Human accountability and oversight
A named individual is accountable for every output that AI assists. Artificial intelligence supports professional judgement; it does not replace it, and no client deliverable is issued without human review.
Firm policy
MRC advises organisations on AI governance and the EU AI Act. We hold our own use of artificial intelligence to the standard we set for the organisations we advise. These are the principles that govern it.
A named individual is accountable for every output that AI assists. Artificial intelligence supports professional judgement; it does not replace it, and no client deliverable is issued without human review.
We are open about where AI materially assists our work. Analytical outputs produced with AI assistance are identified as such, to clients and, where relevant, to the authorities that review them.
AI-assisted analysis is checked for bias, error, and robustness before it informs a decision. The limitations of a model are treated as part of the analysis rather than an afterthought.
Client, safety, and personal data are never entered into consumer or open AI tools. We use only approved tools under appropriate contractual and security terms, consistent with the UK and EU GDPR.
We maintain a list of approved AI tools and the terms on which each may be used. Personal data, client-confidential material, and regulated safety data are handled only within approved, contractually-governed environments. Where a tool is not approved, or where the data is sensitive, the matter is escalated before any use.
Where AI assists our work, it does so under these principles. Our safety-data analytics, for example, are developed in line with the EU AI Act and applicable data-protection law, keeping the models that support safety decisions governed and defensible. In every case, a qualified adviser remains responsible for the result.
These principles are owned by the firm's principal, reviewed at least annually, and reaffirmed by anyone acting on the firm's behalf. Last reviewed September 2026.
The principles above are the standard we apply to ourselves. We put the same governance in place for the organisations we advise, mapped to the EU AI Act, data protection law, and recognised standards.