Trust
Responsible AI
Last updated: 2026-09-07
These commitments apply to every piece of work Totomoko delivers, whatever the client, sector or size of the job. They are the standard the work is held to, and they are also offered as a service: helping organizations set the same standard for AI they build or buy themselves.
1. Safety in operation
1.1 A person stays in control
Actions with consequences for people, money or systems are held for a person to approve until the client decides otherwise. Guardrails define what an automated system may do on its own, and those limits are written down and agreed before a system goes live.
1.2 Autonomy is earned, not assumed
An agent starts with the least autonomy the task allows and gains more only as its behavior is measured. Destructive or irreversible actions run as a preview first, and a stop switch that halts an agent is part of every deployment.
1.3 Tested before release, watched after
A system is evaluated against real cases before it goes live, and monitored for quality, cost and failures once it is running. Serious incidents are reported to the client without delay and the system is paused if a risk appears.
2. Security
2.1 Least privilege for every agent
Agents run with credentials scoped to the task and the session, not with a person's standing access. Secrets are never placed in prompts or logs.
2.2 Untrusted content is treated as data
Web pages, emails, documents and tool results an agent reads are treated as data, never as instructions. Systems are tested for prompt injection and goal hijacking before release, and isolated so that a compromised step cannot reach live systems.
2.3 Security is built to the client's standard
Delivered systems follow the client's existing security policies and, where none exist, the OWASP guidance for agentic applications. Vendors and models are checked for their security posture and data-use terms before they are chosen.
3. Data and privacy
3.1 The client's data stays the client's
Client data is used only for the client's work. It is not used to train models for anyone else, is not retained beyond what the work needs, and is processed where the client's law and policy require. Where data may not leave the organization, models are deployed privately.
3.2 Personal data is handled by the rules that apply to it
Where a system touches personal data, the lawful basis, minimization, retention and access rules of the GDPR and any local law are built in, a data protection impact assessment is carried out where required, and people can find out what is held about them.
3.3 Input data is checked for fitness
Before a system is trained or run on data, the data is checked for accuracy, completeness and representativeness of the people and cases it will be used on, and the client is told what was found.
4. Fairness and inclusion
4.1 Systems that affect people are tested for bias
Where a system scores, ranks, screens or makes recommendations about people, an impact assessment is done first, the system is tested for unfair outcomes before use and monitored after, and the client is told what was found.
4.2 Built for everyone it serves
Systems that face the public are designed to be usable by people with disabilities, in the languages the organization serves, and without excluding people who lack a device, an account or a credit card.
5. Transparency and accountability
5.1 People are told when they are dealing with AI
Anyone interacting with an AI system built by Totomoko is told so, and can reach a person. AI-generated content is marked as such where the law or the context requires.
5.2 What a system did can be inspected
Delivered systems log what they were given, what they decided and what they did, step by step, so that behavior can be reviewed, measured and audited by the client. Logs are kept for as long as the client and the law require.
5.3 Decisions can be explained
Where a system contributes to a decision about a person, the reasons can be stated in terms the person, a manager or a regulator can understand. Each system is documented: purpose, data, limits, and who is responsible for it.
5.4 Someone is accountable, on both sides
Every delivered system has a named owner at the client and a named contact at Totomoko. Totomoko is accountable for what it delivers and says so in writing.
6. Law and standards
6.1 Applicable law is designed in
GDPR, the EU AI Act, and sector rules are treated as requirements from the first design, not as a review at the end. Where the EU AI Act classifies a use as high-risk, the deployer duties (human oversight, monitoring, worker notification, log retention, registration) are planned into the delivery.
6.2 Aligned with recognized standards
Work is aligned with the NIST AI Risk Management Framework, ISO/IEC 42001 and the OECD AI Principles, and with the Fundraising.AI framework for nonprofit clients.
7. People and work
7.1 The people who will run the system are prepared
Staff who use or oversee a system are trained on what it does, what it cannot do and how to intervene, meeting the AI literacy duty of the EU AI Act. Workers affected by a system are told before it is used.
7.2 Work is moved, not people
The aim of automation is to move repetitive work to software and staff time to judgment, strategy and service. Changes to roles are planned with the client and communicated to the people concerned.
7.3 Resources are used in proportion
Models are sized to the task, so that the cost and energy of running a system are no larger than the job requires.
8. Honesty and limits
8.1 Honest about what AI can do
Where AI is not the right answer, or the data is not ready, the client is told so, including the option to do nothing. No result is promised that cannot be measured.
8.2 Work that is refused
No work is taken on that is intended to deceive, manipulate, surveil or harm people. That includes the practices the EU AI Act prohibits outright: social scoring; systems that manipulate people or exploit their vulnerabilities; untargeted scraping of facial images from the internet or CCTV; emotion recognition in workplaces and schools; biometric categorization that infers race, beliefs, sexuality or other protected characteristics; real-time remote biometric identification in public spaces; and predictive policing based on profiling. It also includes covert monitoring of workers, customers or beneficiaries beyond what the law allows and the people concerned have been told about. Surveillance work is refused as a matter of policy, not only where a law forbids it.
9. Where it happens in the work
9.1 AI transformation
| Stage | What is done |
|---|---|
| Diagnose | Who a system affects and what data it needs are recorded alongside the goals; an impact assessment is done for any system affecting people; the option to do nothing is always one of the options proposed. |
| Accelerate | Guardrails, permissions, human approval points, logging, data handling and legal requirements are specified in the design the client approves; evaluation on real cases, bias testing where relevant and security testing including prompt injection before go-live; documentation and training at handover. |
| Scale to AI-Native | Governance reviews as systems grow; monitoring of quality, cost and failures; incident reporting; log retention; review when the law, the data or the model changes. |
9.2 AI Consulting
| Stage | What is done |
|---|---|
| Discovery | Who the work could affect and what data it would rely on are recorded alongside the goals. |
| Audit | Data is checked for fitness; an impact assessment is done for any use that would affect people; legal and sector requirements are identified. |
| Roadmap | Guardrails, human approval points and legal requirements are written into the plan as requirements; the option to do nothing is always one of the options proposed. |
9.3 AI Development
| Stage | What is done |
|---|---|
| Define | Guardrails, permissions, human approval points, logging, data handling and legal requirements are specified in the design the client approves. |
| Build | Evaluation on real cases, bias testing where relevant and security testing including prompt injection before go-live; documentation for the people who will run the system. |
| Iterate & Scale | Monitoring of quality, cost and failures; incident reporting; log retention; review when the law, the data or the model changes. |
9.4 AI Training
| Stage | What is done |
|---|---|
| Baseline | Existing AI use is recorded, including which tools are in use and what data they touch. |
| Practice | People are trained on what the tools do, what they cannot do and how to intervene, using approved tools and the data-handling rules that apply, meeting the AI literacy duty of the EU AI Act. |
| Embed | Standards are written down: where AI is used, what is checked before output is relied on, and how data is handled; reviewed on a cadence the client sets. |
10. As a service
10.1 The same standard for your own AI
The same standard is available as a service: AI governance frameworks and policies, impact assessments, bias testing, evaluation and red-teaming, regulatory readiness for the EU AI Act and GDPR, alignment with ISO/IEC 42001 and the NIST AI RMF, and training for the people who will run the systems. Get in touch or book a call.