LUM-AI-POL-001 · Version 2.3 · Effective September 2026 · Review due April 2027 · Owner: Alex Feeney, Founder, Lumireon Assurance
Version history is maintained at the end of this document. Operating steps for the data handling controls are set out in Appendix A.
1. Purpose
This policy governs how Lumireon Assurance uses artificial intelligence tools in its professional work. It sets out the principles, controls and standards that apply to AI use in all activities, whether internal, client-facing or public-facing.
Lumireon Assurance is an AI governance and assurance practice. Its advice is only credible if it applies the same standard to its own operations that it asks of clients. This policy describes how Lumireon Assurance works in practice, including where its controls are limited.
The controls described here are proportionate to a sole practitioner working in an advisory capacity. As Lumireon Assurance grows, adding clients, staff or associates, the policy will be reviewed and expanded.
2. Scope
This policy applies to:
- all use of AI tools by Lumireon Assurance in connection with its professional activities;
- all content, analysis and advice produced with AI assistance;
- all client engagements, whether advisory, analytical or research-based;
- all thought leadership, published articles and policy papers produced under the Lumireon Assurance name; and
- any connection between an AI tool and Lumireon’s email, file storage, calendar or other business accounts.
It covers the AI tools in current use and any adopted in future. A register of tools in active use is maintained separately (LUM-AI-REG-001).
3. AI Tools in Use
Lumireon Assurance uses two AI platforms. They operate under different contractual terms, and those terms decide what each may be used for.
| Tool and account | Terms and permitted use |
|---|---|
| Gemini (Google), used through Lumireon’s Google Workspace Business Plus account | Covered by Lumireon’s Google Workspace agreement, under which Google acts as a data processor. Google states that prompts and responses are not used to train models without permission. This is the only AI tool that may be used with Lumireon’s mailbox, Drive, Calendar or client correspondence, subject to Section 6. |
| Claude (Anthropic), Claude Pro subscription | Consumer terms. No data processing agreement. Training use switched off in account settings. Used for research on public material, drafting, editing and disguised scenarios under Section 6.2. Must not be connected to Lumireon’s Workspace accounts. |
Gemini must only be used for Lumireon work while signed in to the Lumireon Workspace account. Gemini on a personal Google account is not covered by the Workspace agreement and must not be used for Lumireon work.
3.1 Account Settings
On Claude, Lumireon Assurance has switched off data sharing and training use. In the Google Workspace admin console, Gemini’s access to Workspace apps is set deliberately and reviewed. All of these settings are checked in the quarterly self-assessment described in Section 8.
Opt-out settings are a real control, but they are not a contract. They do not give Lumireon the protections of a data processing agreement, which is why Section 6 limits what may be entered into Claude.
3.2 Multi-Model Practice
Lumireon Assurance uses more than one AI platform deliberately. Outputs on significant matters are cross-checked across models to identify inconsistencies, gaps or errors. No single model’s output is treated as definitive without review.
4. Governing Principles
Accuracy. AI outputs are a starting point. Every output used in professional work is reviewed and verified by the practitioner before use, and claims, figures and references are checked against independent sources.
Transparency. Lumireon Assurance does not misrepresent how its work is produced. Where AI tools have contributed materially to an output, this is disclosed to clients on request and, where appropriate, proactively. Published content that has involved AI assistance is held to the same editorial standard as any other content.
Human accountability. Every output, recommendation and piece of advice produced by Lumireon Assurance is the professional responsibility of the practitioner. AI tools inform and assist; they do not decide. Professional judgement is not delegated to an AI system.
Proportionality. The scrutiny applied to an AI output is proportionate to the consequences of it being wrong. Outputs used in client advice, published material or formal assessments receive the highest level of review.
Ongoing calibration. AI tools change over time in behaviour, capability and limitations. Lumireon Assurance follows developments in AI governance, model behaviour and regulation, and adjusts its practice accordingly.
5. Output Controls and Verification
5.1 Review Before Use. No AI output is used in client-facing work, published content or formal advice without human review. Review means reading critically. Where an output makes a factual claim, the claim is checked against an independent source.
5.2 Source Verification. All links, citations and references in published articles and policy papers are checked before publication. A source that cannot be verified is not included.
5.3 Calibration Framework. Lumireon Assurance applies a structured calibration prompt framework (LUM-AI-CAL-001) to test the consistency and reliability of AI outputs on substantive matters, surface uncertainty and identify where further verification is needed.
5.4 Epistemic Labelling. Analysis developed with AI assistance is sorted into three categories: verified fact (source identified and checked), extrapolation (reasoning made explicit) and speculation (identified as such and not presented as established).
6. Client Engagements and Data Handling
This section sets out how Lumireon Assurance handles client information and personal data when using AI tools. It should be read alongside our Privacy and Data Protection Policy (LUM-GDPR-001).
Two different obligations apply. Information about a client organisation is confidential and is protected under the terms of the engagement. Information about identifiable individuals, such as a client’s staff, directors or customers, is personal data and is also protected by data protection law. Information about a company is not personal data in itself, but a person’s name, role or work email address is.
6.1 Platform Terms and Personal Data. A data processing agreement is the contract data protection law requires when a supplier processes personal data on Lumireon’s behalf. It is separate from, and does not replace, the need for a lawful basis for the processing. Gemini used through Lumireon’s Workspace account is covered by such an agreement. Claude, on its current subscription, is not. Therefore:
- personal data belonging to clients or third parties must not be entered into Claude in identifiable or pseudonymised form. This is a firm rule;
- personal data may be processed with Gemini inside Workspace only for a purpose already set out in the Privacy and Data Protection Policy, and only to the extent needed for that purpose; and
- special category data must not be entered into any AI tool, including Gemini, under the current configuration.
6.2 Disguising Client Scenarios. Where AI assistance would help in working through a client situation in Claude, the material is prepared as follows.
- About the organisation. The situation is described in general terms: sector, size band and region, with distinctive details (named products, specific incidents, dates, unusual structures) removed, changed or combined with features from other situations. This protects client confidentiality.
- About individuals. Information about any individual is removed. If it cannot be removed without losing the point of the exercise, it must be anonymised so that no individual could be identified by any means reasonably likely to be used, including by a determined person with ordinary resources. A job title that points to one person (for example, the finance director of a named company) counts as identifying.
- Pseudonymisation. Replacing names with placeholders while Lumireon can still link them back to real people is pseudonymisation. The Information Commission (formerly the ICO) treats pseudonymised data as personal data in the hands of anyone who can re-identify it, so it is subject to Section 6.1 and must not be entered into Claude.
- No mapping keys. Any record linking disguised material back to real clients or individuals is kept outside all AI tools.
- Record. Before client-derived material is submitted, the check in Appendix A is completed and logged.
6.3 Client Documents and Sensitive Material. Material shared by a client is confidential. It is not submitted to Claude unless prepared under Section 6.2. It may be analysed with Gemini inside Workspace where the engagement terms permit the use of AI tools and Section 6.1 is met. Documents containing special category data are not submitted to any AI tool.
6.4 Upgrade Trigger. Lumireon Assurance will move Claude, and any other tool used for client work, to a business tier with a data processing agreement when either of the following applies: an engagement requires personal data to be processed with that tool; or the practice has a regular income that makes the cost proportionate. The upgrade happens before the work begins, not after.
6.5 Connecting AI Tools to Business Accounts. Some AI tools can connect to email, file storage and calendars. These connections give the tool access to whatever the account holds, including personal data about clients, contacts and correspondents. The following rules apply.
- Only a tool covered by a data processing agreement may be connected to Lumireon’s business accounts. At present that is Gemini within Workspace.
- Claude may be connected only to a separate mailbox used solely for newsletters and subscriptions, which contains no client or business correspondence.
- Connections are off by default and switched on only for the task that needs them.
- Gemini’s access to Workspace apps is set in the admin console and limited to the apps needed.
- Every connection in use is recorded in the AI Supplier Register (LUM-AI-REG-001) with its purpose, and reviewed each quarter.
7. Published Content and Thought Leadership
All content published under the Lumireon Assurance name, including Perspectives articles, policy papers and formal communications, meets the following standards:
- AI tools may be used to assist with research, drafting, structuring and editing;
- all factual claims are independently verified before publication;
- all links and cited sources are checked and confirmed as active and accurate before publication;
- published text is checked for AI-typical phrasing before publication;
- the practitioner takes full editorial responsibility for all published content; and
- published content reflects Lumireon Assurance’s considered professional view.
8. Review and Self-Assessment
8.1 Quarterly Self-Assessment. A structured self-assessment is carried out each quarter, in January, April, July and October. It follows a fixed checklist and produces a short written record. The checklist covers:
- whether the AI tools in use have changed, and whether this policy reflects current practice;
- whether opt-out settings on Claude remain active, and whether Gemini’s Workspace settings remain as intended;
- which connections between AI tools and accounts were in use, and whether each complied with Section 6.5;
- whether any client material was used with AI tools, and whether the Appendix A checks were completed and logged;
- any output errors, anomalies or unexpected behaviour, and how they were handled;
- developments in regulation, standards or guidance that require a policy update; and
- whether the calibration framework (LUM-AI-CAL-001) remains fit for purpose.
The record of each self-assessment is retained as evidence and may be made available to clients on request as part of due diligence.
8.2 Triggered Reviews. This policy is also reviewed immediately when:
- a new AI tool is adopted, or a materially new model version (a new flagship generation, not a minor update) is released for a tool already in use;
- a tool’s contractual terms, account tier or connection to business accounts changes;
- a client engagement raises data handling questions this policy does not address;
- a regulatory or standards development requires an update; or
- an output error or governance failure is identified.
Where a new model version is the trigger, adoption is not assumed. The relevant LUM-AI-CAL-001 calibration prompts are run against the new version and weighed against the provider’s published system card, including any independent evaluation results it references, and against behaviour observed in practice. The outcome is one of three decisions: adopt the new version; continue on the prior version pending further testing; or adopt it with defined limitations. Where adoption is deferred, a re-assessment date is set no later than the next quarterly cycle. The decision and its reasoning are recorded under Section 8.1.
8.3 Annual Policy Review. This policy is formally reviewed and reissued each year.
9. Acceptable Use
Generally acceptable
- Research, drafting, editing and structuring of documents, articles and policy papers
- Scenario development and analytical frameworks using hypothetical or disguised context (Section 6.2)
- Summarising publicly available material
- Cross-checking outputs across models
- Internal process development, template creation and operational planning
Acceptable with controls applied
- Working through client scenarios in Claude, prepared and logged under Section 6.2 and Appendix A
- Using Gemini within Workspace with business correspondence or client documents, under Sections 6.1 and 6.3
- Connecting Claude to the newsletter-only mailbox (Section 6.5)
- Drafting client-facing content, subject to full human review before delivery
Not acceptable under current configuration
- Entering personal data about clients or third parties into Claude, whether identifiable or pseudonymised
- Connecting Claude to Lumireon’s business email, Drive or Calendar
- Using Gemini on a personal Google account for Lumireon work
- Entering special category data into any AI tool
- Presenting AI outputs as professional advice without human review and verification
Appendix A. Operating Steps
These steps allow anyone working for Lumireon Assurance to apply Section 6 consistently.
A1. Before submitting client-derived material to Claude
- Remove the client’s name and anything that names or points to an individual.
- Replace specifics with general descriptions: sector, size band, region.
- Remove or alter distinctive details such as named products, specific incidents or dates.
- Ask: could someone who knows the sector work out which organisation, or which person, this is? If yes, generalise further or do not submit.
- Confirm that no mapping between placeholders and real names has been entered into the tool.
- Log the date, tool, engagement reference and the outcome of step 4 in the AI use log kept in Lumireon’s Workspace Drive.
A2. Before switching on a connection between an AI tool and an account
- Confirm the tool and account combination is permitted under Section 6.5.
- Switch the connection on for the task only, and off again when the task is finished.
- Record any new standing connection in the AI Supplier Register (LUM-AI-REG-001).
A3. Quarterly checks on account settings
- Claude: open the privacy settings and confirm training use is off. Record the result.
- Google Admin console: go to Generative AI, then Gemini app, then Apps, and confirm which Workspace apps Gemini can access. Record the result.
- Claude: confirm that only the newsletter-only mailbox is connected. Record the result.
10. Version History
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | March 2026 | Alex Feeney | Initial release |
| 2.0 | April 2026 | Alex Feeney | Revised to reflect sole practitioner scope. Data handling, anonymisation controls and quarterly self-assessment framework added. Aspirational governance structures removed. |
| 2.1 | September 2026 | Alex Feeney | Section 8.2 expanded with a trigger for materially new model versions, a calibration and system-card review before adoption, and a re-assessment deadline. Title block made consistent with Public classification. Reissued on the brand template. |
| 2.2 | September 2026 | Alex Feeney | ChatGPT (OpenAI) removed: no longer used. Section 3 now records the contractual terms of each tool and what each may be used for; Gemini within Google Workspace identified as covered by the Workspace data processing terms. Section 6 rewritten: corrected the description of a data processing agreement (it does not provide a lawful basis); separated client confidentiality from personal data; pseudonymised personal data may no longer be entered into Claude, following ICO guidance that it remains personal data; new Section 6.5 on connecting AI tools to business accounts. Upgrade trigger in 6.4 revised. Quarterly checklist, triggered reviews and acceptable use updated to match. Appendix A (operating steps) added. Wording revised throughout for plain English. |
| 2.3 | September 2026 | Alex Feeney | Section 6.2: reference to the ICO updated to the Information Commission, which replaces it on 30 September 2026 under the Data (Use and Access) Act 2025. |
LUM-AI-POL-001 · Version 2.3 · September 2026 · This document is the property of Lumireon Assurance and may be shared with clients and prospective clients for due diligence purposes.

