AI Transparency Statement
What the AI in CommsOperator does, which models it runs on, how a person stays in control, what is logged, where it can be wrong, and how EU AI Act transparency duties are met.
- Version
- 1.0
- Effective
- 2026-08-26
- Last updated
- 2026-08-26
- Provider
- WomenTech LLC
This statement describes how AI works in CommsOperator so a customer, a security reviewer, or a recipient can judge it. It is written for the transparency expectations of the EU AI Act and for security questionnaires that now ask about model provenance, retention, and human oversight.
1. What the AI does
How to read this table: each row is one AI feature, what it produces, and who decides what happens with the result.
| Feature | What it produces | Who decides |
|---|---|---|
| Inbox triage | A classification: Focused, Other, or Spam | Automatic classification; a person can reclassify and the inbox rules always win |
| Reply drafting | A proposed reply grounded in the thread, knowledge base, and CRM context | A person edits and sends |
| Sales agent | Outreach plans, drafted steps, compliance checks, reply intent classification | A person approves each step unless an administrator enables automatic delivery for a fixed template |
| Knowledge chatbot | Answers from your published content with citations | Answers automatically where the widget is set to auto-reply, with escalation to a person |
| Content tools | Drafted articles, changelog entries, task plans, summaries | A person reviews before publishing |
| Meeting summaries | Summaries, participants, next steps from transcripts | A person reviews; tasks are created only on confirmation |
2. Providers and data handling
- AI processing runs on the OpenAI API using GPT-4.1 and GPT-4o family models, selected per feature.
- Under OpenAI's API data usage policy, content sent through the API is not used to train OpenAI's models.
- CommsOperator trains no models on customer data and builds no cross-customer profiles.
- Prompts carry only what the task needs: the conversation, retrieved knowledge, and relevant CRM fields.
- Embeddings of knowledge base content are stored in the customer's own workspace for search.
- Dedicated instances can run local inference with Ollama, so prompts never leave the instance.
3. Human oversight
- Three autonomy levels: observe, draft for review, and auto-send. Draft for review is the default.
- Auto-send requires a feature flag, a policy pack that permits it, and passes suppression, daily caps, and the EU AI Act check. For fixed-template campaigns it also requires an administrator to confirm the exact rendered sequence; any change invalidates that consent.
- Policy packs set risk tiers, required approver roles including dual approval, disallowed topics, required disclaimers, and channel limits.
- An administrator can disable all AI in a workspace with one switch.
4. Logging and auditability
Every agent step records its phase, input, output, decision, token use, duration, and outcome. Human actions on drafts (unlock, edit, reject, manual send) are logged with the actor and time. An opt-in compliance engine adds trace identifiers, content hashes for tamper detection, and a machine-readable compliance report for authorised auditors. Administrative actions are recorded in the audit log with actor, resource, IP address, and user agent.
5. EU AI Act
CommsOperator is not a high-risk AI system under the EU AI Act: it does not make decisions producing legal or similarly significant effects on individuals. For Article 50 transparency duties, which apply from 2 August 2026:
- Automatically sent AI-drafted messages to recipients likely to be in the EEA are downgraded to a human approval by default, so an accountable person sends them.
- Where a workspace explicitly opts out of that downgrade, an AI-origin disclosure line is appended to the message, telling the recipient the message was generated and sent by an AI assistant and that they can reply to reach a person.
- Recipient location is inferred from the contact's country field, then the email domain. Errors default to the safer behaviour: hold for human approval.
- The chatbot identifies itself as an AI assistant and offers a route to a person.
6. Known limits
- AI output can be wrong, out of date, or confidently plausible. It is a proposal, never advice.
- Grounded answers depend on the quality of your knowledge base; gaps produce a refusal, not an invention, but a wrong article produces a wrong answer.
- Classification is a heuristic: a legitimate message can land in Other, and a well-crafted spam message can land in Focused.
- EU residency inference is a heuristic; a .com address with no country on file is not flagged as EEA.
- Automated purging of expired agent logs is not yet enabled; a six-month working window is computed and reported.
7. Reporting a problem
If an AI feature produced something harmful, misleading, or unlawful, tell us at office@commsoperator.com with the workspace and approximate time. We can trace the exact agent run and its inputs.