01Purpose and scope
This policy describes the principles and practices XTO Pty Ltd (XTO) applies across the lifecycle of the AI systems we research, design, build, deploy and operate, including our own products and the systems we build for clients and partners. It applies to everyone who works at or with XTO.
02Our principles
Our work is guided by Australia's eight AI Ethics Principles:
- Human, societal and environmental wellbeing: AI systems should benefit individuals, society and the environment.
- Human-centred values: AI systems should respect human rights, diversity and the autonomy of individuals.
- Fairness: AI systems should be inclusive and accessible, and should not involve or result in unfair discrimination.
- Privacy protection and security: AI systems should respect and uphold privacy rights and data protection, and ensure the security of data.
- Reliability and safety: AI systems should reliably operate in accordance with their intended purpose.
- Transparency and explainability: there should be transparency and responsible disclosure so people can understand when they are being significantly impacted by AI, and can find out when an AI system is engaging with them.
- Contestability: when an AI system significantly impacts a person, community, group or environment, there should be a timely process to allow people to challenge its use or outcomes.
- Accountability: people responsible for the different phases of the AI system lifecycle should be identifiable and accountable for its outcomes, and human oversight of AI systems should be enabled.
We also draw on the Australian Government's voluntary AI safety guidance and recognised international standards for AI management and risk, such as ISO/IEC 42001 and the NIST AI Risk Management Framework.
03Human oversight
- Systems that inform or make decisions with significant consequences for people are designed with meaningful human review, override and escalation paths.
- Autonomous agents operate within explicit permissions, spending limits and tool scopes, with actions logged and reviewable.
- Every AI system we deploy has a named, accountable owner.
04Data stewardship
- We never use client data to train or improve models for any other party, or for our own general-purpose models, without explicit written permission.
- We collect and retain only the data a system needs, and apply access controls, encryption and retention limits.
- Where required, we design deployments that keep data within Australia.
- We handle personal information in accordance with the Privacy Act 1988 (Cth) and our Privacy Policy.
05Evaluation and testing
- Before release, systems are evaluated for accuracy, robustness, safety and security against criteria agreed in advance.
- We test for unfair bias across relevant groups and document known limitations.
- Higher-risk systems undergo adversarial testing ("red-teaming"), including for prompt injection, data leakage and misuse.
- Evaluations continue after release, with monitoring for drift, failures and emerging risks.
06Transparency
- People should know when they are interacting with an AI system. Our products make this clear.
- We label AI-generated media where there is a risk it could be mistaken for authentic content.
- We provide clients with documentation describing each system's intended use, limitations and evaluation results.
07What we will not build
XTO will not knowingly design, build or deploy AI systems intended to:
- cause physical harm, or serve as weapons or weapons-targeting systems;
- conduct unlawful surveillance or mass profiling of individuals;
- deceive or manipulate people in ways that undermine their autonomy, including non-consensual deepfakes or impersonation;
- unlawfully discriminate against people or groups; or
- facilitate fraud, cyber-attacks or other illegal activity.
We may decline or end any engagement that we believe conflicts with this policy.
08Contestability and incidents
We maintain processes to receive, investigate and respond to concerns about the behaviour or impact of our AI systems. Where an AI incident occurs, we act to contain it, notify affected parties where appropriate, and apply lessons learned across our work.
09Governance and review
Responsibility for this policy sits with XTO's leadership. We review it at least annually, and whenever there are significant changes in technology, regulation or our business.
10Raising a concern
If you have a concern about an XTO AI system, or about this policy, please contact us. Concerns can be raised confidentially.
XTO Pty Ltd, Responsible AIEmail: support@xto.au (subject: "Responsible AI")