Trust Center · AI
AI Policy
This policy describes how Monolitica develops and deploys AI systems, including intelligent agents, automations, dashboards, integrations and internal systems, within the scope of the projects it carries out for its clients, and how we align with Regulation (EU) 2024/1689 (the AI Act).
Last updated: 20 July 2026
Principles
- Transparency. Whenever a system we develop interacts directly with citizens, residents or employees, it clearly identifies itself as AI.
- Human oversight.We do not design systems that make, on their own, administrative or operational decisions with significant impact. The client's human always retains the final decision.
- Proportionality. We automate what is repetitive and what can be assisted by AI; we do not automate high-impact administrative, legal or financial decisions without human review.
- Privacy. Client data does not feed the training of public models. A training opt-out is contracted with the model providers we use.
- Operational honesty. Models make mistakes. We describe the limits of each system we deliver instead of hiding them.
Transparency about AI (AI Act art.
50)
Under article 50 of the EU AI Act, applicable from 2 August 2026, any AI system that interacts directly with individuals must ensure that those individuals are informed. In the systems we design for clients:
- conversational interfaces (chat, assisted forms) identify themselves as AI on the first interaction and indicate how to request human intervention;
- reports, summaries or recommendations generated by AI are flagged as such when they reach a human decision-maker or a citizen;
- decision-support systems make it explicit that the recommendation is generated by AI and requires human validation before it takes effect.
Human oversight and escalation
In the systems we design, escalation criteria apply:
- an explicit request for human intervention;
- detection of a case outside the trained or designed scope;
- any decision with a significant effect on an individual is always subject to human validation before being executed.
Accuracy and error mitigation
Factual sources
For factual answers, systems are built from the client's actual documentation, data and processes, mapped during the project. When the use case requires it, they can consult these sources to ground the answer.
Domain safeguards
In a municipal context, the systems we deliver do not make binding administrative decisions without human validation. In an industrial context, they do not replace the client's safety or regulatory compliance responsibilities. Whenever the user pushes past the limit, the system escalates to a responsible person on the client's side.
Confidence and uncertainty
When the model does not know, the system is designed to say it does not know. We prefer an answer that acknowledges its limits to a confident hallucination.
User rights
The rights under the GDPR apply (arts. 15-22), including the right not to be subject to a decision based solely on automated processing with significant effects (art. 22). Any person affected by a system we develop for a client can request human intervention and challenge a decision with the client responsible for the processing, or contact us at /dpo.
Data and training
Project data is not used to train public models. In the reference contracts we use with OpenAI and Anthropic, training on data sent via the API is disabled by default. When a system is configured with the client's own API key or tenant, the data is processed directly under that client's contract with the provider in question. We do not sell or share project data with third parties beyond the strictly necessary technical subprocessors, listed at /sub-processadores.
Bias mitigation
The underlying models are tested by their providers for demographic and linguistic bias. We add, per project:
- Review of the system's behaviourin European Portuguese and in the client's real context before going into production.
- Continuous monitoring in the first weeks after launch, with guardrail adjustments when necessary.
Phased adoption
The work starts with diagnosis and mapping, workshops and pilots on real use cases. Expansion is accompanied by team training and ends with knowledge transfer, so the client can operate and evolve the systems autonomously.
AI-related incidents
If a system we developed causes or is likely to cause harm (a material error, an incorrect recommendation in a sensitive context, improper handling of data), the client can contact [email protected]. We triage the report, apply a correction and document what happened.
Changes to this policy
Material changes to this policy are communicated with reasonable advance notice to clients with active projects.