AI Transparency Statement
Which AI systems are involved, what they decide, what they do not decide, and what is never used for training.
- Applies to
- Everyone
- Last updated
- 1 September 2026
- Questions
- legal@oakhive.ai
OakHive is an AI product that talks to employees about their work. This document says which models are involved, what they are allowed to do, and — more usefully — what they are structurally prevented from doing.
It is written to satisfy the transparency duties in Article 50 of the EU AI Act and the equivalent expectations elsewhere, and to give a works council or a data protection officer something concrete to interrogate.
1Which AI systems are involved
| Component | What it does | Where it runs |
|---|---|---|
| Large language model | Conducts the conversation — decides the next question from what has been said — and afterwards writes the summaries, the handover guide and the coverage record. | Microsoft Azure OpenAI, EU West Europe |
| Speech recognition | Turns speech into text as the conversation runs. | Azure Speech and ElevenLabs |
| Speech synthesis | Gives the interviewer a voice. | Azure Speech and ElevenLabs |
| Avatar generation | Generates an animated face for the interviewer. Optional, and currently restricted to our own test accounts. | Anam |
| Embedding model | Turns text into vectors so that knowledge can be retrieved by meaning rather than by keyword. | Microsoft Azure OpenAI, EU West Europe |
The provider-by-provider detail, including retention, is on the Subprocessors page.
2People are told they are talking to a machine
- Participants are told before the interview begins that they are speaking to an AI interviewer. It is stated on the screen they read before they start, and it is recorded on the interview record which version of that text they were shown.
- The interviewer’s voice is synthetic. It is not a recording of a person and does not imitate any identifiable individual.
- Where the animated interviewer is used, the face is generated. It is not a real person, not a likeness of one, and the Interview Privacy Notice says so in terms.
- A customer is contractually prohibited from representing to a participant that they are speaking to a human being — clause 7.4 of the Subscription Agreement.
3What the AI does not decide
The system produces no decision, score, rating or recommendation about a person. Not a performance judgement, not a flight-risk score, not a sentiment rating, not a ranking against colleagues. This is a design constraint, not a setting.
- There is no scoring model, and no field on any record that holds a score about a person.
- The artefacts describe work — projects, risks, dependencies, what a successor needs to know. They are not an assessment of the person who described it.
- Customers are contractually prohibited from using the output to make or materially inform a decision with legal or similarly significant effects — dismissal, discipline, promotion, pay, or the content of a reference.
- Declining an interview is recorded as a decline and nothing else. No reason is requested and none is stored.
4Emotion, and the one safety signal that exists
The system does not infer emotional state, and no emotion, sentiment or stress signal is produced, stored or reported. There is exactly one exception, it exists for safety, and it is described here in full rather than left to be discovered.
The crisis safeguard
An interview about leaving a job can occasionally touch something serious. If a participant says something indicating self-harm, suicide or intent to harm another person, the system stops interviewing. It sets aside the topic, responds supportively, and surfaces the support contacts the employer has configured. The person outranks the interview.
Two mechanisms sit behind that, and they are different in kind:
- A deterministic phrase recogniser. A fixed list of explicit statements — literally, the words a person uses when they say this. It is pattern matching, not inference: it does not read tone, does not read voice, does not model mood, and cannot conclude anything about someone who has not said one of those things outright. It is tuned deliberately to fire rather than to be precise, because the cost of missing this is not symmetrical with the cost of an awkward moment.
- The model’s own response. The language model is instructed to respond to acute distress with support rather than with the next question, and it marks such a reply internally so the system can react.
What is recorded, and who sees it
When this happens, the interview record stores that it happened — a tier and a timestamp — and never what was said. The flag is visible to the manager and HR only. It is not shown to a viewer, never reaches the successor’s handover guide, and is not added to the searchable archive.
We are not going to pretend this is a neutral piece of metadata. A record that a named employee had a crisis moment is sensitive by any measure, and may amount to data concerning health. It exists because a real interview in August 2026 reached that point and the product had no deterministic way to respond. The design choices — that and not what, manager and HR only, never indexed, never in the handover — are what we think the responsible version of this looks like. An employer deploying OakHive should make its own assessment, tell its people, and make sure the support contacts it configures are real ones.
Article 5(1)(f) of the EU AI Act prohibits AI systems that infer the emotions of a person in the workplace, subject to an exception for medical or safety reasons. Our position is that a fixed phrase recogniser is not an inference system at all, and that a safeguard against self-harm falls squarely within the safety exception. That position is one we have reasoned about rather than assumed, and we will say so plainly to any customer or regulator who asks.
5Training
- Customer content is never used to train a model. Not ours, not a provider’s. Interview transcripts, summaries and handover documents are not training data, are not fine-tuning data, and are not evaluation data.
- The models used are general-purpose models supplied by the providers named in section 1. We do not train our own.
- The interview behaviour is shaped by prompts and by deterministic rules in our own code, not by learning from customer conversations.
- Improvements come from reading our own aggregate operational metrics and from testing against material we generate ourselves, not from mining customer interviews.
6Accuracy, and how we handle being wrong
A language model summarising a conversation can be wrong. It can miss something, misread what someone meant, or state something with more confidence than the transcript supports. That is a property of the technology, and we would rather say it here than bury it in a warranty disclaimer.
What we do about it:
- Artefacts are generated from the transcript, and the transcript is kept, so anything in a summary can be checked against what was actually said.
- Where the system produces a recap of an earlier part of a conversation, that recap is checked mechanically against the transcript before it is spoken, and a deterministic fallback is used if it does not hold up. Grounding is a check, not a hope.
- An interview too thin to support a meaningful artefact is marked as such and produces an honest notice, rather than a confident-sounding document built from very little.
- Each generated artefact is produced independently, so one failure does not silently degrade the rest.
- Every interview record stores which version of the prompt produced it, so an output can always be traced to the instructions that generated it.
7Human oversight
- A human decides that an interview happens, who is interviewed and what topics matter. The system never initiates one.
- A human decides who may read the result. Access is granted by a person, not inferred by a model.
- The customer is responsible for reviewing output before acting on it or distributing it further — clause 17.3 of the Subscription Agreement.
- Participants receive their own summary, which is the most direct form of oversight available: the person who was interviewed can see what was written.
8How we classify the system under the EU AI Act
Our current view is that OakHive is not a high-risk AI system under Annex III of the EU AI Act. Annex III point 4 covers systems used for recruitment, for decisions about promotion or termination, for allocating work, and for monitoring or evaluating performance and behaviour. OakHive does none of those: it captures what someone knows about their work and produces documents about that work, and the contract prohibits using it to inform decisions about the person.
It is subject to the transparency duties in Article 50, because it interacts with people and generates synthetic audio and, optionally, a synthetic face. Those duties are met as described in section 2.
Two honest qualifications. First, this classification is our own reasoned position and has not been confirmed by a regulator or by outside counsel. Second, it depends on how the product is actually used: a customer who used OakHive to evaluate people — in breach of the contract — could push the deployment into a different category. If your own assessment reaches a different conclusion, we want to hear it rather than argue with it.
9Questions and challenges
Questions about how the AI in OakHive works, challenges to anything stated here, and requests for the detail a data protection impact assessment needs: privacy@oakhive.ai.
If you are a participant and you think a summary about your work is wrong, you can ask for it to be corrected. The route is through your employer, who can action it directly — see section 7 of the Interview Privacy Notice.