peopleVersion 1SOC2ISO27001NIST AI RMFEU AI Act
AI Acceptable Use Policy
Approved AI tools and prohibitions for handling Rex Black and client data.
AI Acceptable Use Policy
Rex Black is an AI-forward company. We use AI aggressively to move faster and ship better work. This policy establishes the few absolute limits required to do that without leaking data, breaking contracts, or violating regulation.
1. Approved tools
The Security Officer maintains a list of approved generative-AI tools with a category assigned to each:
| Category | Data allowed | Example tools |
|---|---|---|
| Public | Public, Internal | Public chatbots |
| Enterprise | Public, Internal, Confidential (with DPA) | Workspace-tier LLM products with no-training contracts |
| Restricted | Public, Internal, Confidential, Restricted | On-prem / VPC-deployed models with contract-level controls |
The current list lives in registers/approved-ai-tools.md.
2. Prohibited
- Pasting Rex Black or client source code above Internal classification into a Public-tier AI tool.
- Pasting Restricted data into any AI tool not explicitly approved for Restricted scope.
- Enabling training/model improvement on data sent to a vendor without Privacy Officer written approval.
- Connecting unapproved AI tools to Rex Black SaaS (Google Workspace pickers, GitHub agents, Slack bots) via OAuth.
- Using AI to generate client deliverables without disclosure where the contract requires disclosure.
- Using AI to impersonate people (deepfakes, synthetic voices) for any Rex Black business purpose.
- Using AI for fully automated consequential decisions about individuals (hiring, credit, medical, legal) without a documented human-in-the-loop step, as contemplated by GDPR Art. 22 and the EU AI Act.
3. Expected practice
- Classify before sending. If the data is above your approved category, stop; elevate or redact.
- Redact secrets (tokens, passwords, customer PII) before pasting into any AI tool.
- Cite your sources in any AI-assisted written deliverable (internal or client) that borrows more than boilerplate.
- Don't trust without review. AI output, code, legal language, compliance language, technical claims, is reviewed before shipping.
- Flag AI-generated content in client deliverables where the client has asked to know, or where the contract requires.
4. Model development and usage
Where Rex Black builds AI features for clients or itself:
- A design doc covers training data provenance, bias analysis, and the appropriate evaluation harness.
- PII is not sent to commercial model APIs for training without a DPA that forbids retention and training.
- For government engagements with CUI, models must be deployed in an accreditation-boundary-appropriate environment (CJIS / CUI / IL4 etc. per the contract).
5. Audit and enforcement
- AI tool usage is part of Rex Black's access log. Anomalous
exfiltration to AI endpoints is monitored per
021-logging-and-monitoring-policy.md. - Violations follow the disciplinary process in
023-hr-security-policy.md. Material leaks trigger the Incident Response Plan.
6. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Maintains the approved tool list; enforces categories. |
| Privacy Officer | DPIAs for new AI processing. |
| All personnel | Comply with categories; redact before pasting. |
7. References
009-data-classification-and-handling-policy.md003-acceptable-use-policy.md019-privacy-policy-internal.md
8. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.