Security and data protection
Responsible use of AI
How Telonic's agents stay honest with your customers, answer from your sources, leave decisions that belong to people with your team, and remain open to review.
On this page
- The agent says what it is
- Answers come from your approved sources
- Decisions that belong to people stay with your team
- People oversee the agent's work
- Customers who may be vulnerable
- Every customer is answered to the same standard
- Testing before release
- Every action can be explained
- Your customers' data
- When a customer disagrees with an outcome
- Principles in the UAE and Saudi Arabia
- In practice
- What your team controls
- Related
When an agent speaks for your business, your customers should be able to trust what it says, know what they are dealing with, and reach a person when they want one. Your risk and compliance teams should be able to see why it did what it did. Where it can, Telonic builds these commitments into the structure of the agent, such as which actions are connected to it, and tests the rest before every release. This page sets out each one, how it works, and what your team controls.
The agent says what it is
The agent tells customers it is an AI agent, and offers them a person. A customer who asks to speak to someone is handed to your team under the handover rules you set, with the conversation so far, so they do not have to start again. A customer who knows what they are talking to, and got their answer, is far better served than one who later feels misled.
Answers come from your approved sources
Anything that could create an obligation for you is taken from your systems and approved documents rather than generated by the language model (the AI component that interprets the conversation and composes the reply). Prices, policy terms, entitlements, dates and commitments are retrieved from your systems and approved documents during the conversation, and amounts and dates are inserted directly from your system's record rather than retyped by the model. If the information is not in your sources, the agent says so and offers a person.
The language model decides how retrieved information is expressed: the wording, the order and whether to ask a clarifying question first. Topics you place out of scope, such as legal or investment advice, are declined and routed to a person, including when a question is rephrased. Scope is tested before every release. See How an agent works.
Decisions that belong to people stay with your team
Some decisions stay with your people in every deployment. In insurance, the agent does not assess liability, set a settlement amount, or approve or decline a claim. The actions that would make those decisions are not connected to the agent at all, so it has no way to make them, however a customer phrases the request.
Where the agent can act, it acts within values your rules permit. Actions you mark as sensitive are prepared by the agent and held until a person on your team approves them. See Decision boundaries.
People oversee the agent's work
Your team sets when the agent hands a conversation to a person. Escalation combines rules set for each type of question with a confidence threshold (a measure of how sure the model is of an answer), measured for the model before deployment, below which a consequential answer goes to a person. The person taking over receives a brief of the conversation, so the customer does not repeat themselves. See Human oversight in practice and Escalation rules.
Customers who may be vulnerable
Vulnerable customer routing is configured during implementation. The agent recognises signals that a customer may be vulnerable or distressed, such as a mention of bereavement, serious illness or financial difficulty, and routes them to a person with the full conversation. Your team decides which signals trigger the handover and who receives it.
Every customer is answered to the same standard
A customer's answer should not depend on the time of day, the channel or who happened to pick up. The agent answers every customer from the same sources, under the same rules, in Arabic, English and every other language it works in. Eligibility, prices and entitlements come from your systems and your rules, not from the agent's judgement of the customer, so the facts and rules applied do not depend on who asks or when.
Testing before release
Before release, and before any change goes live, the agent is tested against conversations drawn from your industry, scored against what a correct outcome means there. Tests include the requests that should be declined or handed over, as well as those the agent should handle. A new model is adopted only when it performs at least as well on those tests as the one it replaces. See Testing before every release.
Every action can be explained
Every request, lookup, decision and handover is logged, with the sources used, the rule or trigger that applied, and the agent's stated reason. When a customer, your auditors or a regulator asks what the agent did and why, you can show them. See Audit trail and decision records.
Your customers' data
Your customers' data is used only to provide your service. Contracts with every model provider prohibit using your data to train or improve their models, and zero data retention arrangements are used wherever a provider offers them.
Personal information is redacted before data leaves your deployment for anywhere other than your own systems and your own customers. All processing runs in the region you choose, unless you explicitly choose a language model provider outside it. See Personal information redaction.
When a customer disagrees with an outcome
A customer can ask for a person at any point in a conversation. Because the decisions that affect them are made by your rules and your people, a customer who disagrees with an outcome raises it through your own complaints and review process, as they would today. Your team has the full conversation, the sources used and the agent's stated reason to review it against.
Principles in the UAE and Saudi Arabia
Government bodies in the UAE and Saudi Arabia have published principles for the ethical use of AI, covering themes such as transparency, accountability, fairness and human oversight. This page describes how the product works, so that your own teams can assess it against those principles and any policy of your own.
In practice
Wadi Assurance, an insurer, deploys an agent on its claims line.
- A policyholder, Huda, calls about her late husband's motor claim. The agent introduces itself as Wadi Assurance's AI agent and says she can ask for a person.
- She asks for the claim's status. The agent gives it from the claims system, with the name of the assessor handling it.
- She mentions her husband's death. The vulnerability signal the insurer configured fires, and the agent routes her to a senior handler with the full conversation.
- The senior handler takes over without asking Huda to repeat anything.
- Weeks later, the compliance team reviews the conversation. The log shows the source of the status, the signal that triggered the handover, and the time it happened.
What your team controls
- The sources the agent answers from, and the topics it declines.
- The decisions that stay with your team, and the actions that need approval.
- The escalation rules, and the signals that route a customer to a person.
- Who receives each handover.