// Rules

How we use AI ourselves

We help companies set rules for AI, so here are ours. Short and specific.

We use AI mainly for drafting text, research and writing code. We work with company accounts, not private ones. We don't paste client data into public AI tools. Every article is reviewed and signed by a named author, and every code change is reviewed by a person before it ships. A human is always accountable for the result.

// Scope

What we use AI for, and what we don't

We use AI for

  • Drafts of articles, proposals and documentation, which the author then rewrites and checks
  • Research: collecting sources, comparing versions of regulations and summarizing public documents
  • Writing and reviewing code, including the code of this website
  • Pre-sorting findings in the Evidence Box, on models that run locally in the client's network

We don't use AI for

  • Working on client data in public AI tools: logs, configurations, code and personal data
  • Publishing text without the author's review
  • Signing off audit findings, because a human signs the result
  • Changing clients' production systems

If your security policy requires stricter rules for a project, we agree them in writing before the project starts.

Articles: a named author, facts from sources

Every article on our blog has an author: Michal or Łukasz. AI helps with the draft and with collecting sources. The author checks the facts against primary sources, such as acts, regulations and documents from authorities, adds experience from projects and is accountable for the text. We mark dates and legal facts with "as of" and correct them when they change.

Code: a review before every deployment

We use AI assistants when writing code, including the code of this website. Every change goes through a pull request, automated tests and a human review before it reaches production. We check AI-assisted code the same way as hand-written code, and on client projects also for the risks we describe in our article on securing AI-built applications.

Client data stays out of public tools

We don't paste client logs, configurations, personal data, code or documents into public AI chats. When a project needs AI-assisted analysis, we run it in an environment agreed with the client or on a locally hosted model. We follow the advice we give clients: shadow AI starts with a single personal account.

Local models in the Evidence Box

FutureCode Evidence Box runs inside the client's network, with no internet access. An AI model makes the first assessment of findings, and a second model from a different family checks it. Disagreements go to a human. The appliance suggests fixes but never changes production systems, and an auditor signs off the result.

Our internal rules

  • Company accounts only for AI tools at work, no personal accounts.
  • Where the vendor offers the choice, we opt out of model training on our data.
  • A human is accountable for every result: the author for text, the approver for code, the auditor for findings.
  • We support AI literacy in our team, as Article 4 of the AI Act requires.

We help clients put the same rules in place: AI governance and security.

// FAQ

Questions about AI at FutureCode

Is the blog written by AI?

Not end to end. AI helps with the draft and the sources, and the author writes, checks and signs the text. We verify facts against primary sources before publishing.

Do you paste our data into a public AI chat?

No. Client data stays in the environment agreed with the client. If AI-assisted analysis makes sense, we run it on a locally hosted model or in a tool you have approved.

Does AI-assisted code reach you without a review?

No. Every change is reviewed by a person and passes automated tests before it reaches production. The person who approves a change is accountable for it.

Which models does the Evidence Box use?

Models that run locally in your network, with no internet access. One model makes the first assessment and a second model from a different family checks it. We show the exact setup in the demo.

Let's talk about your situation

We reply within one business day

Tell us which system, data or regulation you are dealing with. We'll come back with questions about scope and a proposed first step of 4 to 6 weeks. No sales pitch.