AI ethics policy
This is Isotoma's policy on the ethics of artificial intelligence. It covers both what we build for our clients and how we use AI tools in our own work.
Our position
We value sustainability, creativity, and craft: things and teams that last, interesting work, and quality in what we make. AI is now part of how that work gets done, and the question is not whether to use it but how to use it in a way that makes us better.
As with all powerful technologies, these tools have great potential for benefit and for harm. They are powerful enough to deskill teams, displace workers, and harm users when used carelessly, and powerful enough to make our work more interesting, more durable, and more accessible when used well.
What we will not build or deploy
The following are lines we will not cross, regardless of commercial pressure.
- AI companions, or systems that present AI as representing a real person with real relationships.
- Image or video generation creating representations of identifiable people without their express consent.
- Scams, fraud, or systems designed for intentional misrepresentation.
- Weapons systems, or components intended for weapons systems.
- Systems that make consequential decisions about people, such as employment, credit, healthcare, justice, or access to services, without meaningful human review.
- Surveillance systems that monitor workers rather than empower them.
- Systems that use training material where intellectual property rights were not obtained.
- Slop and spam: systems designed to flood communication channels with low-quality content.
- Systems designed to subvert accepted rules, norms, or institutions, for example essay mills.
How we work with AI
These commitments apply to everyone at Isotoma using AI in their work, and to what we build for clients.
- Ownership. The individual owns the output, regardless of how it was produced. AI assistance does not change accountability or quality standards.
- Comprehension over throughput. We do not ship code we do not understand. Time spent understanding what we produce is a core part of the engineering effort.
- Pro-worker by default. We choose AI that extends our people's judgement over AI that replaces it, and we apply the same standard to what we build for clients.
- Knowledge capture. What the team learns gets written down: for each other, and for the agents we work with. Documentation is a first-class activity.
- Security and provenance. We treat AI-assisted code with the same security discipline as any other code, and we keep clear records of how it was produced so we can answer client and regulatory questions.
- Honest with customers. We tell clients how we use AI in their work, including where we won't.
- Fairness. Systems we build are tested for bias against the people they affect. Where AI is used in decisions that affect people, we design for human oversight, not around it.
- Ethics from the start. Ethical review is part of how we begin a project, not how we finish one. Questions about bias, fairness, privacy, and harm are raised at the design stage, before decisions are locked in. Returning to them once a system is built makes them harder to answer honestly.
- Inclusive tool selection. The people who will use AI tools day-to-day have a say in choosing them, before decisions are made. The same principle applies to what we build for clients: where AI affects the people who use a system, we consider their needs and seek input where appropriate.
- Privacy and customer data. We use AI tools configured not to retain or train on client code or data, and we do not share client information with AI systems beyond what the engagement permits. Personal data handled through AI tools is governed by the same standards as any other personal data we hold.
Where we stand
There are public debates about AI on which a working policy ought to be explicit.
Training data
The primary value in language models is in their training data, which makes the industry's widespread use of unlicensed copyrighted material a serious problem, not a technicality. We won't pretend the problem is solved, or that we can avoid it entirely. The reality is that most current models carry some level of unresolved copyright risk that individual organisations cannot remedy. Meaningful change requires industry transparency and government action, and we'll say that plainly to anyone who asks.
Environment
Data centres use energy and water, and the aggregate impact is real, particularly where they are concentrated and can account for a significant share of local electricity demand. The per-query cost of a typical text interaction is small, comparable to seconds of everyday appliance use, but agentic and generative tasks consume meaningfully more, and much of AI's energy use happens invisibly, embedded in search, social media, and enterprise tools most people don't think of as AI at all. We don't think this means avoiding AI, in the same way the environmental cost of travel or food doesn't make those things simply wrong. But it does mean being deliberate: choosing tasks where AI adds genuine value, preferring vendors who are transparent about energy sourcing, and not treating environmental cost as someone else's problem to solve.
Regulation
We welcome the EU AI Act's transparency provisions and intend to be ready for them. Clear rules about how AI-assisted systems are produced and audited are good for our clients and good for us.
Questions
If you have a question about any of this, or want to talk about how it applies to your project, email hello@isotoma.com or call 01904 313969.