AI Agent & Virtual Assistant Policy

Effective: July 2026  |  Last updated: July 2026

This Policy describes the governance standards Web Semantics applies when it designs, configures, hosts, operates, or supports artificial-intelligence agents, virtual assistants, and related automated systems. It is intended to explain our default operating practices to clients, users, and the public.

Our operating principle: Before an AI system receives access or authority, we define what it may read, write, communicate, approve, purchase, publish, delete, or execute—and which actions require human authorization.

This Policy is a public statement of general practices. A client’s Order, AI Agent Service Terms, Agent Authorization Schedule, Data Processing and Security Schedule, and other written agreements control a specific deployment.

1. Purpose and scope

This Policy applies to AI Systems Web Semantics provides as a service or materially configures or operates for a client. It does not convert every ordinary software feature, analytics process, or third-party platform into a Web Semantics-managed AI System. It does not replace a contract, legal requirement, or client-specific risk assessment.

Controls are selected according to the deployment’s purpose, users, data, integrations, autonomy, reversibility, and potential effect. A low-risk internal drafting assistant does not require the same controls as a system that communicates externally, modifies records, or initiates financial activity.

2. Definitions

An “AI System” is software that uses machine learning, a foundation model, a language model, rules, retrieval, tools, workflows, or a combination of those components to generate content, make recommendations, or perform actions.

An “AI Agent” or “Virtual Assistant” is an AI System configured to pursue defined tasks, interact with users or systems, or invoke approved tools. “Agent” is technology terminology only.

An “Authorized User” is a person permitted by the client to use or supervise the AI System. A “Human Approver” is a designated person whose approval is required before specified actions.

3. No legal agency relationship

An AI Agent is software. It is not a legal person, employee, officer, fiduciary, licensed professional, or representative with inherent authority. Calling software an “agent,” “assistant,” or similar term does not create a legal agency, employment, partnership, fiduciary, or professional relationship.

An AI System may communicate or act only within authority expressly established by a client-specific agreement and configuration. It may not bind Web Semantics or a client to a contract, admission, waiver, settlement, price, refund, purchase, or other obligation unless the applicable written authorization expressly permits that action and defines its limits.

4. Transparency and automated interactions

Where reasonably appropriate to the context, an externally facing AI System should identify itself as automated or AI-assisted and provide a practical path to human escalation. It must not falsely claim to be a human employee or licensed professional.

Disclosure methods may vary based on the interface, audience, interaction, and legal requirements. We do not promise a separate disclosure in every internal, administrative, testing, or machine-to-machine exchange.

5. Defined authority and least privilege

AI Systems should receive only the data, credentials, tools, permissions, and duration of access reasonably necessary for the approved purpose. Material authority should be documented in an Agent Authorization Schedule.

Authorization should identify, where applicable:

  • systems and data the AI System may access;
  • permitted read, write, communication, publication, deletion, execution, and transaction actions;
  • prohibited systems, records, and actions;
  • human approval gates;
  • financial, frequency, geographic, recipient, and time limits;
  • escalation and emergency shutdown contacts; and
  • logging, review, and retention requirements.

Silence, technical capability, possession of credentials, or a user’s informal request does not expand documented authority.

6. Human oversight and approval gates

By default, a qualified person should review consequential actions before execution. A client-specific schedule may permit narrowly defined automated actions when the expected harm is limited and reasonable safeguards, monitoring, limits, and recovery procedures are documented.

Human oversight must be meaningful. A Human Approver should have sufficient information, authority, time, and competence to review the action and should not be instructed to approve outputs automatically.

7. Output, tool action, and consequential action

Content output

Generated text, summaries, classifications, recommendations, drafts, or other informational output. Output generally requires verification before material reliance.

Tool action

An action through a connected system, such as sending a message, updating a record, creating a ticket, scheduling an event, publishing content, changing a configuration, or executing a command.

Consequential action

An action reasonably capable of materially affecting money, legal obligations, access, employment, housing, credit, insurance, healthcare, safety, privacy, reputation, system availability, or another person’s rights. Consequential actions require enhanced controls and, by default, human approval.

Controls should increase as a system moves from generating output to taking external, irreversible, privileged, or consequential action.

8. Accuracy and verification

AI Systems can produce incorrect, incomplete, outdated, fabricated, biased, or contextually inappropriate output. Retrieval, grounding, testing, and review can reduce but do not eliminate these risks.

Users and clients must verify material facts, citations, calculations, instructions, and decisions before relying on them. AI output is not legal, medical, financial, accounting, employment, safety, or other regulated professional advice unless it is independently reviewed and delivered by a properly qualified professional acting within an authorized engagement.

9. Data privacy and model providers

AI Systems should process only information reasonably necessary for the documented purpose. Data categories, processing instructions, retention, deletion, locations, and approved providers may be specified in a Data Processing and Security Schedule.

Web Semantics may use third-party model, cloud, communications, analytics, security, and infrastructure providers. Their processing depends on the selected service, configuration, and contract. We seek service terms and configurations appropriate to the deployment, but do not represent that every provider offers identical controls.

Sensitive or regulated data requires prior classification and an approved workflow. Users must not place passwords, private keys, full payment-card data, government identifiers, protected health information, privileged legal material, or other restricted data into an AI System unless expressly authorized and protected by suitable controls.

10. Security and credential handling

Reasonable controls may include scoped credentials, separate service accounts, role-based access, encryption, secret-management tools, network restrictions, rate limits, approval gates, monitoring, backups, and revocation procedures. The appropriate controls depend on risk and architecture.

Credentials must not be embedded in prompts, public source code, ordinary chat, or unprotected documents. Clients remain responsible for their own identity systems, user lifecycle, endpoint security, and permissions unless a written agreement assigns those functions to Web Semantics.

11. Prompt injection and adversarial inputs

External messages, websites, documents, files, images, and tool results may contain instructions designed to manipulate an AI System. AI Systems may also misunderstand benign inputs. Web Semantics may use filtering, isolation, instruction hierarchy, content controls, allowlists, confirmation steps, and monitoring to reduce risk.

No safeguard can guarantee detection of every malicious or misleading instruction. An AI System’s ability to access content does not make that content trusted. High-risk actions should not depend solely on the model’s judgment about whether an instruction is safe.

12. Logging and accountability

Where practical and proportionate, material actions should generate operational records showing the time, initiating user or workflow, tool invoked, action requested, approval state, result, and error or escalation. Logs support troubleshooting, security, billing, audit, and dispute resolution.

Operational logging does not require Web Semantics to preserve or disclose hidden model reasoning, chain-of-thought, proprietary security logic, or every transient system event. Logs may be incomplete because of outages, provider limitations, privacy restrictions, or technical failure.

13. High-impact and regulated uses

AI Systems must not independently make final decisions that determine or materially affect a person’s eligibility for employment, housing, credit, insurance, healthcare, education, legal services, government benefits, essential utilities, or similar high-impact opportunities unless a separately approved engagement establishes legal authority, qualified human decision-making, testing, notices, appeal processes, records, and other required safeguards.

Clients are responsible for identifying laws, industry rules, licenses, notices, consents, and recordkeeping requirements applicable to their use. Web Semantics may require legal review or decline a proposed deployment.

14. Prohibited uses

AI Systems provided by Web Semantics may not be used for unlawful surveillance, fraud, phishing, malware, credential theft, unlawful discrimination, harassment, impersonation intended to deceive, spam, unlawful calling or texting, rights violations, unauthorized scraping, security circumvention, weapons-related harm, exploitation of children, or other activities prohibited by our AI Acceptable Use Policy.

15. Incidents, escalation, and emergency suspension

Web Semantics may limit, isolate, suspend, or disable an AI System or integration when reasonably necessary to address suspected compromise, data exposure, prompt injection, unlawful use, excessive spending, unauthorized activity, provider-policy violation, material malfunction, or risk to a person, system, or legal interest.

Emergency protective action may occur before notice when delay would increase risk. Restoration may require investigation, credential rotation, configuration changes, additional safeguards, client approval, or a revised scope.

16. Client and user responsibilities

Clients and Authorized Users are responsible for:

  • providing accurate requirements, data classifications, and authority limits;
  • maintaining lawful rights to data, systems, content, and accounts;
  • designating qualified approvers and escalation contacts;
  • reviewing outputs and consequential actions;
  • training users and preventing credential sharing;
  • complying with applicable laws, notices, consents, and industry rules;
  • monitoring business outcomes and reporting suspected errors or incidents promptly; and
  • not expanding access, tools, or uses outside the approved scope.

17. Limitations and document priority

This Policy does not guarantee accuracy, uninterrupted operation, complete explainability, absence of bias, detection of every attack, or prevention of every unauthorized action. AI Systems remain probabilistic and dependent on data, providers, software, networks, users, and external systems.

If this Policy conflicts with an executed client agreement, the executed agreement controls for that engagement. Our Privacy Policy, Terms & Conditions, AI Agent Service Terms, and AI Acceptable Use Policy may also apply.

18. Contact

Questions or concerns about an AI System may be directed to:

Web Semantics
Attn: AI Governance
607 SE Olympia Dr.
Vancouver, WA 98683
[email protected]
(360) 365-5005


For an active incident, also use the escalation contact identified in the applicable Agent Authorization Schedule or service agreement.

Call Now