Legal

AI transparency

What Genie is, what it can and cannot do, and the disclosure obligations we carry as the provider rather than pushing them to you.

commit toa client approvebillable time attestcompliance send onyour behalf deleteevidence change aboundary grant itselfaccess conclude a personis at fault enforced at one chokepoint · an unreadable state refuses not a prompt, not a policy · a control the model cannot reach

You are always told

Every surface where a person interacts with Genie discloses that they are interacting with an AI system, and content Genie generates carries machine-readable marking.

Article 50 of the EU AI Act requires this. It took effect on 2 August 2026 and it is a provider obligation — ours, not yours. It cannot be delegated to you in a licence agreement, and we do not try.

What Genie is

A large language model running on your hardware, with tool access, operating inside a permission system that scopes every action to its consequence.

It is not a general intelligence, it does not have goals of its own, and it does not learn in the sense of changing its own parameters. The model is frozen; what changes is what it knows to apply and when.

What it can do without asking

Only what you have granted, per capability, at a tier derived from what the action would do if it were wrong. Every capability starts proposing-only and is promoted by a named person on evidence.

The full model is documented in the autonomy ladder.

What it can never do

Eight actions are refused at every tier with any confidence — the full list is published. Several are database constraints rather than code, so the wrong state is unspellable rather than merely rejected.

Human oversight

  • Every action is recorded and replayable from the audit log
  • A refusal is recorded with the same detail as an action
  • Genie cannot resolve his own request for help
  • No commitment to a client, no approval of billable time, and no compliance attestation is ever made by the model

What leaves your deployment, and what never will

Two things are designed to leave, and both are opt-in today. The health record is ten fields and a signature. The second is new and it is being built: what Genie learned about solving problems, never what the problem was about.

The distinction is not whether a hostname appears. A method derived from real cases can carry the shape of the estate that produced it without naming one, so the test is stricter: a pattern must hold on cases from practices that did not contribute it, and we attempt to recover a hostname, an address, a client name, a username and a field value from every published pattern — and fail at each.

The boundary came before the capability The shared brain carries method and never evidence, and it was built that way from the first line. We are publishing the boundary before the capability, because a boundary published in advance is one we can be held to. How Genie learns.

Known limits, stated plainly

  • He can be wrong. Where he is uncertain he says so, and where he cannot establish something he names what would establish it
  • He does not predict hardware failure, because at a single MSP's scale nobody can validate a predictor
  • Content-matched controls are partial controls, and they are labelled as such in the record
  • Retrieved content is treated as untrusted by construction, but no defence is complete

Training data

We do not train on your data, your clients' data, or anything from your deployment. There is no mechanism to — the platform runs on your hardware and sends us ten fields.

Last updated 7 August 2026. Questions: support.

Try it on your own estate

Thirty days, read-only, on your own hardware. No card, no call, and nothing to uninstall if you walk away.