Back to Home
UK Compliance

AI Governance & Responsible AI Policy

AnaOS, a product of Anas Technologies Ltd. (registered in England & Wales), is committed to the responsible and transparent deployment of Artificial Intelligence in all our products and services. This policy outlines our compliance with the UK Government's AI Regulation Framework and our internal governance principles.

Last updated: 08 September 2026

1Alignment with UK AI Regulation White Paper

AnaOS operates in alignment with the UK Government's March 2023 "A pro-innovation approach to AI regulation" White Paper and subsequent updates. We design our AI systems around the five core cross-sector principles established by the UK government:

  • Safety, Security & Robustness: Our AI systems are tested rigorously before deployment and continuously monitored for harmful outputs, data leakage, and adversarial vulnerabilities.
  • Appropriate Transparency & Explainability: Users and clients are always informed when they are interacting with or being processed by an AI system. Automated decisions can be reviewed and explained.
  • Fairness: We actively audit our AI models for biases across demographic groups and ensure equitable treatment in all automated processing pipelines.
  • Accountability & Governance: A named AI Officer within Anas Technologies Ltd. is responsible for the oversight of all AI systems. All third-party AI services (e.g., OpenAI) are bound by sub-processor agreements.
  • Contestability & Redress: End-users have the right to contest any automated decision made by an AnaOS system. Clear escalation pathways are provided via our support team.

2ICO Guidance on AI & UK GDPR

In compliance with the UK Information Commissioner's Office (ICO) guidelines on AI and Data Protection (under UK GDPR and the Data Protection Act 2018), AnaOS adheres to the following:

  • We process personal data through AI systems only with a lawful basis (e.g., legitimate interests, consent, or contract performance).
  • We conduct Data Protection Impact Assessments (DPIAs) for all high-risk AI processing activities.
  • We do not use personal data of UK residents to train our core AI models without explicit consent.
  • We provide clear opt-out mechanisms for AI-driven communications and profiling.
  • All AI outputs involving personal data are subject to human review mechanisms where required by law.

3Prohibited Uses of AnaOS AI

In line with UK government guidance and industry best practices, the following use cases are strictly prohibited on the AnaOS platform:

  • Using AnaOS AI systems for discriminatory targeting based on race, religion, gender, age, or sexual orientation.
  • Generating or distributing synthetic media (deepfakes) designed to deceive or defraud individuals.
  • Automated processing of UK residents' special category data (health, biometric, political views) without explicit consent.
  • Using AI-generated messaging to impersonate a human without disclosing the AI nature of the communication.
  • Any application that falls under the definition of 'unacceptable risk' AI as defined by the EU AI Act (which AnaOS applies as best practice).

4Third-Party AI Sub-Processors

AnaOS integrates with the following third-party AI service providers, all of whom are bound by Data Processing Agreements and are assessed for their own compliance posture:

ProviderPurposeData Location
OpenAILarge Language Model (AI responses, workflow generation)USA (SCCs in place)
Meta (WhatsApp/Instagram)Messaging delivery & receiptUSA/EU (SCCs in place)
TwilioSMS / Voice call deliveryUSA (SCCs in place)
Google CloudInfrastructure, Cloud StorageEU (London region preferred)
StripePayment processingEU (Dublin)

5Incident Response & Reporting

In the event of an AI-related incident (e.g., biased output causing harm, a data breach involving AI-processed data), Anas Technologies Ltd. will:

  1. 1Contain and assess the incident within 24 hours of discovery.
  2. 2Notify affected data subjects and the ICO within 72 hours if the incident constitutes a reportable breach under UK GDPR.
  3. 3Conduct a root cause analysis and publish a remediation report within 30 days.
  4. 4Report significant AI safety incidents to the relevant sectoral regulator as guided by the UK AI Safety Institute (AISI).

AI Governance Contact

For questions regarding our AI Governance policy, to exercise your rights under UK GDPR, or to report an AI-related concern:

Email: ai-governance@anaos.ai

Company: Anas Technologies Ltd.

Registered Office: 12 Lime Street, Liverpool, L1 1JJ, England, United Kingdom

Regulator: Information Commissioner's Office (ICO)

AnaOS 1.0.0 (Build 2026.06)