Skip to main content

WeSalute Generative AI Use Policy

What

WeSalute Generative AI Use Policy

At WeSalute, we are committed to leveraging the power of generative Artificial Intelligence (AI, or GenAI) to drive innovation, enhance efficiency, and do better work in the course of carrying out our mission. We will prioritize responsible use, data security, and ethical considerations as we embrace AI technologies. This policy outlines the goals, use, and guidelines around using generative AI tools.

Why

This policy applies to all employees, third-party contractors, and anyone else working on behalf of WeSalute and exists to encourage and guide generative AI usage on top of our principles.

Goals for Generative AI Use

At WeSalute, we seek to understand and engage with generative AI and build its implementation into our plans. Although AI tools present an opportunity to innovate, grow, and create efficiency, all teams must understand the risks and rules regarding the technology’s use.

AI can broadly be broken up into two functional types: Large Language Models (GenAI or LLMs) and all other non-generative machine learning (ML) AI algorithms. Traditional deterministic ML algorithms that have no predictive/generative capabilities – and even those with limited predictive capabilities – do not carry the wide variety of risks that come with GenAI, require specific technical expertise, and need no formal guidelines for company-wide use.

Uses for generative AI at WeSalute:

  • Enhancing operational efficiency and productivity
  • Delivering superior customer experiences through personalized services
  • Driving innovation in products and services
  • Supporting data-driven decision-making

Generative AI tools are not to be used for/as:

  • Creating uncredited or unvalidated statements
    • Example: Fabricating an email or communication from a team member, customer, or business partner, or using a “fact” generated by AI that you have not verified is factual in the course of an official manner on behalf of the company.
  • A replacement for human expertise
    • Example: When authenticity of character, personal experience, or creative talent is the point, such as:
  • Making hiring decisions based on an AI summary of an interview of a potential candidate for a job.
    • AI summaries are not to be used in the decision-making process of hiring a candidate for a position, as it is a poor replacement for your attendance and attention in the meeting itself.
  • Generating a soundalike song instead of licensing a distinct song for use in an advertisement or video
  • Generating images or video in the style of a particular artist rather than licensing said artist’s work or commissioning said artist for new images or video

Using Generative AI

Generative AI - including AI that creates content such as text, images, audio, and videos - must be used ethically and responsibly.

At WeSalute, we adhere to the following ethical principles:

  • Accountability: Review all AI-generated content. All employees are responsible for the actions taken on their behalf by their generative AI.
  • Accuracy: Ensure the accuracy and reliability of AI-generated content. This includes validating facts and figures with other sources that weren’t cited by the AI in generating its content. Nearly all GenAI tools display a disclaimer stating that AI can make factual errors or make things up, and that its output should be double-checked.
  • Respect The User: When importing or uploading data into a generative AI tool, ensure that personally-identifiable information (names, addresses, emails, phone numbers, medical identifiers, social security numbers) is redacted/erased from your uploaded content. This prevents violations of privacy and the circumventing of internal access policies.
    • All user or team member PII should only be ingested and accessed through properly set integrations or company-approved systems that respect company user access policies set by SystemsOps.
  • Transparency: Clearly disclose to WeSalute employees when content is generated by AI. If generative AI is used in the creation of customer-facing creative content (music, images, or video), you will create an accompanying conspicuous disclosure to users that the content was generated by AI.
    • Honest disclosure reinforces the trust our customers have in us. Attempts to disguise AI-generated content as human-made content will erode that trust and can be seen by users to discount their intellectual capacity to discern the authenticity of human-made content.
  • Accepting Legal Limitations: The US Copyright Office has declared that AI-generated content with no further substantial creative human contribution is not copyrightable (United States Copyright Office).
    • Additional AI prompts to refine the generated content are not considered creative human contributions. You must further alter the content manually and substantively in order for the works to be considered as WeSalute intellectual property, otherwise we cannot control how it is further used by the public.
  • Non-Maleficence: Avoid using AI to intentionally mislead or for harmful purposes. GenAI is a cutting-edge technology in the middle of a meteoric rise in its capabilities and financial backing, while at the same time being largely unrestrained by legal regulation. As such, the capacity for GenAI to be able to be used in misleading or harmful ways is also increasing disproportionately to other technologies.
    • “With great power comes great responsibility.”

AI Agent Usage

In 2026, AI Agents are the cutting edge of generative AI, able to plan and execute sequences of actions in response to user instructions independently of the user’s supervision. With this ability, users must take extra care to limit the scope of their requests of AI agents so that they can maintain control over the actions taken.

Our primary rules for working with AI echo those of Ukraine’s Ministry of Digital Transformation’s:

  • You, the human, maintain responsibility for any agents you create and actions they take at your request.
  • Don’t give an AI agent access to data it doesn’t need for your request (configure the connectors you allow your agent to access with each request you make.)
  • Give an agent simple tasks first to prove it will do what you intended before giving it more complex tasks, as agents are less reliable at greater task complexities.
  • Audit your agent regularly if it is designed to work without your communication to ensure it stays on-task and provides the intended outcome.
  • If an AI agent is doing anything harmful, against our company policies, or destructive, it is your responsibility to stop the AI agent from continuing. Do not delete the agent. Report the agent and its behavior to members of the WeSalute AI Oversight Committee for further evaluation.
  • Before creating or moving consumer user, internal user, or business partner personal data in or into a data destination where it does not already reside, first evaluate the following:
    • Is the user’s personal data necessary for the intended use?
    • Are there safeguards in place to keep teammates who shouldn’t be able to access this data from accessing it?
    • Will this make permanent changes in the destination?
      • Agents should rarely need to create or move personal data for users because of the sensitivity and regulations surrounding the use of personal data. If you are unsure of the answer to these questions, contact DataOps for assistance before continuing.

Accountability: You maintain full responsibility and liability for all actions executed by an AI agent on your behalf, including any resulting consequences. Notification: If your creation or movement of personal data is necessary, notify DataOps to obtain approval before you take action.

Compliance with relevant laws and regulations is a cornerstone of our AI strategy. All work produced with the help of generative AI must demonstrate adherence to these guidelines.

  • Intellectual Property (IP): As mentioned above, work produced by generative AI systems is not copyrightable without substantive human alteration. Additionally, work produced by generative AI systems carries the risk of unintentionally or intentionally reproducing the intellectual property that it has been trained on (IP of other third parties).
    • Plan accordingly before the content is employed to customers or partners outside of the WeSalute team to ensure that the content does not violate IP laws.
    • Do not input the copyrighted material of any third party into a generative AI system. You must own the copyright to any image, video, song, or work of text that you input unless you have specific written consent from the copyright holder to use a copyrighted work.
  • Product Liability: As case law and state-based or federal regulation is being established around GenAI, it is becoming increasingly evident that AI is being treated legally as a product on behalf of the company that uses or develops it, rather than a neutral technology that exists separate of the company. As such, if it is deployed for a customer’s use, we should expect that we will face an elevated level of liability.
    • Any customer-facing use of GenAI will be subject to oversight by the WeSalute AI Oversight Committee to identify and mitigate potential liabilities that may be introduced by its use.
  • Data Privacy: Ensure that all AI use complies with data protection regulations, such as GDPR and CCPA. Do not upload or import any customer personal data into any generative AI system. Reference the WeSalute Data Policy for company guidelines on compliance with data protection regulations.
    • Use of official AI integrations into destinations (such as official Google Gemini connectors) that match users with their corresponding level of access in the destination system is a permitted use of customer personal data. Customer data that exists in these systems is not able to be exfiltrated or accessed by users that lack the permissions to access the data already.
      • Appropriate access level assignment by SystemsOps is important for this reason.
  • Training and Compliance: The WeSalute Data Privacy Officer (currently Frank Serafine) shall be responsible for answering questions from team members on compliant use of AI according to developed and developing applicable data privacy and AI laws, and will refer to LegalOps in the case of unknowns or higher risk scenarios. The WeSalute AI Oversight Committee will be responsible for procuring training material or instruction on AI use and data privacy compliance.

How

Data and Security

Protecting data integrity and security is crucial. To ensure that employee use of generative AI does not compromise our resources, the following guidelines are the responsibility of all team members and managers.

  • Data Protection: Do not share “sensitive personal information,” company trade secrets, confidential information, or login information for any company systems with any AI software.
  • Access Control: Restrict access to sensitive data and AI systems to authorized personnel.
  • Use of Approved Implementations: Only utilize the approved GenAI tools when doing WeSalute work on approved company devices. Use of personal GenAI accounts for WeSalute work is not authorized and puts company data at risk.
  • Regular Auditing: The WeSalute Data Protection Officer (currently Frank Serafine) will conduct regular GenAI audits and applicable data privacy assessments to identify and mitigate risks associated with generative AI use.
  • Single-Tenant Preference: When considering new generative AI tools or vendors that utilize generative AI tools, ensure that those tools are “single tenant,” meaning that we get a dedicated, private instance of an AI and its underlying infrastructure.
    • Unlike a multi-tenant system, where resources are shared, a single-tenant environment gives us our own implementation of the AI and resources. In most cases, this also means that the public-facing version of the AI product will not be retrained on the data we expose to our private implementation of the AI. However, this is not always guaranteed.
  • No Training on Company or Customer Data: When considering new generative AI tools or vendors that utilize generative AI tools, ensure that the data we put into the AI will not be used to train the public-facing AI.
    • This ensures that sensitive data does not get exfiltrated outside the company.

Monitoring AI Bias

AI systems can inadvertently perpetuate biases that are present in the data it is trained with. To ensure that all work and content created for WeSalute does not further these biases, DataOps will be responsible for:

  • Bias Identification: Review AI agents for social or data biases when the agents are geared toward evaluative or creative purposes or that are used for automated decision-making, which present higher consequences for bias.
  • Bias Mitigation: Implement strategies and technologies to reduce bias in AI outputs.

Approved AI Tools

GenAI tools that are generally accepted for use at WeSalute with adherence to the guidelines above are listed in this linked document (click here). Many AI-driven tools may be acceptable upon review by the WeSalute AI Oversight Committee and SystemsOps.

  • Only use licensing supplied by SystemsOps so that usage is tracked and billed appropriately.
  • For unlisted GenAI tools, please submit a help desk ticket (here) to begin the approval process and refrain from use until completed.

Questions About AI?

Refer all questions and concerns regarding the use of AI at WeSalute to the WeSalute AI Oversight Committee via Slack (Roy Asfar, Frank Serafine, Rin Camelia, Leonid Makarov, Jourdan Morris, or Stephanie Padilla)