Responsible & Ethical AI Policy
Human-centred AI for equitable, safe and trustworthy education
1. Purpose
ICARUS AI uses and enables artificial intelligence in education. This policy establishes the principles, responsibilities and minimum controls required to ensure that AI supports human capability, equitable access to learning and the rights, safety and dignity of learners, educators, employees, contractors and other affected people.
2. Scope
This policy applies to ICARUS AI Inc., its directors, officers, employees and contractors, and to AI systems developed, configured, procured, integrated or used for ICARUS products, services and internal operations. It covers generative AI, machine-learning systems, automated recommendations, profiling, translation, assessment support, content generation and any other automated system capable of materially influencing educational or business outcomes.
Where ICARUS relies on third-party AI providers, the requirements of this policy apply through proportionate vendor assessment, contractual controls and ongoing monitoring.
3. Our principles
Human agency and oversight. AI supports people; it does not displace meaningful human judgment where rights, learning outcomes or significant interests may be affected.
Educational benefit and proportionality. We use AI only for a defined, legitimate purpose and when the expected educational or operational benefit is proportionate to the risks.
Fairness and inclusion. We seek to prevent discrimination, reduce bias and design for diverse languages, cultures, abilities and levels of digital access.
Privacy and data protection. We minimise data, respect purpose limitation, protect confidentiality and apply applicable privacy and data-protection requirements.
Transparency. People should know when they are interacting with AI or receiving AI-generated or AI-assisted content when that fact is material.
Safety, security and reliability. AI systems must be tested, monitored and protected against misuse, harmful outputs, unauthorised access and avoidable failure.
Accountability. A named human owner remains accountable for every material AI use case, including decisions to deploy, modify, suspend or retire it.
Sustainability. We consider energy and resource use when selecting and operating AI services and favour proportionate, efficient solutions.
4. Prohibited uses
- AI that unlawfully discriminates, manipulates or exploits people, including vulnerable learners.
- Fully automated decisions with legal or similarly significant effects without a lawful basis, appropriate safeguards and meaningful human review.
- Deceptive impersonation, fabricated credentials, academic misconduct, surveillance or emotion inference where unlawful or disproportionate.
- Training or configuring systems with personal, confidential, copyrighted or restricted data without appropriate authority and safeguards.
- Deployment of an AI system when material safety, bias, privacy or security risks cannot be reduced to an acceptable level.
5. Risk classification and approval
Every material AI use case must have a named business owner and be documented before deployment. The owner must identify the purpose, affected people, data used, provider, potential benefits, foreseeable harms, human-oversight arrangements and monitoring plan.
Higher-risk uses
Uses that may affect admission, assessment, certification, access to opportunity, employment, payment, discipline, safety, privacy, vulnerable groups or other significant interests require a documented impact assessment and approval by the CEO or a delegated governance body, with input from learning, technology and privacy expertise as appropriate.
Lower-risk uses
Administrative or productivity uses may follow a streamlined review, but must still comply with confidentiality, security, intellectual-property and transparency requirements.
6. Minimum controls across the AI lifecycle
Design and selection. Define the educational purpose; consider non-AI alternatives; assess accessibility, vendor practices, data flows, cybersecurity, intellectual property and environmental efficiency.
Data governance. Use relevant, proportionate and lawfully obtained data; document sensitive data; apply access controls, retention limits and secure deletion.
Testing. Test for accuracy, robustness, harmful content, bias and performance across relevant languages and user groups before release.
Human oversight. Assign people with authority, competence and sufficient information to review outputs, intervene and override or stop the system.
Transparency. Provide clear notices and explain the system’s role, relevant limitations and routes for questions, correction or appeal.
Monitoring. Monitor material incidents, complaints, drift, bias, security and performance; reassess after significant changes.
Retirement. Suspend or retire systems that no longer meet their purpose or risk threshold, and manage retained data and user communications responsibly.
7. Educational integrity
- AI-generated educational content must be reviewed by a suitably qualified person before publication when accuracy or learner safety may be affected.
- Learners and educators must receive practical guidance on appropriate AI use, academic integrity and verification of outputs.
- AI should enhance—not replace—the role of educators, learner agency, critical thinking and meaningful feedback.
- Accessibility and multilingual support must be evaluated in context; translation or adaptation must not be assumed accurate without proportionate review.
8. Rights, concerns and remedy
ICARUS will provide accessible routes for people to ask questions, challenge material AI-supported outcomes and report suspected harm, bias, privacy or security incidents. Reports will be handled promptly and confidentially to the extent possible, without retaliation for good-faith concerns.
Where ICARUS determines that it caused or contributed to an adverse impact, it will take proportionate steps to stop or mitigate the impact, correct affected information or outcomes where possible, communicate with affected people and enable or cooperate in appropriate remedy.
9. Roles and accountability
Board / highest governance body. Approves the policy and oversees material AI risks and significant incidents.
Chief Executive Officer. Owns implementation, assigns accountability and approves higher-risk uses unless delegated.
Chief Technology Officer. Oversees technical architecture, security, testing, monitoring and vendor controls.
Chief Learning Officer. Oversees educational quality, pedagogy, accessibility, educator guidance and learner impact.
All personnel and contractors. Use approved tools, protect data, verify outputs, complete required training and report concerns.
AI use-case owner. Maintains documentation, controls, monitoring and periodic reassessment for the assigned system.
10. Training, records and assurance
ICARUS will provide role-appropriate responsible-AI training. It will maintain an inventory of material AI systems, impact assessments, approvals, testing evidence, incidents, corrective actions and material vendor reviews. Compliance with this policy will be reviewed periodically, and lessons learned will be incorporated into product, service and operational procedures.
11. Legal, ethical and international alignment
ICARUS commits to implementing this policy consistently with applicable law and the authoritative frameworks below. Alignment does not imply certification, endorsement by any institution or that every provision applies to every ICARUS use case. Where legal or contractual requirements impose a higher standard, the higher standard applies.
European Union requirements
EU Artificial Intelligence Act. ICARUS follows the risk-based approach established by Regulation (EU) 2024/1689. In accordance with ICARUS’s role in a particular use case and the Act’s phased application, this includes identifying prohibited and high-risk practices; maintaining appropriate documentation and AI literacy; providing transparency and human oversight; and addressing accuracy, robustness, cybersecurity and post-deployment monitoring.
EU data-protection law. Where AI involves personal data, ICARUS applies the General Data Protection Regulation and other applicable privacy law, including lawfulness, fairness and transparency; purpose limitation and data minimisation; accuracy, security and retention controls; respect for individual rights; and safeguards for automated decision-making where applicable.
United Nations and UNESCO frameworks
UNESCO Recommendation on the Ethics of Artificial Intelligence (2021). ICARUS follows its human-rights-centred principles, including human dignity and agency, fairness and non-discrimination, transparency and explainability, responsibility and accountability, privacy and data governance, human oversight, sustainability, AI literacy and proportionate ethical impact assessment.
UN Guiding Principles on Business and Human Rights. ICARUS integrates a policy commitment, proportionate human-rights due diligence, prevention and mitigation of adverse impacts, and access to or cooperation in remedy where the company causes or contributes to harm.
UN Global Compact Ten Principles. ICARUS applies the principles on human rights, labour, environment and anti-corruption to the governance, development, procurement and use of AI.
UN Global Digital Compact (2024). ICARUS supports a human-centred, inclusive, open, safe and secure digital future, including respect for human rights, improved digital inclusion, responsible data governance and broader capacity to use AI safely.
How ICARUS operationalises this alignment
- Maintain an inventory and named accountable owner for each material AI use case.
- Conduct proportionate AI, human-rights, educational, privacy and security impact assessments before higher-risk deployment.
- Apply meaningful human oversight, accessible transparency and routes to question or challenge material AI-supported outcomes.
- Assess relevant AI suppliers and document data, intellectual-property, security and contractual safeguards.
- Test and monitor accuracy, bias, accessibility, robustness, misuse and material incidents throughout the system lifecycle.
- Provide role-appropriate AI literacy and responsible-use training to relevant personnel and contractors.
- Stop, correct and remediate adverse impacts where ICARUS causes or contributes to them, and cooperate appropriately where it is directly linked to harm.
Reference instruments
- Regulation (EU) 2024/1689 (Artificial Intelligence Act): https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Regulation (EU) 2016/679 (General Data Protection Regulation): https://eur-lex.europa.eu/eli/reg/2016/679/oj
- UNESCO Recommendation on the Ethics of Artificial Intelligence: https://unesdoc.unesco.org/ark:/48223/pf0000381137
- UN Guiding Principles on Business and Human Rights: https://www.ohchr.org/documents/publications/guidingprinciplesbusinesshr_en.pdf
- UN Global Compact Ten Principles: https://unglobalcompact.org/what-is-gc/mission/principles
- UN Global Digital Compact: https://www.un.org/global-digital-compact/en
12. Review and contact
The policy owner will review this policy at least annually and after any material incident, regulatory development or significant change to ICARUS AI systems. Questions and concerns should be directed through the contact or reporting channel published by ICARUS on its website.
13. Aligned with policies
- The EU AI Act and GDPR
- The UNESCO Recommendation on the Ethics of AI
- The UN Guiding Principles on Business and Human Rights
- The UN Global Compact Ten Principles
- The UN Global Digital Compact
- Practical controls covering impact assessments, human oversight, vendor review, AI literacy, monitoring and remedy