How we govern the models we build.
Our models inform decisions about real places and the people who live in them: where a clinic is sited, where vaccination teams go, where a network expands. We build our models to be used safely and responsibly, and a written policy governs how we build and use them.
The policy applies to every model we build, every AI tool we use, and everyone who works for us.
The AI models inside Pulse and Foresight, and the AI tools our teams use in their own work.
Every employee, contractor, and consultant, whatever their role or seniority.
A named executive is accountable for AI governance.
An AI operations lead
A senior scientist or engineer keeps the list of approved AI tools and the incident log, coordinates model validation and release, and trains the team.
A release review
No new model or major update reaches production without a documented release review. The decision and the reasoning behind it are recorded in the model’s audit trail.
We review the governance structure itself every quarter.
Every model is validated and approved before it reaches production.
- Development
- Internal validationFour required checks
- External reviewWhere the model calls for it
- ReleaseWritten approval
- Production
- Retirement
Technical
Performance against defined criteria, benchmarking, error analysis, and a record of failure modes and edge cases.
Scientific
An expert independent of the development team reviews whether what the model has learned is scientifically plausible. A model that makes causal claims must address correlation and causation explicitly.
Data
Where the training data came from and how it was collected, with its known biases, gaps, and limitations documented.
Ethics
How the model could be misused, the effect of its known biases, and whether its documentation honestly represents its performance.
Two more reviews apply when a model will inform consequential decisions, involves causal inference, or significantly updates a model in production.
- Adversarial and stress testing, under conditions unlike its training data
- A regulatory and compliance review
We’re transparent about how our models perform and where they apply.
What we document for every model
- Its purpose and intended use
- Its known limitations
- The assumptions it rests on, and the conditions under which they hold
- Its failure modes, and what triggers them
What we disclose to you
Whenever AI plays a material role in something we deliver to you, we disclose:
- How AI was involved
- The model and version used
- Known limitations relevant to your use of the output
- Whether a person reviewed the output, and to what standard
For any output, we can tell you which models produced it.
Five commitments that apply to everyone at Atlas AI.
People make the decisions
Every AI-assisted scientific output, model result, and customer deliverable is reviewed by a person who is accountable for it.
Engineers sign off on AI-generated code
A qualified engineer reviews and signs off on any AI-generated code before it reaches production.
We credit AI-generated content accurately
In scientific publications, patent applications, customer deliverables, regulatory submissions, and any other work where authorship matters.
Protected data needs executive approval
Customer, proprietary, and regulated data goes to an external AI system only with explicit written approval from an executive. Work on AI platforms uses company accounts only.
We use only approved AI tools
Our AI operations lead keeps the approved list, and it covers every tool used for work, in any context.
How we protect and handle your data.
Hosted on Google Cloud
Atlas AI runs on Google Cloud and Google Workspace, the infrastructure Google built to run and secure enterprise applications worldwide.
- Security built into Google’s infrastructure, from its data centers up
- The reliability and scale that enterprise applications depend on
- Your hosting and data-residency requirements, worked through with you in the security review
Estimates that describe places
Pulse and Foresight produce estimates for places, such as 10 m cells, settlements, and districts, and don’t identify individuals. When a customer provides personally identifiable information, our data processing addendum and data handling procedures govern how we use it.
A data processing addendum as standard
Our standard contracts include a data processing addendum covering the GDPR, the UK GDPR, and the CCPA, with Atlas AI as processor.
Support for your security review
We work through security and procurement reviews with your team. We answer security questionnaires and provide our list of subprocessors.
Every incident is reported within 24 hours, including near-misses.
An incident includes materially incorrect or misleading output in a customer-facing context, and any potential harm to a customer from AI-assisted output.
- Immediately
Serious incidents go straight to the CEO and the Chief Product Officer.
- Within 24 hours
Every incident is reported and classified by severity. Where regulated data or customer harm is involved, we also assess our duty to report to regulators and affected customers.
- Within 14 days
Medium- and high-severity incidents get a formal review, and its findings are shared with the team.
- For 5 years
Each incident is logged with its root cause, remediation, and lessons learned, and the record is kept for at least 5 years.
The full policy is available under NDA.
The full AI Use and Governance Policy adds the operational detail: the approved tool list, data handling procedures, and staff obligations. It is available to customers and partners during onboarding.