Purpose and scope of this statement
Phoenix Utd CIC is an active Community Interest Company, company number 11027177. Its registered office is Office 1 Izabella House, 24–26 Regent Place, Birmingham, B1 3NJ. References to “PUCIC”, “we”, “us” and “our” in these documents mean Phoenix Utd CIC.
This statement explains how PUCIC approaches artificial intelligence in its website, communications and service design. It applies to PUCIC-controlled use of AI-assisted tools and does not replace the contractual or legal duties of the providers that develop, host or operate those tools.
Relevant EU AI Act deadlines
The EU AI Act applies in stages. The European Commission states that prohibited-practice rules began applying in February 2025; general-purpose AI rules became effective in August 2025; Article 50 transparency obligations apply from 2 August 2026; and the Commission describes high-risk obligations as beginning from 2 December 2027 for the systems it identifies.[1] [2]
PUCIC is a UK organisation. This statement adopts the Act’s transparency and governance principles where PUCIC’s AI use, outputs or services may be used in the EU, and as a practical standard of accountable AI use more generally.
Our risk classification approach
PUCIC assesses each proposed AI use case before deployment against four practical categories: prohibited or unacceptable risk, high risk, transparency risk, and minimal or no risk. The assessment considers the purpose, affected people, data, decision impact, provider terms, human involvement and potential impact on safeguarding, equality and fundamental rights.
PUCIC currently states that it does not operate a public AI chatbot, automated eligibility or referral decision maker, biometric categorisation, emotion-recognition tool, or AI-assisted safeguarding triage. Any proposal to introduce one requires a documented reassessment and formal approval before use.
Transparency and oversight
PUCIC may use AI-assisted imagery and copy under human review. A responsible person must be able to review, amend, reject or remove material before public publication. PUCIC will disclose a direct AI interaction clearly from the start where it is not obvious, consistent with the Article 50 transparency approach described by the European Commission.[2]
AI must not make a final decision about referral eligibility, service access, safeguarding, support allocation, employment, education access or an individual’s rights. Human staff remain responsible for substantive decisions and escalation.
Governance and monitoring
PUCIC will maintain a proportionate register of AI-enabled use cases, record the owner, purpose, data categories, provider, risk classification, controls and review date. New material risks, harmful outcomes, complaints, model changes or legal changes trigger reassessment. PUCIC will pause or withdraw a use case where safeguards are not adequate.
Data handling and sub-processors
PUCIC uses or plans to use the following approved providers. Processor use is reviewed against purpose, necessity, data handling, security controls and applicable contractual terms.
| Provider | Role in the PUCIC service | Current or planned use |
|---|---|---|
| Manus | Website hosting, application infrastructure and analytics | Website operation and aggregated site measurement |
| Microsoft 365 | Organisational email | Microsoft 365 is not used for the initial attachment-free referral workflow. |
| Mailchimp | Newsletter processor | Email-only double-opt-in newsletter when activated |
| Google Maps | Visitor-requested map service | Map panel is loaded only after a visitor requests it |
| Cloudflare | Web-security and delivery services | Where enabled for PUCIC web delivery |
Personal, referral and safeguarding information must not be provided to an AI tool unless PUCIC has approved the use case, data handling, contract and safeguards in writing.
Reporting questions, concerns and changes
Questions or concerns about PUCIC’s AI use can be sent to Policy@pucic.co.uk. Privacy questions may be sent to DPO@pucic.co.uk. PUCIC will review this statement every 12 months and sooner where UK law, EU law, technology or an identified risk requires a change.
References
[1] European Commission: AI Act regulatory framework. [2] European Commission: Article 50 transparency FAQ.
