AI Ethics and Policy

ReCo Enterprises Pty Ltd (ReCo) · Last reviewed 23 August 2026 · Review cycle: every 6 months

Why this page exists

We build content systems and AI tools for organisations in health, finance, education and the public sector. Several of those clients work under regulatory regimes where an AI mistake is not an inconvenience, it is a breach.

So this page is not a statement of values. It is a description of how we actually work, written so that a client’s procurement or security team can check it. Where we have a control in place, we say so. Where we do not, we say that too.

Where we stand on standards

Australia’s AI governance landscape changed twice in 18 months, and a lot of published policy still cites superseded guidance. For the record, here is what applies now.

  • Australia’s AI Ethics Principles (8 principles, DISR, 2019) Current, voluntary · Adopted. Mapped below.

  • Guidance for AI Adoption (AI6), 6 essential practices, National AI Centre, 21 October 2025 Current primary government guidance · Adopted as our governance framework. Mapped below.

  • Voluntary AI Safety Standard (10 guardrails, 5 September 2024) Superseded by AI6, retained as a control catalogue · Used as our detailed control reference.

  • Mandatory guardrails for high-risk AI Proposed September 2024, not legislated. The National AI Plan (December 2025) relies on existing law and sector regulators instead. · Monitored.

  • ISO/IEC 42001:2023 (AI Management System) International, certifiable · Aligned, not certified. See below.

On ISO 42001

ISO/IEC 42001 is the certifiable standard for an AI management system. Certification requires an accredited external audit, and the cost of that audit is beyond a company our size right now.

We are not certified, and we will not imply that we are. What we have done instead is adopt the practices the standard describes, and document them so an auditor or a client could inspect them:

  • A written AI policy, reviewed on a fixed cycle (this document)

  • A named accountable person

  • A maintained register of AI systems and subprocessors

  • Risk assessment before deployment, not after

  • Human oversight designed into the pipeline rather than added later

  • Logged, traceable outputs

  • Incident response with a written post-incident record

The Australian AI6 guidance is explicitly designed to align with ISO/IEC 42001. Working to AI6 now means that when certification becomes affordable, it is an audit rather than a rebuild.

If certification is a hard requirement for your procurement process, tell us at the start. We would rather lose the work than let you assume a certification we do not hold.

Our principles

Mapped to Australia’s 8 AI Ethics Principles, with what each one means in our practice rather than in the abstract.

1. Human, societal and environmental wellbeing. We have published on the environmental and social cost of AI, including its energy footprint and its effect on the homogenisation of thought. We do not treat AI as cost-free.

2. Human-centred values. AI does not decide anything that affects a person’s care, money or rights in our work. It drafts, retrieves and structures. People decide.

3. Fairness. Our research pipeline draws from sources we can name. Where a model’s output would encode a stereotype about a community, a health condition or a demographic, a person removes it. We check who is missing from a source set, not only what is in it.

4. Privacy protection and security. Governed by our Data Protection Policy, summarised below and available in full.

5. Reliability and safety. Every substantive AI output in our own builds is verified against the live artefact rather than trusted from the model’s own account of what it did. That verification catches real errors, repeatedly.

6. Transparency and explainability. We disclose where AI was used. Every claim in our research bank is traceable to its source and to the run that produced it.

7. Contestability. Any client can ask how an output was produced, which model touched it, and on what source it rests. Any person can challenge content we have published about them and we will correct it.

8. Accountability. One named person is accountable. Not a committee, not a policy.

How we govern AI

Mapped to the 6 essential practices in the National AI Centre’s Guidance for AI Adoption.

1. Decide who is accountable

Danling Xiao, Founder and Strategic Director, is accountable for AI governance at ReCo. That includes approving the tool stack, approving any new subprocessor, owning incident response, and signing off this policy.

There is no AI ethics committee. At our size a committee would be theatre. One named person who can actually be reached is more accountable than five who share the blame.

2. Understand impacts and plan accordingly

Before AI is used on an engagement we establish: what the output will be used for, who is affected if it is wrong, what regulatory regime applies, and what the client’s own AI position is.

Work in regulated sectors gets a higher bar. For health clients this means AHPRA and TGA advertising rules govern the output regardless of how it was produced. A model does not get to be the reason a claim was non-compliant.

3. Measure and manage risks

We treat 3 risks as material and design against each:

  • Fabrication. Models state incorrect work as complete with total confidence. Control: verification against source, described below.

  • Confidentiality. Client material entering a third-party model. Control: the subprocessor register, contractual training exclusions, and per-engagement access separation.

  • Homogenisation. AI output converging on the same voice and the same received wisdom. Control: human authorship of argument and structure; the model does volume, not the point of view.

4. Share essential information

We disclose our stack, our subprocessors, and their data terms rather than describing them in general language. Where a provider’s terms are weaker than we would like, we say which provider and how.

We publish the documentation for our own agentic AI content system, so a client can see the pipeline they are buying into rather than taking a description of it on trust.

5. Test and monitor

Our own site and content system are the test bed. We run our methods on ourselves before we sell them, which is how we know where they fail.

Documented failure modes from our own builds, all real:

  • Components confidently placed in the wrong part of a structure

  • Labels invented rather than read from the existing source

  • Values reported as changed when they had never been written

None of these announce themselves. All were caught by checking the artefact rather than the model’s report of it.

6. Maintain human control

The machine handles volume. A person owns judgement. Verification is a step, not an afterthought.

In practice: AI runs research sweeps, drafting, restructuring and bulk consistency work. People decide what the argument is, what is true, what is compliant, what is kind, and what gets published. No output reaches a client or the public without a person having read it.

How we use AI in client work

What AI does: research sweeps and source gathering; first drafts; restructuring existing content; consistency checks across large sets; structured data generation; summarising and clustering.

What people do: the strategy and the argument; every factual claim; regulatory compliance; tone and judgement; anything involving a named person; the decision to publish.

What we disclose: that AI was used in production, on request and as standard in our engagement documentation. We do not pass AI-assisted work off as unassisted, and we do not pass human work off as AI-generated efficiency.

Client data and model training. Our commercial AI providers are contractually restricted from training their models on our inputs. One exception is disclosed openly: our web-search provider uses query data to improve its products on the standard plan. Queries only, never client documents. Full detail sits in the subprocessor register in our Data Protection Policy.

What we will not do

  • Generate fake reviews, testimonials or endorsements, or anything designed to read as an independent voice when it is not

  • Produce synthetic media of a real person without that person’s explicit consent

  • Present AI-generated statistics, citations or quotes without verifying them against a primary source

  • Use client-confidential material to train anything, or to inform another client’s work

  • Publish AI-written content about a named individual without a person checking it

  • Claim a certification, accreditation or standard we do not hold

  • Use AI to make or materially influence a decision about someone’s employment, credit, healthcare or legal position

Content integrity

Everything we publish is checked against primary sources. In practice that means a claim traced to the body that produced it, not to a secondary article that quoted it.

We routinely find that AI-suggested citations point to real publications that do not contain the claimed statistic, or attribute a finding to the wrong organisation. We treat every model-supplied citation as unverified until opened.

Where we publish research involving named people, we credit them, we record their role as at the date of the interview, and we do not alter quoted speech.

Your rights as a client

  • Ask how anything was made. Which models, which sources, which run.

  • Opt out of AI processing for any part of an engagement. It changes cost and timeline, and we will tell you by how much before you decide.

  • Have your material deleted. Client-confidential inputs are deleted or returned within 30 days of written request at the end of an engagement.

  • Refuse a subprocessor. If a provider in our stack fails your procurement standard, tell us and we will tell you honestly whether we can deliver without it.

  • Take the account with you. Where we operate a platform account on your behalf, it is handed over or closed at your choice at engagement end.

Data protection

Our full Data Protection Policy covers the ReCo Agentic AI Content System: the technology stack, data flow, classification, encryption, hosting and residency, per-provider training and retention terms, access control, credentials, retention and deletion, the subprocessor register, and incident response.

The points clients ask about most:

  • Hosting. Platform data is hosted on Railway across United States and Singapore regions. Railway has no Australian region, so we do not claim Australian data residency, and cross-border disclosure under APP 8 applies.

  • Training use. Anthropic, OpenAI and Google commercial terms exclude training on our content. Our search provider’s standard plan does not, and we disclose that rather than averaging it away.

  • Retention. Third-party abuse-monitoring windows run 30 days (OpenAI) to 55 days (Google) before deletion. We cannot shorten these except through zero-retention agreements.

  • Access. Invite-only, no self-serve sign-up, 2FA on every client account, credentials in a password manager, rotated whenever anyone leaves an engagement.

Limitations we state openly

1. We are not ISO/IEC 42001 certified. We work to the practices, without the audit.

2. We cannot guarantee a model will not fabricate. We can guarantee a person checked. Those are different promises and we make only the second.

3. No Australian data residency for the content system, for the hosting reason above.

4. Our providers’ terms can change. We review the subprocessor register at least annually and whenever the stack changes, but a provider can alter its terms between reviews.

5. This is not legal advice. Obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles, and sector rules such as APRA CPS 234 should be confirmed with your own adviser before contracting.

Governance of this policy

Reviewed every 6 months, and immediately on any change to the tool stack, any new subprocessor, or any incident. Each review is dated. Every incident produces a written post-incident note held with this policy.

Questions, concerns, or a request for evidence behind any claim on this page: danling@reco.net.au

Sources

  • Australia’s AI Ethics Principles, Department of Industry, Science and Resources

  • Guidance for AI Adoption, National AI Centre, 21 October 2025

  • Voluntary AI Safety Standard, National AI Centre, 5 September 2024

  • ISO/IEC 42001:2023, Artificial Intelligence Management System