Scope
This policy applies to the AI systems and autonomous agents that Fellow Data develops. It explains how we design them so that people stay in control of what AI can see, decide and do. For how agents work in our products, see AI agents.
Our principles
Human accountability
AI systems do not replace organisational accountability. Responsibility for decisions stays with people and with the organisations that deploy the technology.
Transparency
We label AI-generated output, such as research summaries, so that users know when they are reading it, and link it to its sources where it draws on documents or data. Important system behaviour should be observable.
Security
AI systems must be protected against:
- Unauthorised access
- Prompt injection
- Data leakage
- Model manipulation
- Malicious inputs
Privacy
Personal data should not be provided to AI systems unless appropriate legal and technical safeguards are in place.
Reliability
AI systems should be tested and monitored according to their intended use.
Human oversight
Fellow Data's AI agents provide analysis and information only. They do not place trades or give investment advice, and decisions based on their outputs are made by people.
Auditability
Relevant agent tasks, outputs and system events should be logged where technically and legally appropriate.
Agent control framework
Every autonomous agent is defined and constrained in this order:
- 01Agent identity: each agent has its own identity and an accountable owner.
- 02Authorised data sources: the agent reads only the sources it is granted.
- 03Defined objective: the agent works towards a written objective.
- 04Permitted tools: only the tools registered for the agent are available to it.
- 05Scope limits: the analysis the agent may perform is fixed in its policy.
- 06Read-only access: the agent cannot place trades, move funds or change records.
- 07Human review: outputs that need checking are routed to a person.
- 08Output: the agent delivers its analysis, alerts and reports.
- 09Logging: events, decisions and results are recorded.
- 10Monitoring: agent behaviour is reviewed over time.
Agent permissions
Each agent has explicit permissions. A typical default looks like this:
| Permission | Default |
|---|---|
| Read market data | Yes |
| Read account data | Conditional |
| Generate analysis | Yes |
| Send alerts | Yes |
| Place or prepare orders | Not available |
| Give investment advice | Not available |
| Modify risk limits | Not available |
| Transfer funds | Not available |
| Delete records | Not available |
Levels of autonomy
Organisations choose how much analysis an agent may do on its own. At every level, agents do not trade or give investment advice. We describe five levels:
- 01Observe: the agent monitors information only.
- 02Analyse: the agent produces analysis and intelligence.
- 03Evaluate: the agent evaluates scenarios and risk, and explains its findings.
- 04Report: the agent prepares research reports and briefings for review.
- 05Autonomous analysis: the agent runs multi-step research on its own, within the data and scope you configure.
Fellow Data's AI agents analyse and evaluate information only. They do not place, prepare or execute trades, and they do not give investment advice. Trading decisions always stay with your traders.
Limitations of AI
AI systems may produce probabilistic or non-deterministic outputs. Fellow Data does not represent that AI-generated outputs will always be accurate, complete, unbiased or suitable for a particular purpose.
Customers should implement appropriate validation, monitoring, human oversight and risk controls based on the intended use of the system.
AI-generated outputs may be incomplete or inaccurate and should be reviewed according to the intended use and applicable controls.
Regulatory context
Regulators have highlighted the risks of AI in financial services. The European Securities and Markets Authority (ESMA), for example, has pointed to issues such as AI bias, data quality, opaque decision-making, over-reliance on AI, privacy and security in investment services.
Relevant considerations may also include AI governance and data-protection requirements in the jurisdictions where the technology is used. Specific obligations depend on the customer's jurisdiction, business model and use of the technology.
Contact
Questions about how we govern AI: info@fellowdata.com.