MCMMCM DocsEngineering (Internal)
User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.

MCM-60 — AI Assistant Data Handling & Human-in-the-Loop Governance

No-training terms, disclosure, and a mandatory human approval step for every AI-suggested action.

MCM-60 — AI Assistant Data Handling & Human-in-the-Loop Governance

← Back to Legal & Compliance Readiness overview

As Legal Counsel,
I want documented data-handling terms and human-in-the-loop safeguards for the AI assistant,
so that customer data sent to any external model provider is contractually protected, and no AI-suggested action is applied to customer infrastructure without explicit human approval.

Acceptance Criteria

  • A no-training / data-use clause is in place with any external model provider used by the AI assistant, confirming customer prompts and data are not used to train a shared model.
  • Customers are told, before first use, what categories of their data (e.g., discovered resource metadata, security findings, draft policy content) may be included in a prompt sent to the AI assistant.
  • Every AI-suggested policy, remediation, or configuration change requires explicit human approval before being applied to customer infrastructure — the assistant never executes a change autonomously, consistent with how policy drafting already works today (see MCM-48).
  • An audit trail records what the AI assistant suggested versus what a human approved and applied, retrievable per customer on request.
  • A documented AI risk classification (e.g., against the EU AI Act or an equivalent internal framework) is completed and is reviewed again whenever AI-assisted capability expands beyond policy drafting.

Technical Design

The disclosure and audit-trail requirements attach to the same draft-then-approve pattern the AI assistant already follows for policy creation: a suggestion is generated, presented to the Admin, and only the Admin's own action in the existing creation flow applies it. This story adds the legal scaffolding around that flow — disclosed data categories, no-training terms with the model provider, and a retrievable record of suggestion versus human decision — without changing the flow itself.

On this page