Responsible AI
Our principles for the ethical use of AI in software development
At Brainit (BRAIN INFORMATION TECHNOLOGIES d.o.o.), AI coding tools are a core part of how we build software — but always under human oversight and clear accountability. This statement summarizes the principles that govern our use of AI.
The full policy is available as a PDF: Responsible AI Policy (PDF). Questions? Contact us at hello@brainit.agency.
1. Human oversight
AI accelerates our engineers; it does not replace their judgment. Architecture decisions, code review, testing, and compliance are owned by senior developers with 10+ years of experience. Every AI-assisted output is reviewed by a human before it ships. This is disciplined, AI-augmented engineering — not autonomous "vibe coding".
2. Data governance and privacy
We handle client and personal data in accordance with the GDPR. Client code and data are used only to deliver the agreed engagement; they are not used to train public AI models. For healthcare work we follow FHIR/HL7 and HIPAA-aligned practices and integrate securely with existing HIS/EMR systems. For fintech we build to PSD2 and Open Banking standards.
3. Transparency
We are open with clients about where and how AI coding tools (such as Claude Code, GitHub Copilot, and Cursor) are used in our workflow, and about the human review that accompanies them. We do not present AI-generated output as if it were free of human responsibility.
4. Accountability
Brainit (BRAIN INFORMATION TECHNOLOGIES d.o.o.) remains accountable for the software we deliver, regardless of the tools used to build it. Named senior engineers are responsible for the quality, security, and compliance of every project.
5. Security
We apply appropriate technical and organizational measures to protect code and data against unauthorized access, alteration, disclosure, or destruction, and we review these measures regularly. Cybersecurity practices are documented in our internal cybersecurity policy.
6. Alignment with the EU AI Act and GDPR
Our responsible-AI practices are designed to align with the principles of the EU AI Act (human oversight, transparency, risk management) and the GDPR (lawful, fair, and secure processing of personal data). We keep our approach up to date as these frameworks evolve.