Customer responsibility
The organization configuring a workspace is responsible for authorising users, defining roles and permissions, deciding what data may be entered, and ensuring its use complies with law and third-party commitments.
Connecting a model or agent does not transfer that responsibility. The person enabling it must define its purpose, context, tools, boundaries, oversight, and withdrawal process.
Illegal or harmful use
BIKLABS may not be used to facilitate crime, fraud, scams, deceptive impersonation, harassment, child exploitation, violence, unlawful discrimination, deliberate rights infringement, or distribution of illegal content.
Generating or distributing malware, obtaining credentials without authorisation, bypassing access controls, testing systems without permission, or intentionally degrading a service is also prohibited.
Privacy and data
Organizations must only enter data they are authorised to process. Agents may not be used to extract, correlate, or monitor personal data without a lawful basis, or to re-identify, covertly profile, or disclose confidential information to unauthorised recipients.
Credentials, secrets, and tokens must be stored using the intended mechanisms, limited to the necessary scope, and revoked when no longer required.
High-impact decisions
BIKLABS must not be used by itself to make decisions with legal or similarly significant effects in employment, credit, insurance, education, essential services, healthcare, justice, or fundamental rights.
Where AI supports a regulated activity, the organization must provide competent professionals, appropriate transparency, a route to review, and meaningful human involvement proportionate to risk.
Agents, tools, and gates
An agent may act only within its assigned role and capabilities. It must not attempt to expand permissions, bypass a gate, hide an action, alter evidence, or reuse credentials or context outside its scope.
Irreversible, external, or sensitive operations should require confirmation or review where risk warrants it. A technical gate does not remove the duty to design a responsible process.
Accuracy and communication
Model and agent outputs may be inaccurate, incomplete, or outdated. They must not be presented as verified facts, professional advice, or human decisions when they are not.
Organizations must disclose AI involvement where required by law, context, or a recipient's reasonable expectations, and retain enough traceability to review what happened.
Service integrity
The service may not be resold or sublicensed outside the agreement, protected components may not be copied, reverse engineering is prohibited except where an unwaivable legal right applies, usage limits may not be bypassed, and the platform may not be systematically extracted to build a competing service.
Enforcement and reporting
We may limit, suspend, or remove access where reasonably necessary to stop a risk, investigate a breach, or comply with law. Where possible, we consider context, severity, repetition, and the opportunity to remediate. Report abusive use to admin@biklabs.ai.