Legal
Responsible AI Policy
Responsible AI Policy
Effective 30 July 2026 · Last updated 30 July 2026
Introduction
Aurexus Group Ltd ("Aurexus", "we", "us" or "our") develops artificial intelligence as part of intelligent transformation — not as an end in itself. This Responsible AI Policy sets out the principles, practices and governance expectations that guide how we research, design, build, deploy and maintain AI-enabled systems.
This policy applies to all Aurexus personnel, contractors and partners involved in AI development and delivery across our corporate activities and product portfolio, including BioAegix, NPTTE PharmaNG and BeatIQ.
Our Commitment
We believe organisations should not have to choose between innovation and responsibility. The most valuable innovation is innovation that can be trusted.
We commit to:
- Engineering AI that supports human expertise rather than replacing accountability
- Embedding governance, security and transparency from the earliest design stages
- Evaluating AI systems for fairness, safety and operational fit before deployment
- Learning continuously from research, practice, client feedback and regulatory guidance
- Being honest about limitations, uncertainties and areas where our capabilities are still maturing
As an early-stage and growing company, we implement this policy proportionately, scaling formal governance as our deployments and regulatory obligations expand.
Guiding Principles
Our responsible AI approach is grounded in The Aurexus Principles and operationalised through the following commitments:
1. Human accountability
AI operates as decision-support within the Aurexus Method™. Professionals and client organisations retain judgement and accountability. We do not design systems that obscure responsibility or bypass required human review in regulated contexts.
2. Purpose and proportionality
AI is deployed only where it addresses a defined organisational need with measurable benefit. We reject capability without purpose — technology for its own sake is not progress we will pursue.
3. Safety and reliability
We prioritise safety, reliability and operational resilience, particularly in healthcare and regulated environments. Systems are tested against realistic scenarios before production use.
4. Fairness and inclusion
We assess AI systems for bias and disparate impact where relevant. Training data, feature selection and evaluation metrics are reviewed to reduce unfair outcomes. We acknowledge that bias mitigation is ongoing, not a one-time checkpoint.
5. Transparency and explainability
We provide appropriate transparency about AI use, limitations and intended scope. Where full explainability is not technically feasible, we document reasoning approaches, confidence indicators and escalation paths.
See our AI Transparency Statement.
6. Privacy and data stewardship
Personal data used in AI systems is processed lawfully under UK GDPR. Data minimisation, purpose limitation, security and retention controls apply throughout the AI lifecycle.
See our Privacy Policy and Information Security Policy.
7. Security by design
AI components are subject to the same security rigour as all platform engineering — including access control, encryption, vulnerability management and incident response.
8. Environmental proportionality
We consider computational efficiency and environmental impact when selecting models and infrastructure, balancing capability with sustainable resource use.
See our Environmental Policy.
Lifecycle Governance
Research and design
- Define intended use, users, benefits and known limitations
- Identify regulatory, ethical and operational constraints
- Conduct privacy and data protection impact assessments where required
- Document assumptions and success criteria
Development and testing
- Use representative evaluation datasets where available
- Test for accuracy, robustness, edge cases and failure modes
- Review for bias, security vulnerabilities and misuse potential
- Maintain version control, audit trails and reproducibility where practicable
Deployment
- Deploy through controlled release processes (pilot, staged rollout, production)
- Provide user documentation, training and governance guidance
- Enable monitoring, logging and feedback mechanisms
- Define conditions for suspension or rollback
Monitoring and improvement
- Monitor performance, drift, errors and user feedback in production
- Investigate incidents and near-misses
- Update models, rules and documentation as conditions change
- Retire capabilities that no longer meet safety or quality thresholds
Sector-Specific Considerations
Healthcare (BioAegix)
Healthcare AI demands the highest standards. BioAegix AI features:
- Support documentation and operational intelligence, not autonomous clinical decision-making by default
- Preserve audit trails and professional review workflows
- Align with client clinical governance and information governance frameworks
- Are subject to enhanced testing before deployment in care environments
Clients retain responsibility for clinical safety, MHRA/DCE classification where applicable, and NHS DTAC or equivalent assessments.
Pharmaceutical supply chain (NPTTE PharmaNG)
AI supports traceability, data integrity and operational visibility. Decisions affecting product safety, regulatory reporting or supply continuity require human authorisation.
Consumer engagement (BeatIQ)
Recommendation systems prioritise user experience while respecting privacy preferences and content rights. Safety-critical constraints do not apply, but fairness and transparency remain important.
Roles and Responsibilities
| Role | Responsibility | |---|---| | Leadership | Set tone, allocate resources, approve high-risk AI deployments | | Engineering teams | Implement controls, testing and documentation | | Product owners | Define intended use, acceptance criteria and user guidance | | Clients and users | Apply AI within authorised scope, maintain oversight, report issues | | Partners | Comply with this policy when contributing to Aurexus AI systems |
We will formalise dedicated AI governance roles as our organisation scales.
Prohibited Uses
We will not knowingly develop or deploy AI to:
- Enable unlawful surveillance, discrimination or harm
- Deceive users about the nature of AI-generated content where disclosure is required
- Circumvent safety, clinical or regulatory controls
- Process special category data without lawful basis and appropriate safeguards
- Make fully automated decisions with legal or similarly significant effects without required safeguards under UK GDPR
See our Acceptable Use Policy.
Incident Response
AI-related incidents (including harmful outputs, security breaches, bias-related harm or system failures) are handled through our information security and incident response procedures. Significant incidents are escalated to leadership and, where required, notified to clients, regulators and affected individuals.
Training and Culture
We promote a culture where personnel can raise ethical concerns without retaliation. AI ethics and responsible development practices are integrated into onboarding and ongoing engineering standards.
External Engagement
We engage with academia, professional bodies, regulators and standards organisations to align our practices with emerging evidence and guidance. We welcome constructive feedback from clients and users.
Review
This policy is reviewed at least annually and updated following significant changes in technology, regulation or business scope.
Contact
Email: admin@bioaegix.com
Post: Aurexus Group Ltd, Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE
Governing law: England and Wales