Skip to content
Aurexus

Legal

Responsible AI Policy

Responsible AI Policy

Effective 30 July 2026 · Last updated 30 July 2026

Introduction

Aurexus Group Ltd ("Aurexus", "we", "us" or "our") develops artificial intelligence as part of intelligent transformation — not as an end in itself. This Responsible AI Policy sets out the principles, practices and governance expectations that guide how we research, design, build, deploy and maintain AI-enabled systems.

This policy applies to all Aurexus personnel, contractors and partners involved in AI development and delivery across our corporate activities and product portfolio, including BioAegix, NPTTE PharmaNG and BeatIQ.

Our Commitment

We believe organisations should not have to choose between innovation and responsibility. The most valuable innovation is innovation that can be trusted.

We commit to:

  • Engineering AI that supports human expertise rather than replacing accountability
  • Embedding governance, security and transparency from the earliest design stages
  • Evaluating AI systems for fairness, safety and operational fit before deployment
  • Learning continuously from research, practice, client feedback and regulatory guidance
  • Being honest about limitations, uncertainties and areas where our capabilities are still maturing

As an early-stage and growing company, we implement this policy proportionately, scaling formal governance as our deployments and regulatory obligations expand.

Guiding Principles

Our responsible AI approach is grounded in The Aurexus Principles and operationalised through the following commitments:

1. Human accountability

AI operates as decision-support within the Aurexus Method™. Professionals and client organisations retain judgement and accountability. We do not design systems that obscure responsibility or bypass required human review in regulated contexts.

2. Purpose and proportionality

AI is deployed only where it addresses a defined organisational need with measurable benefit. We reject capability without purpose — technology for its own sake is not progress we will pursue.

3. Safety and reliability

We prioritise safety, reliability and operational resilience, particularly in healthcare and regulated environments. Systems are tested against realistic scenarios before production use.

4. Fairness and inclusion

We assess AI systems for bias and disparate impact where relevant. Training data, feature selection and evaluation metrics are reviewed to reduce unfair outcomes. We acknowledge that bias mitigation is ongoing, not a one-time checkpoint.

5. Transparency and explainability

We provide appropriate transparency about AI use, limitations and intended scope. Where full explainability is not technically feasible, we document reasoning approaches, confidence indicators and escalation paths.

See our AI Transparency Statement.

6. Privacy and data stewardship

Personal data used in AI systems is processed lawfully under UK GDPR. Data minimisation, purpose limitation, security and retention controls apply throughout the AI lifecycle.

See our Privacy Policy and Information Security Policy.

7. Security by design

AI components are subject to the same security rigour as all platform engineering — including access control, encryption, vulnerability management and incident response.

8. Environmental proportionality

We consider computational efficiency and environmental impact when selecting models and infrastructure, balancing capability with sustainable resource use.

See our Environmental Policy.

Lifecycle Governance

Research and design

  • Define intended use, users, benefits and known limitations
  • Identify regulatory, ethical and operational constraints
  • Conduct privacy and data protection impact assessments where required
  • Document assumptions and success criteria

Development and testing

  • Use representative evaluation datasets where available
  • Test for accuracy, robustness, edge cases and failure modes
  • Review for bias, security vulnerabilities and misuse potential
  • Maintain version control, audit trails and reproducibility where practicable

Deployment

  • Deploy through controlled release processes (pilot, staged rollout, production)
  • Provide user documentation, training and governance guidance
  • Enable monitoring, logging and feedback mechanisms
  • Define conditions for suspension or rollback

Monitoring and improvement

  • Monitor performance, drift, errors and user feedback in production
  • Investigate incidents and near-misses
  • Update models, rules and documentation as conditions change
  • Retire capabilities that no longer meet safety or quality thresholds

Sector-Specific Considerations

Healthcare (BioAegix)

Healthcare AI demands the highest standards. BioAegix AI features:

  • Support documentation and operational intelligence, not autonomous clinical decision-making by default
  • Preserve audit trails and professional review workflows
  • Align with client clinical governance and information governance frameworks
  • Are subject to enhanced testing before deployment in care environments

Clients retain responsibility for clinical safety, MHRA/DCE classification where applicable, and NHS DTAC or equivalent assessments.

Pharmaceutical supply chain (NPTTE PharmaNG)

AI supports traceability, data integrity and operational visibility. Decisions affecting product safety, regulatory reporting or supply continuity require human authorisation.

Consumer engagement (BeatIQ)

Recommendation systems prioritise user experience while respecting privacy preferences and content rights. Safety-critical constraints do not apply, but fairness and transparency remain important.

Roles and Responsibilities

| Role | Responsibility | |---|---| | Leadership | Set tone, allocate resources, approve high-risk AI deployments | | Engineering teams | Implement controls, testing and documentation | | Product owners | Define intended use, acceptance criteria and user guidance | | Clients and users | Apply AI within authorised scope, maintain oversight, report issues | | Partners | Comply with this policy when contributing to Aurexus AI systems |

We will formalise dedicated AI governance roles as our organisation scales.

Prohibited Uses

We will not knowingly develop or deploy AI to:

  • Enable unlawful surveillance, discrimination or harm
  • Deceive users about the nature of AI-generated content where disclosure is required
  • Circumvent safety, clinical or regulatory controls
  • Process special category data without lawful basis and appropriate safeguards
  • Make fully automated decisions with legal or similarly significant effects without required safeguards under UK GDPR

See our Acceptable Use Policy.

Incident Response

AI-related incidents (including harmful outputs, security breaches, bias-related harm or system failures) are handled through our information security and incident response procedures. Significant incidents are escalated to leadership and, where required, notified to clients, regulators and affected individuals.

Training and Culture

We promote a culture where personnel can raise ethical concerns without retaliation. AI ethics and responsible development practices are integrated into onboarding and ongoing engineering standards.

External Engagement

We engage with academia, professional bodies, regulators and standards organisations to align our practices with emerging evidence and guidance. We welcome constructive feedback from clients and users.

Review

This policy is reviewed at least annually and updated following significant changes in technology, regulation or business scope.

Contact

Email: admin@bioaegix.com
Post: Aurexus Group Ltd, Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE

Governing law: England and Wales