Trust / Responsible AI

AI systems should have explicit boundaries and accountable owners.

Amidship uses AI where it improves the system, while keeping responsibility for product behaviour, data access, consequential actions, and final delivery with accountable people. These are current delivery practices and commitments — not an external certification or audit opinion.

Human accountability stays explicit.

Every engagement has a named accountable human lead. Material product, architecture, security, privacy, and AI-risk decisions are reviewed by people responsible for the outcome. AI tools are delivery tools; they are not represented as employees, cleared resources, references, credentials, or decision-makers.

For a material AI-enabled workflow, we document the intended purpose, users, data boundaries, permitted actions, excluded uses, human-approval points, operational owner, and practical escalation or shutdown path.

Agentic systems get only the authority the workflow needs.

When software can invoke tools or take actions, Amidship treats permissions and control paths as part of the product design.

  • allow only the tools and actions required for the workflow;
  • apply least-privilege access to systems and data;
  • require human approval for consequential, irreversible, financial, legal, safety-related, or externally binding actions unless the client has explicitly approved another control model after appropriate assessment;
  • preserve useful logs or traces of material actions where technically and legally appropriate;
  • handle tool failures, unexpected state, prompt injection, and conflicting instructions;
  • provide escalation, human takeover, and practical disable paths;
  • test partial completion, recovery, and failure behaviour rather than evaluating only the happy path.

Evaluation starts before production.

Acceptance criteria should be defined before production use and should match the actual risk of the workflow. Depending on the system, evaluation can include task correctness, groundedness, retrieval quality, action success and failure, escalation behaviour, access boundaries, prompt-injection resistance, latency, cost, degraded-service behaviour, human override, and bias or differential impact where relevant.

AI-generated code and artifacts are held to the same engineering, security, licensing, and review expectations as other work.

Client data and model use stay inside the engagement boundary.

Amidship uses client-approved systems and environments for confidential information, minimizes data to what the task requires, and prefers synthetic, masked, or minimized test data when feasible. Material model providers, data categories, retention/training settings, residency considerations, and subprocessors are identified where the engagement or law requires them to be disclosed.

Sensitive information is not intentionally entered into unapproved consumer AI services contrary to client policy, contract, law, or security classification.

Automated decisions need the client's legal and policy context.

When an AI system may make or support decisions about individuals, benefits, eligibility, enforcement, prioritization, or service access, Amidship flags the use case for the client's legal, privacy, policy, and program review before production.

For federal administrative decision systems, the engagement can be designed to support applicable Government of Canada requirements, including the Directive on Automated Decision-Making and the Algorithmic Impact Assessment where they apply. The responsible government institution remains accountable for determining and satisfying its statutory and policy obligations.

Failure and change are operating conditions, not edge cases.

A material security, privacy, or AI-safety incident should trigger containment or disablement, preservation of relevant evidence, impact assessment, client notification according to applicable obligations, remediation, and re-evaluation before the affected capability is restored.

Production AI systems should retain practical documentation of intended and excluded uses, data sources, material model/provider choices, tool permissions, evaluation results, human-oversight points, known limitations, operational ownership, incident paths, and material changes.

What this statement is — and is not.

This page describes Amidship's current delivery baseline and the commitments it is prepared to make in an engagement. Contract-specific requirements can be stricter and take precedence.

Amidship does not claim that this framework has been independently audited or certified, and does not claim ISO, SOC 2, CPCSC/CMMC, or another external assurance credential unless that credential is actually obtained and current.