Policy / Public document

Responsible AI Policy

The principles and operational practices governing how Rome develops, deploys, and operates AI systems.

We exist to bring AI to the operations that can’t afford to get it wrong — AI that connects your systems and your people. We built an entirely new technology stack to give your teams the controls they need to deploy it safely, reliably, and responsibly.

1. Introduction

Rome Intelligent Systems, Inc. (“Rome AI”) builds AI-powered agents that automate routine supply-chain coordination work, such as supplier follow-up, delivery confirmation, deviation handling, and planning visibility, so that the people responsible for those processes can focus on work that truly requires human judgement.

This Responsible AI Policy sets out the principles, commitments, and operational practices that govern how Rome AI develops, deploys, and operates artificial intelligence systems. It applies to all AI systems incorporated into, or made available through, the Rome AI platform, whether developed by Rome AI or provided by third-party AI providers.

2. Purpose

This policy serves two purposes. Internally, it establishes the governance framework that all Rome AI personnel must follow when building, testing, deploying, and operating AI systems. Externally, it provides clients, regulators, and partners with a clear statement of Rome AI’s responsible AI commitments that can be referenced in commercial agreements in lieu of bespoke contractual AI-principles language.

3. Scope and Applicability

This policy applies to all employees, contractors, and third-party representatives of Rome AI involved in the design, development, deployment, operation, or governance of AI systems. It covers the full lifecycle: research and development, pre-deployment testing, production operation, monitoring, and decommissioning.

3.1 What Rome AI Does

Rome AI provides agentic AI for enterprise operations, with a current focus on supply-chain coordination. Our AI systems interact with external parties on behalf of our clients, process structured and unstructured data from enterprise and communication systems, and surface recommendations and actions to authorized users. The systems operate in a business-to-business context and are designed to augment human operators rather than replace their judgement on consequential decisions.

3.2 What Rome AI Does Not Do

Rome AI systems do not make automated decisions that produce legal or similarly significant effects on individuals. They do not process biometric data, perform social scoring, or engage in emotion inference. They are not classified as high-risk AI systems or general-purpose AI models under the EU AI Act (Regulation (EU) 2024/1689). Obligations specific to those categories, such as CE marking, conformity assessment, and model cards for GPAI, do not apply. Clients are responsible for ensuring that their use of Rome AI’s platform remains consistent with the intended use cases and risk classification. If a client’s deployment configuration or use-case scope materially changes, Rome AI is available to consult on any implications for risk classification and applicable obligations.

4. Core Principles

Rome AI’s responsible AI practices are grounded in six principles. Each principle is operationalized through specific commitments described in Sections 5 through 10 of this policy.

4.1 Human Control

AI systems augment human decision-making. They do not replace it. Clients retain accountability for business outcomes. Every deployment provides mechanisms for human oversight, intervention, and override.

4.2 Transparency

Clients can understand what our AI systems do, how they reach their outputs, and what data they use. Agent actions are logged with full provenance, enabling traceability and auditability.

4.3 Safety and Reliability

AI systems are tested before deployment, including against adversarial and edge-case scenarios. Guardrails prevent actions outside defined boundaries. When the system cannot operate safely, it escalates to a human.

4.4 Data Stewardship

Client data is the client’s data. We segregate it, protect it, and do not use it to train models for the benefit of other clients. Third-party AI providers are held to the same standard.

4.5 Security

AI environments are secured to the same standard as all critical infrastructure under Rome AI’s SOC 2-audited security framework. AI-specific risks such as prompt injection and unauthorized tool use are addressed through dedicated controls.

4.6 Accountability

Roles, responsibilities, and governance cadences are defined for every deployment. Rome AI takes responsibility for the safe operation of its platform. Clients retain accountability for business decisions and the data they provide.

5. Human Oversight and Control

5.1 Human-in-the-Loop

Human oversight is a platform capability, active in every deployment. It operates through two mechanisms:

Proactive escalation. Actions exceeding defined impact thresholds, or triggering guardrails, are escalated for human review before the agent proceeds.

Reactive override. Authorized users can review, approve, modify, or reject any agent-proposed action, and can suspend agent activity.

5.2 Configurable Escalation Thresholds

Escalation thresholds are configured per deployment during client onboarding and documented in the engagement’s deployment documentation. Threshold categories include guardrail triggers, confidence levels, impact classifications, and anomaly detection rules. Thresholds are reviewed and adjusted as part of ongoing governance.

5.3 Agentic AI Boundaries

Agentic AI operates only within the scope of permissions, tools, systems, and data sources expressly authorized by the client. Capabilities not within the authorized scope are denied by default. Rome AI implements least-privilege access controls and runtime guardrails to prevent agents from acting outside their defined boundaries.

5.4 Kill Switch

Rome AI provides clients with a kill switch: the ability to suspend agent activity at the individual-case level and globally.

6. Testing and Evaluation

6.1 Pre-Deployment Testing

No AI system is deployed to a client production environment without documented testing appropriate to the risk level of the use case. Rome AI’s testing methodology includes unit testing of core platform components and integration testing that exercises client-specific configurations against representative scenarios.

6.2 Adversarial and Edge-Case Testing

Rome AI maintains inventories of adversarial and edge-case scenarios relevant to each deployment. These are defined during client onboarding based on use-case-specific risk profiles and expanded over time as new scenarios are identified through production monitoring and user feedback. Adversarial scenarios are evaluated as part of the release cycle and must pass before any release is promoted to production.

6.3 Release Gating

Releases to client production environments follow a defined cadence and are gated on exceeding accuracy and safety thresholds. The specific evaluation methodology and cadence are documented per engagement.

6.4 Performance Metrics

Rome AI tracks system performance both pre-release, through automated evaluation suites, and in production, through user feedback signals such as human-in-the-loop approval rates and escalation patterns.

7. Data Stewardship

7.1 No Cross-Client Training

Rome AI does not use client data, AI outputs derived from client data, prompts, queries, inputs, embeddings, or vectors derived from client data to train, fine-tune, or improve any AI system for the benefit of any third party. Any model training or fine-tuning using client data is performed only within a client-dedicated, segregated environment and solely to create or improve models intended for that client’s use. Rome AI may use aggregated, anonymized, or de-identified data for improving its platform and services, provided that such data does not identify any client or individual and cannot reasonably be used to do so.

7.2 Client Data Segregation

Each client is provisioned an isolated environment. Client data is logically and, where applicable, infrastructure-level segregated from other clients’ data and from any data used for model development. Rome AI maintains technical and organizational measures designed to prevent commingling.

7.3 Third-Party AI Provider Controls

All third-party AI providers used in the delivery of Rome AI’s services are subject to contractual obligations at least as protective as Rome AI’s own commitments. Third-party AI provider services are configured using zero-data-retention or no-training enterprise modes.

7.4 Data Minimization and Retention

Client data is retained only for the period necessary to perform the contracted services. Upon termination or expiration of the engagement, client data is securely deleted in accordance with the applicable data processing agreement.

8. Transparency and Explainability

8.1 Audit Trail

Significant agent actions, including outbound communications, escalations, status changes, and classification decisions, are logged with a timestamp, case or order reference, the classification applied, and the outcome. Audit logs are retained in accordance with client-specific and regulatory retention requirements.

8.2 Traceability

Model decisions are logged with provenance to the model version and source data used, enabling traceability and auditability. For generative models, reasoning traces are captured as part of output logging.

8.3 AI-Generated Content Labeling

Rome AI ensures that AI-generated outputs are identifiable as AI-generated where and to the extent required by applicable law, including the transparency obligations of the EU AI Act.

8.4 Subprocessor Disclosure

Rome AI maintains a list of subprocessors used in connection with AI systems, disclosed to clients in accordance with the applicable data processing agreement and updated upon any material change.

9. Security

9.1 Enterprise Security Posture

AI environments are secured as part of Rome AI’s enterprise security framework, which is independently audited. Controls cover access management, data encryption at rest and in transit, network security, vulnerability management, and incident response.

9.2 AI-Specific Security Controls

In addition to enterprise security controls, Rome AI implements measures specific to AI systems, including guardrails against prompt injection and jailbreak attempts, runtime boundary enforcement, tenant isolation, and monitoring for anomalous AI system behavior.

9.3 Incident Response

AI-related security incidents are managed under Rome AI’s documented incident management process, which includes classification, containment, investigation, remediation, and lessons-learned review. Clients are notified in accordance with the applicable service agreement and data processing agreement.

10. Governance and Accountability

10.1 Roles and Responsibilities

For each client deployment, Rome AI documents roles, responsibilities, and governance cadences as part of the engagement’s statement of work. Rome AI is responsible and accountable for the safe development, deployment, and operation of its platform. Clients retain accountability for business decisions, the data they provide, and the configuration choices they make. Automation does not transfer business accountability.

10.2 Deployment Documentation

Each client deployment is accompanied by documentation that covers the use cases, intended users, operational boundaries, known limitations, human-in-the-loop configuration, risk assessment, and relevant metric definitions. This documentation is established during onboarding and maintained throughout the engagement.

10.3 Risk Assessment

Rome AI conducts risk assessments in accordance with its Risk Assessment Policy, using a recognized risk assessment framework. For AI deployments, risk assessment covers data quality, model accuracy and reliability, scope of automation, downstream impact, and unintended consequences. Identified risks are recorded in a risk register, assigned owners, and tracked for mitigation.

10.4 Ongoing Governance

Governance operates through a defined cadence agreed with each client. Reviews cover system performance, exceptions, tuning actions, and any changes to the risk profile.

11. Regulatory Compliance

Rome AI develops, deploys, and operates its AI systems in compliance with applicable law, including, where applicable, the EU AI Act (Regulation (EU) 2024/1689), the Colorado AI Act, and any successor or analogous legislation applicable to Rome AI’s provision of its platform.

Rome AI’s current assessment is that its AI systems are not classified as high-risk AI systems under the EU AI Act, as they do not fall within the categories enumerated in Annex III of the regulation. If a client’s deployment or use-case scope changes the applicable classification, Rome AI will work with the client to assess any additional obligations.

12. Prohibited Uses

Rome AI does not use, and its AI systems are not designed to be used to:

(a) make fully automated decisions that produce legal or similarly significant effects on individuals without meaningful human review;

(b) engage in social scoring, biometric categorization, or emotion inference prohibited under applicable laws;

(c) generate deceptive content or deepfakes;

(d) perform any activity classified as a prohibited AI practice under the EU AI Act;

(e) use client data to train or improve AI systems for the benefit of any third party, except where expressly authorized in writing by the client; or

(f) monitor, evaluate, or assess the performance of individual employees. Operational metrics generated by Rome AI’s platform, such as approval rates, escalation volumes, and response patterns, reflect supply-chain process health rather than individual worker productivity or conduct. Rome AI does not develop features intended for use in employee evaluation, disciplinary proceedings, or workplace surveillance.

13. Fairness

Rome AI is committed to ensuring that its AI systems operate fairly and without unlawful discrimination. Although Rome AI’s current use cases, coordinating business-to-business supply-chain processes, do not fall within the categories of AI systems subject to fairness and bias-mitigation obligations under the EU AI Act or analogous legislation (which target systems that make or materially inform decisions about natural persons), Rome AI addresses fairness as a matter of principle through the design of its systems.

Rome AI’s AI systems perform mathematical and probabilistic operations on a defined set of supply-chain inputs: material numbers, quantities, dates, lead times, supplier organization identifiers, order references, and structured text. This input set does not include race, ethnicity, gender, age, or any other demographic or protected-class features. By operating exclusively on commercial and logistics data, the system is structurally insulated from the categories of bias risk that arise when AI systems process personal or demographic information. Rome AI maintains this discipline through schema-level controls on the data its systems ingest.

14. Policy Maintenance

This policy is reviewed at least annually, or when there is a material change to Rome AI’s AI systems, business operations, or the regulatory environment. Reviews, revisions, and approvals are captured internally. The version number and date on this document reflect the current effective version.

Partnership inquiry

See Rome in action.

Tell us a little about your operation and we'll follow up to arrange the right conversation.

By submitting, you agree that Rome may contact you about this request. See our Privacy Policy.