ISPnext manages nextAI within an AI management system designed in accordance with ISO/IEC 42001. This page describes the safeguards that apply and what this means for the use of nextAI.
General guidelines for the responsible use of nextAI, including human oversight and responsibilities, are described in the article NextAI - Responsible use of nextAI.
1. Intended use and limitations
Each nextAI functionality (Capability) is developed with a clearly defined purpose, target audience and scope of application. Before development, the following is documented:
- who uses the Capability, for what purpose and with what expected result;
- which uses are not permitted or fall outside the scope;
- which users, customers or processes may be affected by the output;
- what human oversight is required before the output is processed.
This delineation forms the basis for all subsequent design decisions and acceptance criteria.
2. Data protection during development
The following safeguards apply to data during the development of nextAI functionalities:
- Prompts and customer data are not logged unnecessarily.
- ISPnext and Microsoft do not use customer data to train the generative AI models of nextAI. They process customer data in accordance with the contractual, privacy and security agreements.
- For each Capability, the data used, its source, how its quality and integrity are safeguarded and who has access to it are documented.
- When training data is not applicable, this is explicitly documented and justified.
NextAI uses Microsoft Azure AI services within the Azure environment managed by ISPnext. Customer data is processed within the applicable contractual, privacy and security agreements.
3. Models and dependencies
ISPnext actively manages the AI models and technical dependencies on which nextAI is based:
- Model versions, providers and configurations are registered and maintained.
- Known limitations of models are taken into account in the design and communications.
- Changes to models are monitored and assessed for their impact.
- The output of nextAI is validated; the system does not blindly rely on model behaviour.
4. Testing before release
Before release, ISPnext tests the operation, quality, abnormal input and human oversight of each nextAI functionality. The Product Owner assesses the test results, open risks and required measures and makes the release decision. ISPnext records the tests performed and the decision.
The testing process includes at least the following categories:
- Functional: does the Capability do what was agreed, as tested against the acceptance criteria.
- Quality: is the output sufficiently accurate, relevant and consistent, as tested using a test set and thresholds.
- Errors and edge cases: what happens with unclear, incomplete or abnormal input.
- Privacy and security: can data leak, be manipulated or be logged unintentionally.
- Human oversight: can the user recognise, check and correct the output and stop it if necessary.
Despite extensive testing, the output of nextAI may be incomplete, inaccurate or incorrect. When using nextAI components, always check the AI output before it is processed or used as the basis for decision-making.
5. Production acceptance
Before release, ISPnext assesses whether the required monitoring, correction options and recovery measures are available. The required measures differ per functionality. ISPnext handles a high or critical residual risk according to the risk process.
6. Changes after production release
When an existing nextAI functionality is materially changed - for example, through a new model, a new data source, a new target audience or a substantially different risk profile - the full assessment process is repeated before the change is put into production. ISPnext publishes material changes in the release notes. If a change affects the use of or customers' responsibilities, ISPnext informs the customers concerned through the usual customer communications.