ETHICAL AI

Ethical AI Approach

OUR VALUES

Eight principles we hold ourselves to

Every AI initiative at Thesis SM, whether inside the product or inside our own business, is assessed against these principles before deployment and on an ongoing basis.  

ACCOUNTABILITY

Every AI system has a named owner. Accountability is never delegated to a machine. 

SECURITY AND RESILIENCE

AI systems must meet or exceed our existing information security standards, including assessment of adversarial risk before deployment.

CONTINUOUS IMPROVEMENT

AI governance is a living practice. We review systems regularly, learn from incidents, and update our policies as regulation and technology change.

TESTING

Our AI systems are also subject to annual third-party penetration testing and quarterly internal access log reviews. 

 

HUMAN-CENTRED DESIGN

AI supports and augments human judgement; it does not replace it. Every high-stakes decision retains meaningful human oversight and the ability to override. 

PRIVACY BY DESIGN

Privacy is built into AI systems from the start, not bolted on afterwards. We collect only what is necessary, anonymise where possible, and never repurpose student data without consent.

FAIRNESS AND NON-DISCRIMINATION

AI must not perpetuate or amplify existing inequalities. We test for bias before and after deployment, and act when disparate impact is found. 

TRANSPARENCY & EXPLAINABILITY

Every AI recommendation affecting a student, institution or staff member must be explainable in plain language. We publish an annual AI Transparency Report. 

OUR APPROACH

Fairness is audited, not assumed 

AI trained on historical data can encode historical bias. In higher education, where AI may inform decisions about admissions, progression and support, that risk demands more than good intentions.

Before any model influencing decisions about students goes live, it undergoes fairness testing across all protected characteristic groups under the Equality Act 2010, the Canadian Human Rights Act and US civil rights law, along with statistical analysis of training data for representation gaps. No such model is deployed without AIGC sign-off.

After deployment, every AI system that influences decisions about students is included in a quarterly bias audit covering disparate impact analysis, calibration checks across demographic subgroups, review of human override patterns, and any complaints raised by institutions or students. Audit reports are retained for a minimum of five years. Where material bias is identified, a remediation plan is produced within 30 days and implemented within 90.

CONTROLS

Humans stay in charge 

We operate a firm rule: no automated AI decision is final on any high-stakes matter. In practice, that means:

  • No AI system in Thesis SM can automatically deny, approve or alter a student's enrolment, financial support status or academic standing without human review.
  • Every AI recommendation is accompanied by a plain-language explanation of the factors behind it, with confidence shown in plain terms rather than raw probability scores.
  • Authorised reviewers always have a clear override option, tested at every deployment and every major update.
  • Institutions are contractually entitled to configure the level of human review required for AI recommendations within their own Thesis SM instance.

Override rates are monitored as a governance metric. A rising override rate is treated as a signal that a model needs attention, and it is reviewed quarterly.

 

AI inside Thesis SM: the product commitments

Whether an AI capability is built by us or integrated from a partner, the same principles apply within the product:

  • Institutional control. AI features are configurable, not mandatory. Your institution can disable any AI feature within your Thesis SM instance.
  • Safe by default. New AI features arrive in their most privacy-preserving, least automated configuration. Institutions opt in to greater automation; it is never imposed.
  • No black boxes. Every AI feature includes explainability. Users can see why the system made a recommendation.
  • Clearly labelled. AI-generated content and recommendations are always identified as such in the interface. No one is left guessing whether output came from a person or a model.
  • Fully auditable. All AI-driven actions and recommendations are logged and available to authorised institution staff.
  • Your data stays portable. Institutions can export all AI-related data from Thesis SM at any time, in a standard format.
  • Student welfare first. No AI feature ships if it poses an unacceptable risk to student welfare, privacy or equity, whatever the commercial case.

How AI features are built and released

Every AI feature follows a seven-stage lifecycle, from problem definition through ethics review, development with fairness metrics built into QA, a formal pre-deployment gate, phased rollout, ongoing monitoring, and eventually managed decommissioning with at least 90 days' client notice.

Features are classified into three risk tiers. Those that directly influence high-stakes decisions about individual students face the fullest scrutiny: a mandatory data protection impact assessment, mandatory human-in-the-loop review, AIGC sign-off, and a client beta of at least 60 days before general release. Lower-risk features, such as AI-assisted report writing or data quality flagging, follow a proportionate, lighter process.

After release, features are monitored with real-time alerting for unexpected output patterns, monthly performance reviews, and inclusion in the quarterly bias audit programme.

The regulation we work within

Thesis operates across the UK, Ireland, Canada and the US, and our compliance obligations differ in each.

United Kingdom. All AI systems processing personal data comply with UK GDPR and the Data Protection Act 2018, including Article 22: no one is subject to a solely automated decision with legal or similarly significant effects. Data protection impact assessments are completed wherever AI involves systematic profiling or automated decision-making with significant effects. We follow ICO guidance on AI and data protection, and we provide documentation to support institutions' Office for Students obligations, with legal review before every UK feature deployment involving AI.

Canada. We comply with PIPEDA and applicable provincial privacy law, including the enhanced requirements of Quebec's Law 25 (privacy impact assessments for new AI projects, disclosure of automated decision-making, and the right to request human review). We are also preparing ahead of Canada's proposed Artificial Intelligence and Data Act so that we are ready when it becomes law.

Our platform architecture allows jurisdiction-specific controls to be configured at institutional level, and a jurisdiction-by-jurisdiction compliance register is reviewed quarterly. 

We hold our suppliers to the same standard

The AI vendors we work with become extensions of our governance obligations. Before any third-party AI tool is used at Thesis, the vendor must pass our assessment: a signed Data Processing Agreement, confirmation that client data is not used to train their models by default, data residency in the required regions, published bias testing practices, contractual breach notification within 72 hours, and data deletion or export on contract termination. Vendors are re-reviewed annually and after any material change to their AI systems.

Our own staff work under the same discipline. No AI tool is used at Thesis without formal approval, and all approved tools run on managed enterprise plans with proper data governance, never personal accounts.

When something goes wrong

No governance framework eliminates risk entirely, so we maintain a classified incident response process. Critical incidents trigger executive escalation within one hour and, where necessary, immediate suspension of the affected feature. Where an incident constitutes a personal data breach, we follow the applicable notification requirements, including ICO notification within 72 hours in the UK. Affected institutions are told promptly and honestly what happened, what data was involved, and what we are doing about it. Every incident feeds a documented root cause investigation and, where needed, a policy update. 

A framework that keeps moving

 
AI regulation and AI capability are both changing quickly, and a governance framework written once and left alone would not survive contact with either.
Ours is reviewed at least annually, monitored against regulatory developments in every jurisdiction we operate in, and updated in response to incidents, audit findings, and feedback from staff and institutions.
 
We publish an annual AI Transparency Report, available to all institutional clients, summarising the AI systems in use, the year's bias audit results, incidents and their resolution, and our compliance position across jurisdictions. If you would like a copy of the Transparency Report, our full Responsible AI Governance Framework, or explainability documentation for any AI feature, ask your Thesis SM contact or get in touch at hello@thesiscloud.com.
Thesis Logo Vector HEM Implementation  (Logo) (18)-1