT uses AI to help compliance and risk teams work faster — not to replace human judgement. Every AI output is advisory. Every decision requires a human.

AI Model & Provider

ModelGoogle Gemini 2.5 Flash
ProviderGoogle AI Studio / Vertex AI
Integration@google/genai SDK — imported only in lib/providers/ai/
Data retentionGoogle does not retain prompt data for model training under the AUDT API agreement
Data residencyPrompts are processed by Google infrastructure — not stored in AUDT’s India region

Zero Training Guarantee

AUDT’s AI is powered by Google Gemini via the API. Under API terms, customer data submitted to the Gemini API is not used to train or improve Google’s models.

  • Your vendor data is never used to train any AI model
  • Your compliance frameworks and evidence are never shared with Google for training
  • Audit logs, risk registers, and contract data are never used as training data
  • AI-generated outputs are not sent back to improve the model

Human-in-the-Loop by Design

AI in AUDT generates recommendations, summaries, and draft content. No AI action is autonomous — every AI output requires a human to review, accept, or reject before it takes effect.

AI Risk Findings
AI drafts; human reviews and saves
CAPA Suggestions
AI suggests 3 options; human selects and creates
Renewal Recommendation
AI scores; human makes final decision
Gap Analysis
AI identifies; human reviews severity and assigns owner
Control Narrative
AI writes; human approves before use in audit evidence
Agent Actions
AI proposes; human must approve via Approval Queue

AI Audit Trail

AUDT’s Security Command Center™ records every AI prompt with sensitivity classification, PII detection, and user attribution. Enterprise administrators can review all AI interactions.

  • Every AI prompt is logged with timestamp, user, and module context
  • Sensitivity classification: clean · low · medium · high · blocked
  • PII detection — prompts flagged when personal data patterns are detected
  • Blocked prompts tracked — 30-day usage statistics available to admins
  • ai_prompt_logs table — org-scoped, RLS enforced, not accessible cross-tenant

EU AI Act Alignment

AUDT’s AI use cases fall in the minimal risk or limited risk tiers under the EU AI Act. AUDT also provides an AI Governance™ module to help customers manage their own AI systems against EU AI Act, ISO 42001, and NIST AI RMF requirements.

Risk classificationMinimal / limited risk — all uses are advisory
TransparencyAI-generated content is clearly labelled in the UI
Human oversightNo autonomous decisions — human approval required
AccountabilityFull audit trail with user attribution
Model cardGemini 2.5 Flash — Google’s published model documentation
Customer AI governanceAI Governance™ module manages customer AI inventories

AI Output Caching Policy

AUDT caches AI-generated summaries and reports to reduce latency and cost. Cached outputs are stored in the ai_compliance_insights table (org-scoped, RLS enforced) and refreshed on demand.

Executive summaries24-hour TTL — refresh via the Refresh button in the UI
Per-entity narratives24-hour TTL — risk narratives, control summaries
Advisory outputs24-hour TTL — Regulatory Advisor, AI Governance Copilot
Chat responsesNot cached — each turn is a live API call