Introduction and Commitment
These Guidelines cover the design, development, deployment, and use of AI systems across InterSystems' business operations, product offerings, and third-party integrations.
InterSystems is committed to promoting responsible AI practices and implementing necessary and appropriate safeguards for AI use. InterSystems promotes transparency and accountability with respect to the use of AI by following our principles set forth at www.intersystems.com/about-us/trust-and-responsibility-with-ai/ (AI Principles) and follows applicable laws, has put safeguards in place for its AI use and expects customers and other business partners to do the same. These Guidelines follow the NIST AI Risk Management Framework (AI RMF) four core functions (Govern, Map, Measure, Manage) and incorporate seven trustworthy AI characteristics: validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, Privacy enhancement, and Fairness with Harmful ias managed.
Parenthetical references (e.g., GOVERN 1, MAP 2) denote the specific AI RMF subcategories to which a given practice corresponds.
1. Applicability
These Guidelines apply to: (a) internal use of AI by InterSystems in its business operations, including development, testing, and deployment of offerings; (b) AI offered by InterSystems as part of its product or service offerings; and (c) use of AI by third parties who deploy independently procured AI in conjunction with InterSystems' offerings or in the provision of products or services to InterSystems.
These Guidelines should be read in conjunction with any contract to which InterSystems is a party. If there is a conflict between the terms of any such contract and these Guidelines, the Guidelines shall control unless the contract specifically and explicitly overrides these Guidelines.
2. Definitions
For purposes of these Guidelines, the following definitions apply:
Artificial Intelligence (AI) refers to an engineered or machine-based system that can generate outputs such as predictions, recommendations, or decisions influencing real or virtual environments, operating with varying levels of autonomy. For these Guidelines, AI includes machine learning, generative AI models, and similar probabilistic systems.
AI Actors refers to those who play an active role in the AI Lifecycle, including organizations and individuals that design, develop, provide, deploy, evaluate, or operate AI systems.
AI Lifecycle refers to the stages an AI system passes through, from planning and design, through data collection and model building, to deployment, operation, and eventual decommissioning.
AI Provider refers to a third-party entity whose AI tools or functionality are included with or connected to an InterSystems offering.
Bespoke AI Development refers to AI functionality that InterSystems (or an appointed third party) develops or deploys specifically for a customer or other third party, as distinct from Innate AI Features or Runtime Services.
Explainability refers to providing information or reasons for system output in a manner meaningful to users, developers, and auditors. Interpretability refers to the ability to understand AI system output in the context of its designed functional purposes.
Fairness means that an AI system is designed, developed, deployed, and monitored to manage harmful bias and reduce discriminatory or inequitable outcomes, considering the system’s context of use and its potential impacts on individuals, groups, communities, organizations, and society.
Harmful Bias refers to conscious or unconscious bias resulting in inequitable treatment of certain social groups. The three major categories are systemic bias, computational and statistical bias, and human-cognitive bias.
Innate AI Feature refers to AI functionality that has been included in certain InterSystems offerings.
Privacy refers to freedom from intrusion into the private life or affairs of an individual, including freedom from undue or illegal gathering and use of data about that individual.
Resilience refers to a system's ability to prepare for, adapt to, and recover from disruptions.
Runtime Service refers to functionality or features provided by a third party and included with an InterSystems offering, which may include AI tools or models of a third-party AI Provider.
Safety refers to the property of a system such that it does not, under defined conditions, lead to a state in which human life, health, property, or the environment is endangered. Safety involves reducing both the probability of expected harms and the possibility of unexpected harms as well as taking reasonable steps to mitigate such.
Security refers to resistance to unauthorized acts designed to cause harm, including protection of information and data with appropriate access controls.
3. AI Governance Framework
Consistent with the NIST AI RMF's GOVERN function, InterSystems operates an internal AI Governance Framework with the following key elements.
3.1 Leadership and Governance
The AI Council, comprising representatives from relevant business divisions, sets AI strategic direction, establishes risk tolerances, and ensures AI risk management policies are transparent and effective (GOVERN 1). Executive leadership owns AI risk decisions and sets the tone for risk management; management aligns technical AI risk management to policies and operations (GOVERN 2.3).
3.2 AI Review Bodies
The AITRUST Committee reviews proposals to incorporate AI into external-facing InterSystems’ offerings, including Runtime Services, Innate AI Features, and Bespoke AI Development, conducting risk assessments and developing mitigation recommendations; all external-facing offerings may require senior executive approval. The AI Enablement Team reviews proposals for internal AI use, including administrative functions, operational workflows, development support, and supplier AI oversight. Both bodies evaluate compliance with these Guidelines, applicable law, assess risks, and coordinate with each other (GOVERN 2).
3.3 Training, Culture, and System Management
InterSystems conducts periodic training on AI literacy, risk awareness, applicable laws, organizational risk management goals, and trustworthy AI characteristics (GOVERN 2.2). AI risk decisions are informed by diverse teams with varied demographics, disciplines, and expertise (GOVERN 3). InterSystems maintains an AI system inventory resourced according to organizational risk priorities, with processes for safe decommissioning that do not increase risks or decrease trustworthiness (GOVERN 1.6, GOVERN 1.7).
4. Categories of AI Use
4.1 Internal Use of AI by InterSystems
InterSystems uses AI in internal operations including content summarization, marketing materials, training content, RFP responses, code generation, documentation amalgamation, and project planning. It maintains policies governing supplier AI use with required transparency regarding AI involvement in deliverables. Operational AI use is deployed at InterSystems' discretion and is confidential, though InterSystems acknowledges that operational AI may contribute to downstream external deliverables and these Guidelines provide assurances as to the integrity of those outputs (MAP 1, MAP 3).
4.2 AI Included with an InterSystems Offering
InterSystems may include AI in its offerings as Runtime Services (third-party AI Provider tools), Innate AI Features (developed by InterSystems), or Bespoke AI Development (custom AI for a specific customer). In all cases, user organizations will be informed and, where feasible, permitted to opt out.
4.3 Adjacent Use of AI by Third Parties
Customers may connect InterSystems offerings to third-party AI or, with appropriate permission, develop AI capabilities used in conjunction with InterSystems offerings, at the customer's sole risk, discretion and cost. Customers are expected to follow these Guidelines, applicable regulation(s) and are solely responsible for such adjacent AI, including data accuracy, security, and lawfulness; InterSystems is not responsible for adverse outcomes arising from such use. If a customer uses AI in connection with InterSystems' proprietary materials, InterSystems is not responsible for the accuracy or reliability of outputs generated therefrom, no transfer of intellectual property rights results, and all derivative works vest with InterSystems. Contractual language may be amended to reflect properly the responsibility between the relevant parties.
5. Trustworthy AI Characteristics
InterSystems is committed to developing and deploying AI systems that exhibit the trustworthy characteristics as defined by the AI RMF and aligned with Responsible AI principles. Creating trustworthy AI requires balancing each of these characteristics based on the AI system's context of use (MEASURE 2). InterSystems looks for its customers, partners, and suppliers to achieve similar trustworthy AI practices.
5.1 Valid and Reliable
With respect to all Innate AI Features, InterSystems validates such AI Feature that it provides or deploys for its intended use, designs human oversight within workflows and where applicable, ensures reliable performance through accuracy measurements with realistic test sets, documented test methodology, and ongoing assessments of validity, accuracy, robustness, and reliability.Customers and other business partners are expected to do the same with respect to all other AI functionality used.
5.2 Safe
AI systems must meet the Safety standard in Section 2, achieved through rigorous simulation and testing, real-time monitoring, ability to shut down or modify deviating systems, and human intervention capabilities.
5.3 Secure and Resilient
InterSystems designs AI systems to exhibit Resilience and Security (as defined in Section 2), addressing adversarial examples, data poisoning, exfiltration of models or data, and unauthorized access, aligned with the NIST Cybersecurity Framework.
5.4 Explainable and Interpretable
InterSystems aims to provide users of its AI systems with transparency on their interaction with the tool in order to facilitate human-based user judgement when interacting with AI in the user interface.It also looks to design AI systems to help end users understand purposes and potential impact, providing system outputs in a manner meaningful to users; explainability risk is managed by describing AI system functions tailored to the user's role and skill level, user guides and clear statements on intended purpose of the AI outputs and associated software.
5.5 Privacy-Enhanced
InterSystems offerings and internal deployments are guided by anonymity, confidentiality, and user control, using privacy-enhancing methods including de-identification, data aggregation, and documentation of Privacy risks.
5.6 Fair with Harmful Bias Managed
InterSystems addresses Fairness by managing Harmful Bias — systemic, computational and statistical, and human-cognitive — by implementing measures to identify, evaluate, and mitigate bias throughout the AI Lifecycle.
6. Transparency, Disclosure, Lifecycle Governance; Disclaimers
InterSystems discloses the intended purpose, material limitations, training-data categories, guardrails, and human-oversight expectations for each AI offering (GOVERN 1.6, GOVERN 4). Third-party AI Providers are identified so customers may seek additional detail directly (MANAGE 4.1). Before development, risk review establishes context and identifies risks for the intended purpose (MAP 1, MAP 2). During development, data provenance, legal risks, accuracy, robustness, bias, and security are evaluated and documented (MAP 4, MEASURE 2). In operation, deployed systems are monitored for drift, incidents are managed, and material changes are recorded and communicated to customers (MANAGE 2, MANAGE 4). Governance records are retained to demonstrate compliance with these Guidelines, applicable law, and EU AI Act Article 26 deployer obligations.
7. Third-Party AI Risk Management
InterSystems is developing and maintains policies to address AI risks from third-party software, data, and supply chain issues, covering risks of infringing third-party IP, transparency into third-party system functions, knowledge about training data and algorithms, assumptions and limitations, and testing of third-party AI systems (GOVERN 6; MANAGE 3). Contingency processes address failures in high-risk third-party AI system use, with regular monitoring of risks and benefits and documented risk controls.
8. Compliance with Laws and Regulations
InterSystems, its customers, and other business partners must comply with all applicable AI laws and regulations (GOVERN 1.1, GOVERN 1.2).
For example, under the EU AI Act (Regulation (EU) 2024/1689), customers must adhere to the intended use associated with the InterSystems offering and understand the regulatory risk category associated with the AI system and how outputs are used . The varying classifications trigger additional deployer obligations and changes in use may change the risk category of the AI system itself and the role of the relevant parties (e.g. a deployer, importer or reseller may become a provider under the regulation under certain circumstances).
InterSystems documents the intended use and instructions for its offerings within its Product Documentation. Customers may not use AI outside its stated intended use. Questions should be directed to legal@intersystems.com.
These Guidelines do not expand or modify legal obligations under applicable law.
9. Compliance with Responsible and Ethical AI Use
Customers, and other business partners, should not use any InterSystems offering or any third-party AI in conjunction with such offering:
- to reverse engineer, probe the model or undertake adversarial testing on any AI made available by InterSystems;
- as a substitute for professional advice (e.g., clinical, legal, financial);
- to make automated decisions about individuals without a lawful basis and meaningful human review and validation;
- to generate or disseminate harmful, deceptive, infringing, or unlawful content;
- To train, improve, develop or finetune independent AI systems unless explicitly authorised in writing;
- to use any InterSystems Innate AI Feature, Bespoke AI Development, or Runtime Service — or the underlying models, weights, prompts, embeddings, fine-tuning data, or non-public outputs made available through them, to train or build a model or offering intended as a substitute for the applicable InterSystems or third-party AI offering. This clause targets extractive practices such as model distillation, weight or prompt reconstruction, and systematic scraping of non-public outputs, and is not intended to restrict AI features or offerings that a customer or partner has independently developed, currently offers, or develops in the future without using the materials above, including those of InterSystems' established partners operating under a written agreement. It also does not restrict benchmarking, interoperability testing, or internal evaluation, or the use of the customer's or partner's own data, its customers' data (subject to applicable terms), or publicly available information.; or
- to commercially exploit or circumvent any restriction on InterSystems or third-party AI offerings or contracts; or
- for processing, generating, classifying, or filtering content in ways that can inflict harm on individuals, organizations, or society.
10. Customer Inputs and Outputs from AI
InterSystems will not use customer AI inputs or outputs to train any AI model and will seek similar undertakings from any AI Provider. InterSystems may, however, analyze AI inputs and outputs for market research, and use such inputs and outputs to improve InterSystems' offerings, functionalities, and features, unless the customer instructs InterSystems otherwise (MANAGE 2).
11. Incident Reporting and Escalation
If any party becomes aware of a material risk of any of the following resulting from or in connection with any use of AI in conjunction with an InterSystems offering, that party should send an email to incident@intersystems.com within twenty-four (24) hours:
- Any harm to individuals, including physical, psychological, economic, reputational, or discriminatory harm.
- A violation of these Guidelines, applicable contractual terms, applicable law, rule, or regulation.
- Significant deviation from expected or intended behavior of the AI or its output(s).
- Unauthorized disclosure or misuse of personal or sensitive data.
- Critical failure or misuse of AI in Safety, rights, or decision-critical contexts (e.g., employment, recruitment, healthcare, legal, financial).
- Any other AI-related outcome that requires escalation, investigation, correction, or notification under applicable AI governance, ethical, or legal frameworks.
Incidents and errors are communicated to relevant AI actors, including affected parties (MANAGE 4.3). Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.
Each incident report under this Section 11 should include, to the extent known at the time of reporting (MANAGE 4.1, MANAGE 4.2):
- System identification (name, version, category), nature and scope of the incident, and timeline (discovery, first occurrence, submission dates).
- Affected stakeholders and estimated number of persons affected, harm assessment (type, severity, actual or anticipated), and preliminary root cause analysis.
- Immediate actions taken (containment, mitigation, shutdowns), planned remediation steps with estimated timelines, and reporting party contact information.
Reports should be supplemented as additional information becomes available. InterSystems may request further details as reasonably necessary.
For general AI-related questions or concerns, please contact legal@intersystems.com and ai-enablement@intersystems.com.
12. Updates, Contacts, and Support for These Guidelines
These Guidelines may be updated at www.intersystems.com/AI-Use-Guidelines. InterSystems is committed to keeping them current as AI technology, standards, and rules evolve.
For AI-related questions or concerns, please contact ai-enablement@intersystems.com.







































