AI Governance & EU AI Act Readiness Policy

Version 1.0 · Last Updated:

1. Purpose

This policy sets out Murzo Group's approach to AI governance, EU AI Act readiness, AI risk classification, prohibited uses, high-risk AI, transparency, human oversight, data protection, security, and responsible deployment.

The purpose is to allow useful AI adoption while preventing unlawful, unsafe, discriminatory, misleading, insecure, or poorly controlled AI use.

2. Scope

This policy applies to AI systems, machine learning, generative AI, automated decision tools, chatbots, image generation, voice tools, biometric tools, surveillance analytics, recruitment tools, scoring tools, customer tools, code assistants, security tools, and AI embedded in products, platforms, supplier systems, or client work.

3. Policy Position

Murzo Group will use AI proportionately, transparently, and under human control where decisions affect people, safety, legal rights, employment, security, access to services, public communications, product compliance, or high-value decisions.

AI must not be used merely because it is available. The business purpose, risk, data, security, accuracy, legal basis, human review, and supplier position should be understood before use.

4. Prohibited and Restricted Uses

  • Manipulative, deceptive, exploitative, discriminatory, or unlawful AI use
  • Untargeted scraping of faces, biometric identification, emotion recognition, or biometric categorisation without lawful basis and senior approval
  • Fully automated employment, recruitment, disciplinary, vetting, credit, eligibility, legal, or significant personal decisions without appropriate legal review
  • AI-generated financial, legal, medical, safety, product, food, customs, tax, cultural property, or investment advice without expert human review
  • Deepfakes, impersonation, fake endorsements, synthetic evidence, or misleading media
  • Uploading confidential, personal, client, security-sensitive, trade, provenance, source-of-funds, or controlled information into unapproved AI tools

5. EU AI Act Readiness

Where Murzo Group provides, deploys, imports, distributes, or uses AI in the EU or in connection with EU-facing products or services, the relevant EU AI Act role and risk category must be considered.

High-risk or potentially high-risk AI requires stronger review, including purpose, data quality, bias, human oversight, technical robustness, cybersecurity, instructions, monitoring, incident handling, and supplier responsibilities.

6. Recruitment, Vetting and Worker AI

AI used for recruitment, CV screening, interview analysis, worker monitoring, performance, rota allocation, vetting, or disciplinary decisions can create legal, equality, privacy, and EU AI Act risks.

Such use requires approval before deployment and must include human review, bias awareness, transparency where required, and a clear route for challenge or correction where appropriate.

7. Transparency and Public Communications

AI-generated or AI-assisted content must not mislead customers, investors, regulators, workers, suppliers, or the public. AI-generated claims, images, product descriptions, provenance statements, sustainability claims, safety statements, legal wording, or investment wording require suitable human review.

Where AI interaction, synthetic media, or AI-generated content should be disclosed, Murzo Group will make the disclosure clear and proportionate.

8. Supplier and Data Controls

AI suppliers and tools must be assessed for data handling, confidentiality, security, model use, training use, location, output ownership, audit support, incident routes, and exit options where relevant.

AI governance, supplier, approval, risk, and incident evidence should be limited to what is needed for lawful use, safety, accountability, client assurance, regulatory response, or dispute handling.

9. Review

This policy will be reviewed when Murzo Group adopts material AI tools, launches AI-enabled products, uses AI in recruitment or security, targets EU markets, or AI law materially changes.

Murzo Group authorised signature