BACK

AI Supplier, Foundation Model & API Due Diligence Policy

Version 1.0 · Last Updated:

1. Purpose

This policy sets out Murzo Group's approach to AI suppliers, foundation model providers, API providers, hosted agents, automation platforms, model marketplaces, AI plugins, AI infrastructure, and third-party AI services.

The purpose is to reduce risk from opaque suppliers, unsuitable model use, weak contracts, insecure APIs, hidden training uses, poor support, data leakage, hallucinations, service outages, and unclear liability.

2. Scope

This policy applies to AI tools used for text, images, audio, video, code, data extraction, translation, customer service, recruitment, analytics, robotics, security, product development, compliance, marketing, legal drafting, design, ecommerce, and internal operations.

It applies to free tools, paid tools, enterprise tools, APIs, open-source models, local models, cloud models, AI agents, browser tools, developer tools, embeddings, vector databases, fine-tuning services, data labelling services, and AI subcontractors.

3. Supplier Due Diligence

Before using an AI supplier for sensitive, business-critical, customer-facing, regulated, or public activity, Murzo Group should consider supplier identity, jurisdiction, security, data use, model behaviour, service terms, IP position, privacy terms, subcontractors, hosting, audit rights, support, continuity, incident reporting, and exit route.

Convenience, low cost, novelty, or popularity must not override confidentiality, data protection, intellectual property, product safety, cyber security, customer trust, or legal compliance.

4. Data Use and Training Restrictions

Murzo Group must understand whether prompts, uploads, outputs, logs, feedback, embeddings, files, customer data, source code, or telemetry may be used by an AI supplier for training, evaluation, abuse monitoring, support, human review, or onward sharing.

Sensitive data must not be sent to AI suppliers unless the tool, purpose, data type, jurisdiction, security, and contractual position are suitable.

5. Contract and Role Allocation

Contracts or terms should allocate responsibility for data processing, confidentiality, IP rights, model output use, service availability, security incidents, vulnerability reporting, subcontractors, regulatory cooperation, support, deletion, audit, indemnity, warranty, and liability where appropriate.

Where Murzo Group integrates, rebrands, modifies, fine-tunes, or deploys a third-party AI system, role allocation under UK, EU, China, product, data, and customer law must be considered. Murzo Group must not accidentally become responsible for high-risk AI, product, or regulatory obligations without approval.

6. Foundation Models and General-Purpose AI

Foundation models and general-purpose AI systems may behave unpredictably across different use cases. Murzo Group should consider model capability, limitations, safety settings, known risks, prohibited uses, model cards, technical documentation, training data disclosures, evaluation results, and provider warnings where available.

High-impact use requires stronger review than low-risk drafting, brainstorming, formatting, or internal productivity use.

7. APIs, Agents and Automation

AI APIs and agents must be controlled where they can access files, email, accounts, payment systems, customer systems, code repositories, websites, devices, robotics, databases, or external tools.

AI agents must not be given broad credentials, production access, payment authority, legal authority, publication authority, deletion rights, or physical control permissions unless approved for that specific purpose and protected by safeguards.

8. Monitoring, Incidents and Exit

Murzo Group should monitor material AI suppliers for major changes in terms, pricing, data use, ownership, hosting, security, model behaviour, support, sanctions, export controls, availability, and regulatory position.

Where an AI supplier suffers a breach, outage, model regression, vulnerability, unsafe output pattern, regulatory restriction, or unacceptable contractual change, Murzo Group may suspend use, change supplier, notify affected parties, or apply alternative controls.

9. Third-Party Responsibility

Suppliers remain responsible for their own models, services, infrastructure, training practices, technical claims, security, support, outages, licences, and legal compliance unless Murzo Group has expressly accepted responsibility in writing.

To the fullest extent permitted by law, Murzo Group does not accept responsibility for third-party AI supplier failures, hallucinations, downtime, model changes, data misuse, security incidents, API misuse, unlawful training, or unsupported outputs outside Murzo Group's approved use and control.

10. Review and Evidence

Murzo Group may keep proportionate evidence of supplier checks, approvals, terms, data decisions, API permissions, incidents, and exit decisions where needed for legal, privacy, security, customer, or dispute purposes.

This policy should be reviewed when suppliers, models, APIs, law, customer services, or Murzo Group AI uses change.

Murzo Group signature