Artificial intelligence, in the forms this policy governs, produces output by predicting likely content from patterns in the data it was trained on. Unless it is connected to a live source, it is not looking anything up, and it has no way to check what it produces against a source of truth.
Fluency is not accuracy. A wrong answer arrives sounding exactly like a right one, and the system gives no signal that anything is off. This is how these tools behave normally. It is not a fault or a sign that something has gone wrong.
Output quality follows input quality. General instructions produce general output. Specific instructions, real context, and a clear statement of what correct looks like produce something usable.
The Human Ownership Standard, also referred to as No AI Slop, is the standard this policy applies to every AI-assisted output. Artificial intelligence is a tool, and the individual who uses it is accountable for the result.
Any output produced with AI assistance that carries your name, your team's name, or the Company's name belongs to you, not to the AI system. Output that has not been read, understood, and confirmed accurate is not ready for use.
Ownership of AI-assisted work requires all five of the following:
- Read the output in full, not a summary or excerpt.
- Independently verify material factual claims.
- Edit the output to reflect the Company's voice and the facts as known.
- Remove anything that cannot be verified or is not yours to stand behind.
- Be able to defend the output if questioned: understanding what it does and why, verifying it behaves as intended, and accepting accountability for the outcome.
Covered people. All employees of the Company in every department, including leadership. All contractors, consultants, temporary workers, and agents performing work on behalf of the Company. All third parties who access organizational systems or data while providing services.
Covered systems. Generative AI producing text, images, code, audio, or video. Agentic AI taking autonomous actions. Analytical and decision-support AI embedded in software platforms. AI features within approved applications. Custom or internally developed models.
Six principles govern any situation the policy does not explicitly address:
| Principle | What it requires |
|---|---|
| Human ownership | Every AI output that represents or affects the organization has a named human owner before use. |
| Least privilege | AI gets the minimum access needed for the specific approved task. |
| Transparency | Disclose AI use where the policy, a contract, a regulation, or professional expectation requires it. |
| Proportionate risk | Controls match risk. Low-risk use gets light oversight; high-risk use gets rigorous review. |
| Continuous oversight | Approval today is not approval forever. Tools and access are reviewed on a set cadence. |
| No silent agents | Autonomous action requires documented authorization, defined scope, logging, and human interrupt. |
An unapproved AI tool may not be used for organizational work. This applies regardless of the tool's cost, general availability, or how low the risk appears.
AI features newly switched on inside software the Company already approved require separate review. Approving the software was not approving the feature.
Approval is per use case, not per tool. Being cleared to draft marketing copy in a tool is not clearance to process customer financial data in that same tool. A new use case requires a new intake submission.
Check the registry before using any AI tool for organizational work. Any employee may submit a tool for vetting through the AI Tool Intake Form, which routes to the CISO for a risk-tier determination.
| Risk tier | Decision timeline | Note |
|---|---|---|
| Tier 1 | Within 5 business days | Decisions are issued in writing. |
| Tier 2 | Within 15 business days | Approved tools reach the registry within 5 business days. |
| Tier 3 | Within 30 business days | Agentic capability is automatically Tier 3. |
- An AI tool operating under your credentials cannot reach systems, files, or data you are not personally authorized to access.
- Granting an AI system elevated permissions to work around a workflow inconvenience is a policy violation.
- When your access changes through promotion, role change, or departure, your AI access is adjusted at the same time.
- Shared or service-account AI access is prohibited without written CISO approval.
Default AI access by system. Variation from these defaults requires written approval from the CISO.
| System | Default access | Key condition |
|---|---|---|
| FOS | Read + draft | No automatic release of flights. A human reviews and executes all scheduling and dispatch actions. |
| Financial systems | Read + draft | Write access requires President and CFO written approval. No AI-initiated transactions. |
| HR and people systems | Read only | AI may not modify compensation, titles, employment status, or performance records. |
| Code repositories | AI-assisted | Human commit required. No autonomous merge or deploy. |
| Email and messaging | Draft only | No automatic send. Sending requires explicit human action. |
| External-facing content | Draft only | Full human review and approval before publication. |
| Customer and passenger data | Scoped read | Limited to approved fields. Governed by data classification and TSA SSI handling rules. |
| Identity and access management | Read only | AI may not provision, modify, or revoke user access under any circumstances. |
| Payment and transaction systems | Prohibited | No access without explicit AI Steering Committee approval. |
Use AI freely in your personal life, on personal devices and personal accounts, for any purpose unrelated to Company business. No approval, oversight, or disclosure is required. That freedom ends where personal use touches organizational systems, data, or work product.
- Nothing unapproved on Company equipment. If it is not in the Approved Tool Registry, do not install it, sign into it, or open it on a Company laptop, phone, account, or network. This holds even when what you are doing is personal.
- No Company data in a personal account. Client information, passenger information, anything confidential: it does not go into your own AI account or into an unapproved tool. Your kitchen table counts the same as your desk.
- No Company work on a personal tool. Not drafts, not analysis, not code. Moving the finished output into an approved tool afterward does not fix it, because the data already left.
- Personal output is not Company work product. Something you made on your own account for your own purposes does not get submitted, forwarded, or folded into a Company deliverable.
If you are unsure whether a specific use qualifies as personal, treat it as organizational and apply the approval requirement.
Different output types carry different minimum review standards. These supplement, and do not replace, the Human Ownership Standard.
| Output type | Minimum review |
|---|---|
| External communications | Full read and edit by the named sender, who executes the send personally. |
| Legal or contractual documents | Full review plus legal sign-off. Attorney review for anything legally binding. |
| Financial analyses and reports | Full review plus numerical verification, with written attestation on file. |
| Code and technical artifacts | Tested before use, by a person who can confirm it does what it is supposed to do. No AI-driven deploy, and nothing goes live without a person choosing to put it there. |
| Regulatory and compliance filings | Full review plus sign-off by the accountable manager for that filing. |
| Presentations and board materials | Full review by the presenter, who is accountable for every claim. |
Disclosure is required for external documents submitted to regulators, courts, or government agencies including the FAA and TSA; client-facing deliverables where the engagement agreement specifies it; published content where platform or industry rules require it; and internal communications where a material business decision rests on AI-generated analysis.
Reporting. Submit a safety report, the same way you would for any other safety event. Anonymous and confidential options are both available.
AI-related incidents fall into three categories:
| Report this | What happens |
|---|---|
| Shadow AI use, yours or a colleague's | Triaged by the CISO. During the amnesty window, no disciplinary consequence. |
| Suspected data exposure through an AI tool | Category A. Triaged by the CISO and Director of Safety within 1 business day. |
| A hallucination that drove a material decision | Category B. Same channel and triage timeline. |
| An AI agent acting outside its authorized scope | Category C. Addressed whether or not harm resulted. |
| A deepfake, AI fraud attempt, or AI phishing | Triaged by the CISO. External Legal engaged where there is legal exposure. |
Knowledge Check
Complete all eight sections above to unlock the assessment
Complete all 8 content sections to unlock the assessment.