AI policy
How Poku uses AI
Last reviewed: [DATE] · Responsible person: the owner
We ask the businesses we work with about their AI posture — so it's only fair we publish ours. This page took one afternoon. It's the same exercise we'd walk any small business through, and you're welcome to copy the structure.
Our AI inventory
Every AI tool Poku uses, what it's for, and what it never touches.
Claude (Anthropic)
Minimal risk · internal use- What we use it for
- Drafting documents and marketing copy, writing code for our own internal tooling, research support.
- What it never sees
- Client-identifiable findings, credentials, or vulnerability details — see the client-data rule below.
ChatGPT (OpenAI)
Minimal risk · internal use- What we use it for
- Deep-research tasks on public-source material.
- What it never sees
- Same rule: public-source inputs only.
Our client-data rule: no client-identifiable security findings, credentials, or report contents go into third-party AI tools. If AI assistance would ever genuinely help on client material, we ask the client first, in writing — the same consent discipline we apply to security testing itself.
Do we ship any AI to customers?
No. Poku has no customer-facing chatbot, assistant, or AI feature. That means the EU AI Act's Article 50 transparency rules (applying from 2 August 2026 — AI that interacts with people must disclose it's AI; synthetic media must be labelled) don't currently bite us directly.
Our commitment: if we ever do ship one, it will say it's AI from day one — not from the deadline.
Transparency on our own content
Where a published piece — a newsletter issue, a guide, a page like this — is materially AI-assisted, we say so with a plain note: “supported by AI, checked by a human.” We don't over-label: a human-written piece that merely used AI for background research isn't the same thing, and pretending otherwise would make the label meaningless.
AI literacy
The Act's AI-literacy duty (in force since 2 February 2025) asks that people using AI in a business understand what the tools can and can't do. For a one-person business that's simple to evidence: the owner uses these tools daily, tracks their known failure modes (hallucinated facts, fabricated citations, insecure generated code), and every AI-assisted output is human-checked before it reaches a client or the public. Nothing AI-generated goes out on autopilot.
When we'll review this
- When we adopt or drop an AI tool;
- when a new Act obligation becomes applicable — next relevant date for businesses like ours: 2 August 2026 (Article 50);
- otherwise at least every six months.
The honest small print
This is our posture, documented — not a certification, and Poku is not an AI Act auditor or compliance consultancy. If you'd like to run the same one-afternoon exercise for your own business, email hello@poku.ie and we'll send you the blank template. For the regulation itself, go to the primary sources: the European Commission's AI Act pages and the text on EUR-Lex — not second-hand summaries (including this one).
For what data this website collects generally, see the privacy notice.
EU AI Act dates referenced above, from the European Commission's published timeline: entry into force 1 Aug 2024 · prohibited practices + AI literacy 2 Feb 2025 · general-purpose model obligations 2 Aug 2025 · Article 50 transparency 2 Aug 2026.
This page: supported by AI, checked by a human.