Legal
Responsible AI at Germinate
Last Updated: August 2, 2026
We deploy AI agents that do real work on our clients' businesses. That only works if the AI can be trusted — by the leaders who buy it, the teams who work alongside it, and the people its outputs affect. This page summarizes how we build and run AI responsibly. The full detail lives in our AI Ethics Policy and AI Accuracy & Bias Disclosure.
Our position is simple: AI should do useful work on your business without creating new harm to that business, its people, or the people it serves.
Our Principles
Human accountability. AI assists people; it does not replace their judgment on decisions that matter. For consequential outcomes — financial, legal, contractual, safety-related, or affecting an individual — a qualified person stays responsible and in the loop. We do not deploy agents to make autonomous decisions about individuals.
Honesty about capability. AI is useful, not infallible. Our agents can make mistakes, omit relevant information, or misinterpret a request, and we say so plainly. We do not oversell accuracy, hide limitations, or let a demo imply a guarantee. If we are unsure an agent is fit for a use, we say so.
Your data stays yours. Client data is connected to do the agreed work, isolated from every other customer, and used only for the purposes the client authorized. We never train AI models on client data — not for our own use, not for any other customer's benefit. Agent configurations, prompts, and knowledge bases built for a client stay private to that client's tenant. Where we generalize implementation patterns into reusable templates, they contain no client data, content, or confidential business information.
Grounded, checkable outputs. Wherever possible, agents draw from your connected data and surface what they used, so outputs can be checked against the record rather than taken on faith. We favor agents that show their sources over agents that ask to be trusted.
Fairness. AI models learn from data, and data carries the biases of the world that produced it. We treat this as a real risk to manage — especially where agents touch people. Agents that influence decisions about people get extra scrutiny, additional testing, and mandatory human review, and where feasible we test for disparate outcomes across groups. We decline work we cannot do fairly.
Security and safety. Agents run on systems that hold data our clients cannot afford to leak. We build for tenant isolation, least-privilege access, and safe failure — an uncertain agent should escalate, not improvise.
Accountability for outcomes. Because we build and run the agents, we own the results with our clients. When something goes wrong, you get a person who is responsible — not a support queue and a shrug.
What We Will Not Do
Some uses are out of bounds regardless of commercial appeal. Germinate will not knowingly build or operate agents that: make autonomous, unreviewed decisions that materially affect a person's employment, finances, health, legal standing, or access to a service; deceive people into believing they are interacting with a human when disclosure is warranted; conduct unlawful surveillance or process personal data without a lawful basis; generate deliberately deceptive, defamatory, or manipulative content; discriminate on protected characteristics or help evade anti-discrimination laws; or operate in safety-critical settings without controls and human oversight appropriate to the risk.
Where a request is ambiguous, we escalate it rather than guess — and an unresolved ethical concern can halt a build.
How We Practice This
Every agent goes through a lifecycle designed to make these principles real, not decorative. Before we build, each proposed agent is screened for ethical risk and its intended use, data sources, limitations, and out-of-scope conditions are documented — people-affecting uses are flagged for a fairness review and a named human reviewer. Before launch, agents are tested against representative real cases with an accuracy bar agreed with the client; failures block deployment until resolved. In production, agents run with monitoring, defined escalation paths, and human-in-the-loop checkpoints for high-impact work, and every agent is re-reviewed on a set cadence or sooner when the business or the models change.
Framework Alignment
Our practices are organized around the four functions of the NIST AI Risk Management Framework (AI RMF 1.0) — Govern, Map, Measure, Manage — informed by the NIST Generative AI Profile (NIST-AI-600-1). We use the framework as our governance discipline; we do not claim certification, which NIST does not offer. Section-by-section mapping is in the AI Ethics Policy and AI Accuracy & Bias Disclosure.
Your Part
Responsible AI is shared work. Clients are responsible for providing accurate, lawfully obtained data for agents to work from; keeping a qualified human in the loop for consequential decisions; using each agent for its intended purpose and telling us when the business changes; and meeting the legal and regulatory obligations of their industry.
Questions or Concerns
Concerns about how a Germinate agent is built or behaving: ethics@germinate.ai. Questions about a specific agent's accuracy and fairness profile: policy@germinate.ai, or speak with your Germinate contact. Good-faith reports are welcomed, not penalized.
This page describes our practices and commitments. It is not a warranty, and nothing here overrides the terms of a signed agreement between Germinate and a client.