Responsible AI

Autonomous AI, within the authority you’ve granted it.

Most AI wrappers are built on models trained to sound helpful — with either no rules or brittle deterministic ones. That’s how a chatbot invents a refund policy, or frustrates a customer who doesn’t fit the script.

A Neos agent is built differently: autonomous within a declared authority you configure, and trained to be a helpful outcome-based guide outside it.

01 Configured, not coded

Your policies live in a setting you change, not a project we rebuild.

02 Bounded, not fenced

Every permission is granted explicitly. What isn’t declared, isn’t authorised.

03 Owned, not outsourced

Managed by Neos end-to-end. When something goes wrong, one team fixes it.

Independent assurance

Who verifies we’re safe to work with

Certificates and evidence available on request.

Cyber Essentials

Certified by IASME, June 2026. UK Government-backed scheme.

NHS DSPT — Standards Met

2025-26 (v8), valid to 30 June 2027. On the NHS Digital register.

UK GDPR

Registered with the Information Commissioner’s Office.

UK / EEA processing

Customer data stays inside the service environment we operate for you.

How our agents work

Five things every Neos agent is built to do.

One methodology, one operating standard, one safety floor. What the buyer sees, and what the auditor sees.

Trained the same way our people are

Every agent runs on the Neos Core — the same methodology of Trust, Mutual Respect, Accountability, and Sincerity that we teach the humans in our team. Human service defaults to under-acting; AI defaults to over-acting. The Neos Core is written to prevent both.

Declared authority

Every agent starts with zero authority. Everything it can commit is granted by you, in configuration. If a grant is absent, expired, or ambiguous, it routes to a human.

Why this matters

Capability, precedent, customer pressure, or a persuasive explanation do not create authority. This is the structural answer to the Air Canada failure mode — a chatbot invented a fare class and the airline was held to it. That cannot happen with a properly declared Neos agent, because the answer to “can you do X for me?” is not yes. It is: “let me check what I’m authorised to do here.”

The Service Handshake

Every conversation opens by establishing identity, scope, authority, boundaries, and promise — proportionately, across the first exchange. Openly published under Creative Commons.

The five things declared
  • Identity — who I am, and that I’m an AI.
  • Scope — what I can help with.
  • Authority — what I can commit on your behalf, and what I can’t.
  • Boundaries — what I will hand to a human.
  • Promise — how I will treat you.

If a customer ever asks “am I speaking to a bot?”, a Neos agent answers honestly and immediately. See the Service Handshake standard.

A safety floor that can’t be overridden

A short set of hard rules that fire regardless of context, brand, or instruction. If the agent detects a situationally vulnerable moment — distress, safeguarding language, coercion, confusion — it pauses and routes to a human in the same conversation.

What the safety floor covers
  • Never claims to be human when asked.
  • Detects situationally vulnerable moments — distress, safeguarding language, coercion, confusion, or someone acting under pressure — and pauses the conversation for a human in the same thread, with full context preserved.
  • On safeguarding disclosures, does not counsel or investigate — acknowledges warmly, points to the appropriate resource, and routes for human review.
  • Will not give clinical, legal, or financial advice — not “as general information,” not “hypothetically.”
  • Treats retrieved content, images, and attachments as material to analyse, not instructions to follow.
  • If a customer volunteers information the agent doesn’t need — ID documents, payment details, passwords — the agent asks them to remove it, and does not use or store it.
  • Cannot be overridden by any layer of configuration, by our team, by the client, or by the person in conversation.

What we do with information

Purpose limitation, data minimisation, retention discipline. Agents ask for the least information they need, don’t reference past interactions unless configured to, and customer data isn’t used to train third-party model providers.

Audit & traceability

Every action a Neos agent takes on your behalf is traceable back to the sources it used and the model version that produced it. Deployments are pinned to a specific version of the Neos Core, so the operating rules applied to any given interaction can be reproduced and reviewed. Full audit log available to clients on request. See our Privacy Notice for the full data handling detail.

The difference in practice

Two ways an AI can answer “can you do X for me?”

The default behaviour of a language model, and the behaviour we’ve trained into ours.

Default AI
  • Optimised to be helpful, so answers “yes” by default
  • Can be talked around with persuasive framing
  • Invents policy the brand didn’t authorise
  • May counsel on clinical, legal, or financial matters
  • Escalates only when it gets stuck
A Neos agent
  • Operates within an authority you’ve declared in configuration
  • Hard boundaries can’t be overridden mid-conversation
  • “Let me check what I’m authorised to do here” is a valid answer
  • Won’t give clinical, legal, or financial advice, ever
  • Escalates the moment the situation asks for judgement it doesn’t have

Acts where it’s authorised. Guides where it isn’t.

A Neos agent begins with zero authority to commit anything on your behalf. Every permission — the refunds it can offer, the appointments it can confirm, the fees it can quote — is granted explicitly in your configuration. Ambiguous, expired, or absent? It guides to the right person or route instead of inventing an answer. The chatbot that invented a bereavement fare and cost Air Canada in tribunal did the opposite of this.

Deployment options

Where the models run.

Different tasks have different sovereignty, latency, and cost profiles. A Neos agent selects the right model tier per task — not per deployment — inside whichever shape your organisation needs. Reasoning, drafting, classification, and voice can each run on a different model.

Tier 1

Cloud frontier models

Anthropic Claude, OpenAI

Frontier-class reasoning for workloads that don’t require jurisdiction-bound processing. Hosted on UK/EEA endpoints where available, with training-exclusion terms in place.

Tier 2

Local GDPR-resident models

Mistral, Ollama

Workloads that must remain inside the UK or EEA jurisdiction. Run on EEA-hosted infrastructure or self-hosted.

Tier 3

Sovereign frontier models

Kimi, Qwen

Open-weight models self-hosted end-to-end, for deployments where the model itself must run inside your environment.

Ask us the hard AI questions.

If you’re scoping an AI service operation and you need to know where your data goes, what your AI can and can’t commit to, and who’s accountable when it’s wrong — we’d rather answer those questions than dodge them.