About This Article
This article is designed to help provide answers to a variety of common questions that might come up regarding Recognition Coach. These questions are based on topics such as data, compliance, infrastructure, legal, privacy and GDPR. Take a look at the questions listed below.
Frequently Asked Questions
What data does it use to create recognition messages?
The Recognition Coach uses only the employee's input, which includes their draft or key points for the recognition. It does not retrieve or cite any other content beyond what the user provides.
What are the inputs and outputs?
The inputs consist of the employee's draft or notes for the recognition message. The output is a restructured recognition message derived from that input, providing a more polished and thoughtful version of what the employee originally wrote.
Which AI models and infrastructure are used?
The Recognition Coach uses Anthropic Claude Sonnet, delivered via Amazon Bedrock on AWS. Altenative Bedrock-available models may be introduced in the future, based on a thorough internal review process.
How is sensitive or PII information handled?
Amazon Bedrock guardrails inspect inputs and outputs to detect and mask sensitive information and filter harmful content. The Recognition Coach does not add personal data that the user did not provide. If a user includes sensitive details, the guardrails may mask or block them.
Is the Recognition Coach GDPR compliant?
The solution is designed to align with GDPR principles, including:
- Lawful, purpose-limited data processing
- Data access and deletion controls
- Transparency and auditability
- Configurable retention policies, where applicable
What legal, privacy, or regulatory considerations should organizations review before enabling the feature?
We design and operate our AI solutions in alignment with applicable privacy, data protection, and AI governance requirements, including GDPR, the EU AI Act, accessibility requirements, and emerging AI-related employment regulations such as NYC Local Law 144. Compliance is supported through regular legal and privacy reviews, data minimization practices, PII protection and redaction controls, transparency and notice mechanisms, access controls, retention and deletion policies, and oversight from our privacy, security, and governance teams before significant AI-related changes are deployed.
We maintain documentation of our compliance and governance practices and can provide additional information upon request where appropriate. The solution is hosted on Amazon Bedrock, which provides enterprise-grade security, privacy, and compliance capabilities. While Bedrock supports our compliance objectives through its infrastructure and controls, responsibility for compliance with applicable laws and regulations remains a shared responsibility between the platform provider and the solution operator.
What testing or assurance activities are performed on the AI system?
- Testing is performed at least once per month
- Guardrail language coverage is reviewed every 6 months
- AWS and Anthropic documentation, along with bias and guardrail testing, is reviewed quarterly
How would organizations be notified in the event of a security incident or breach?
Using the same procedures as other components of the platform.
Comments
0 comments
Please sign in to leave a comment.