AI Ethics and Policy
ReCo Enterprises Pty Ltd (ReCo) · Last reviewed 23 August 2026 · Review cycle: every 6 months
Why this page exists
We build content systems and AI tools for organisations in health, finance, education and the public sector. Several of those clients work under regulatory regimes where an AI mistake is not an inconvenience, it is a breach.
So this page is not a statement of values. It is a description of how we actually work, written so that a client’s procurement or security team can check it. Where we have a control in place, we say so. Where we do not, we say that too.
Where we stand on standards
Australia’s AI governance landscape changed twice in 18 months, and a lot of published policy still cites superseded guidance. For the record, here is what applies now.
Australia’s AI Ethics Principles (8 principles, DISR, 2019) Current, voluntary · Adopted. Mapped below.
Guidance for AI Adoption (AI6), 6 essential practices, National AI Centre, 21 October 2025 Current primary government guidance · Adopted as our governance framework. Mapped below.
Voluntary AI Safety Standard (10 guardrails, 5 September 2024) Superseded by AI6, retained as a control catalogue · Used as our detailed control reference.
Mandatory guardrails for high-risk AI Proposed September 2024, not legislated. The National AI Plan (December 2025) relies on existing law and sector regulators instead. · Monitored.
ISO/IEC 42001:2023 (AI Management System) International, certifiable · Aligned, not certified. See below.
On ISO 42001
ISO/IEC 42001 is the certifiable standard for an AI management system. Certification requires an accredited external audit, and the cost of that audit is beyond a company our size right now.
We are not certified, and we will not imply that we are. What we have done instead is adopt the practices the standard describes, and document them so an auditor or a client could inspect them:
A written AI policy, reviewed on a fixed cycle (this document)
A named accountable person
A maintained register of AI systems and subprocessors
Risk assessment before deployment, not after
Human oversight designed into the pipeline rather than added later
Logged, traceable outputs
Incident response with a written post-incident record
The Australian AI6 guidance is explicitly designed to align with ISO/IEC 42001. Working to AI6 now means that when certification becomes affordable, it is an audit rather than a rebuild.
If certification is a hard requirement for your procurement process, tell us at the start. We would rather lose the work than let you assume a certification we do not hold.
Our principles
Mapped to Australia’s 8 AI Ethics Principles, with what each one means in our practice rather than in the abstract.
1. Human, societal and environmental wellbeing. We have published on the environmental and social cost of AI, including its energy footprint and its effect on the homogenisation of thought. We do not treat AI as cost-free.
2. Human-centred values. AI does not decide anything that affects a person’s care, money or rights in our work. It drafts, retrieves and structures. People decide.
3. Fairness. Our research pipeline draws from sources we can name. Where a model’s output would encode a stereotype about a community, a health condition or a demographic, a person removes it. We check who is missing from a source set, not only what is in it.
4. Privacy protection and security. Governed by our Data Protection Policy, summarised below and available in full.
5. Reliability and safety. Every substantive AI output in our own builds is verified against the live artefact rather than trusted from the model’s own account of what it did. That verification catches real errors, repeatedly.
6. Transparency and explainability. We disclose where AI was used. Every claim in our research bank is traceable to its source and to the run that produced it.
7. Contestability. Any client can ask how an output was produced, which model touched it, and on what source it rests. Any person can challenge content we have published about them and we will correct it.
8. Accountability. One named person is accountable. Not a committee, not a policy.
How we govern AI
Mapped to the 6 essential practices in the National AI Centre’s Guidance for AI Adoption.
1. Decide who is accountable
Danling Xiao, Founder and Strategic Director, is accountable for AI governance at ReCo. That includes approving the tool stack, approving any new subprocessor, owning incident response, and signing off this policy.
There is no AI ethics committee. At our size a committee would be theatre. One named person who can actually be reached is more accountable than five who share the blame.
2. Understand impacts and plan accordingly
Before AI is used on an engagement we establish: what the output will be used for, who is affected if it is wrong, what regulatory regime applies, and what the client’s own AI position is.
Work in regulated sectors gets a higher bar. For health clients this means AHPRA and TGA advertising rules govern the output regardless of how it was produced. A model does not get to be the reason a claim was non-compliant.
3. Measure and manage risks
We treat 3 risks as material and design against each:
Fabrication. Models state incorrect work as complete with total confidence. Control: verification against source, described below.
Confidentiality. Client material entering a third-party model. Control: the subprocessor register, contractual training exclusions, and per-engagement access separation.
Homogenisation. AI output converging on the same voice and the same received wisdom. Control: human authorship of argument and structure; the model does volume, not the point of view.
4. Share essential information
We disclose our stack, our subprocessors, and their data terms rather than describing them in general language. Where a provider’s terms are weaker than we would like, we say which provider and how.
We publish the documentation for our own agentic AI content system, so a client can see the pipeline they are buying into rather than taking a description of it on trust.
5. Test and monitor
Our own site and content system are the test bed. We run our methods on ourselves before we sell them, which is how we know where they fail.
Documented failure modes from our own builds, all real:
Components confidently placed in the wrong part of a structure
Labels invented rather than read from the existing source
Values reported as changed when they had never been written
None of these announce themselves. All were caught by checking the artefact rather than the model’s report of it.
6. Maintain human control
The machine handles volume. A person owns judgement. Verification is a step, not an afterthought.
In practice: AI runs research sweeps, drafting, restructuring and bulk consistency work. People decide what the argument is, what is true, what is compliant, what is kind, and what gets published. No output reaches a client or the public without a person having read it.
How we use AI in client work
What AI does: research sweeps and source gathering; first drafts; restructuring existing content; consistency checks across large sets; structured data generation; summarising and clustering.
What people do: the strategy and the argument; every factual claim; regulatory compliance; tone and judgement; anything involving a named person; the decision to publish.
What we disclose: that AI was used in production, on request and as standard in our engagement documentation. We do not pass AI-assisted work off as unassisted, and we do not pass human work off as AI-generated efficiency.
Client data and model training. Our commercial AI providers are contractually restricted from training their models on our inputs. One exception is disclosed openly: our web-search provider uses query data to improve its products on the standard plan. Queries only, never client documents. Full detail sits in the subprocessor register in our Data Protection Policy.
What we will not do
Generate fake reviews, testimonials or endorsements, or anything designed to read as an independent voice when it is not
Produce synthetic media of a real person without that person’s explicit consent
Present AI-generated statistics, citations or quotes without verifying them against a primary source
Use client-confidential material to train anything, or to inform another client’s work
Publish AI-written content about a named individual without a person checking it
Claim a certification, accreditation or standard we do not hold
Use AI to make or materially influence a decision about someone’s employment, credit, healthcare or legal position
Content integrity
Everything we publish is checked against primary sources. In practice that means a claim traced to the body that produced it, not to a secondary article that quoted it.
We routinely find that AI-suggested citations point to real publications that do not contain the claimed statistic, or attribute a finding to the wrong organisation. We treat every model-supplied citation as unverified until opened.
Where we publish research involving named people, we credit them, we record their role as at the date of the interview, and we do not alter quoted speech.
Your rights as a client
Ask how anything was made. Which models, which sources, which run.
Opt out of AI processing for any part of an engagement. It changes cost and timeline, and we will tell you by how much before you decide.
Have your material deleted. Client-confidential inputs are deleted or returned within 30 days of written request at the end of an engagement.
Refuse a subprocessor. If a provider in our stack fails your procurement standard, tell us and we will tell you honestly whether we can deliver without it.
Take the account with you. Where we operate a platform account on your behalf, it is handed over or closed at your choice at engagement end.
Data protection
Our full Data Protection Policy covers the ReCo Agentic AI Content System: the technology stack, data flow, classification, encryption, hosting and residency, per-provider training and retention terms, access control, credentials, retention and deletion, the subprocessor register, and incident response.
The points clients ask about most:
Hosting. Platform data is hosted on Railway across United States and Singapore regions. Railway has no Australian region, so we do not claim Australian data residency, and cross-border disclosure under APP 8 applies.
Training use. Anthropic, OpenAI and Google commercial terms exclude training on our content. Our search provider’s standard plan does not, and we disclose that rather than averaging it away.
Retention. Third-party abuse-monitoring windows run 30 days (OpenAI) to 55 days (Google) before deletion. We cannot shorten these except through zero-retention agreements.
Access. Invite-only, no self-serve sign-up, 2FA on every client account, credentials in a password manager, rotated whenever anyone leaves an engagement.
Limitations we state openly
1. We are not ISO/IEC 42001 certified. We work to the practices, without the audit.
2. We cannot guarantee a model will not fabricate. We can guarantee a person checked. Those are different promises and we make only the second.
3. No Australian data residency for the content system, for the hosting reason above.
4. Our providers’ terms can change. We review the subprocessor register at least annually and whenever the stack changes, but a provider can alter its terms between reviews.
5. This is not legal advice. Obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles, and sector rules such as APRA CPS 234 should be confirmed with your own adviser before contracting.
Governance of this policy
Reviewed every 6 months, and immediately on any change to the tool stack, any new subprocessor, or any incident. Each review is dated. Every incident produces a written post-incident note held with this policy.
Questions, concerns, or a request for evidence behind any claim on this page: danling@reco.net.au
Sources
Australia’s AI Ethics Principles, Department of Industry, Science and Resources
Guidance for AI Adoption, National AI Centre, 21 October 2025
Voluntary AI Safety Standard, National AI Centre, 5 September 2024
ISO/IEC 42001:2023, Artificial Intelligence Management System