If someone is in immediate danger, call 999.Safeguarding and urgent help

EU AI Act disclosure and AI policy

A contextual statement of how PUCIC approaches AI-assisted work, transparency, human review and accountable governance.

Published for the limited information launchReview: every 12 months or sooner where UK law requires

Purpose and scope of this statement

Phoenix Utd CIC is an active Community Interest Company, company number 11027177. Its registered office is Office 1 Izabella House, 24–26 Regent Place, Birmingham, B1 3NJ. References to “PUCIC”, “we”, “us” and “our” in these documents mean Phoenix Utd CIC.

This statement explains how PUCIC approaches artificial intelligence in its website, communications and service design. It applies to PUCIC-controlled use of AI-assisted tools and does not replace the contractual or legal duties of the providers that develop, host or operate those tools.

Relevant EU AI Act deadlines

The EU AI Act applies in stages. The European Commission states that prohibited-practice rules began applying in February 2025; general-purpose AI rules became effective in August 2025; Article 50 transparency obligations apply from 2 August 2026; and the Commission describes high-risk obligations as beginning from 2 December 2027 for the systems it identifies.[1] [2]

PUCIC is a UK organisation. This statement adopts the Act’s transparency and governance principles where PUCIC’s AI use, outputs or services may be used in the EU, and as a practical standard of accountable AI use more generally.

Our risk classification approach

PUCIC assesses each proposed AI use case before deployment against four practical categories: prohibited or unacceptable risk, high risk, transparency risk, and minimal or no risk. The assessment considers the purpose, affected people, data, decision impact, provider terms, human involvement and potential impact on safeguarding, equality and fundamental rights.

PUCIC currently states that it does not operate a public AI chatbot, automated eligibility or referral decision maker, biometric categorisation, emotion-recognition tool, or AI-assisted safeguarding triage. Any proposal to introduce one requires a documented reassessment and formal approval before use.

Transparency and oversight

PUCIC may use AI-assisted imagery and copy under human review. A responsible person must be able to review, amend, reject or remove material before public publication. PUCIC will disclose a direct AI interaction clearly from the start where it is not obvious, consistent with the Article 50 transparency approach described by the European Commission.[2]

AI must not make a final decision about referral eligibility, service access, safeguarding, support allocation, employment, education access or an individual’s rights. Human staff remain responsible for substantive decisions and escalation.

Governance and monitoring

PUCIC will maintain a proportionate register of AI-enabled use cases, record the owner, purpose, data categories, provider, risk classification, controls and review date. New material risks, harmful outcomes, complaints, model changes or legal changes trigger reassessment. PUCIC will pause or withdraw a use case where safeguards are not adequate.

Shared responsibility

AI suppliers remain responsible for their systems and contractual commitments. PUCIC remains responsible for how it selects, configures, deploys, reviews and communicates about tools used under its authority. Staff and contractors must follow this policy, report concerns and avoid putting confidential, referral or safeguarding information into unauthorised AI tools.

Data handling and sub-processors

PUCIC uses or plans to use the following approved providers. Processor use is reviewed against purpose, necessity, data handling, security controls and applicable contractual terms.

ProviderRole in the PUCIC serviceCurrent or planned use
ManusWebsite hosting, application infrastructure and analyticsWebsite operation and aggregated site measurement
Microsoft 365Organisational emailMicrosoft 365 is not used for the initial attachment-free referral workflow.
MailchimpNewsletter processorEmail-only double-opt-in newsletter when activated
Google MapsVisitor-requested map serviceMap panel is loaded only after a visitor requests it
CloudflareWeb-security and delivery servicesWhere enabled for PUCIC web delivery

Personal, referral and safeguarding information must not be provided to an AI tool unless PUCIC has approved the use case, data handling, contract and safeguards in writing.

Reporting questions, concerns and changes

Questions or concerns about PUCIC’s AI use can be sent to Policy@pucic.co.uk. Privacy questions may be sent to DPO@pucic.co.uk. PUCIC will review this statement every 12 months and sooner where UK law, EU law, technology or an identified risk requires a change.

References

[1] European Commission: AI Act regulatory framework. [2] European Commission: Article 50 transparency FAQ.

Need to raise a policy question?

For policy and accessibility questions, contact Policy@pucic.co.uk. For personal-data and privacy questions, contact DPO@pucic.co.uk.