neomigrate.ai

Trust & governance

What happens when it gets something wrong.

Handing a real workflow to software is a risk decision before it is a technology decision. This page is written for whoever has to sign that off — what the system may do on its own, where your data goes, how accuracy is contracted, and what we can and cannot yet prove.

The boundary

What runs without a person, and what never does

Autonomy is set per workflow and written into the engagement. It is a dial you control, not a property of the software.

Reads

The system reads records, documents and queues in the systems you connect. Read access is scoped per workflow, never account-wide by default.

Proposes

It drafts the decision — a classification, a match, a chase, a routing — with the evidence it used attached, so the reasoning can be checked rather than trusted.

Acts, within a boundary

It writes back only the specific actions agreed for that workflow. Anything outside that boundary stops and waits, rather than improvising.

Escalates

Low confidence, an unseen edge case, or anything crossing a threshold you set goes to a person. Exceptions are the point of the design, not a failure of it.

Every run leaves a record: what was read, what was decided, on what evidence, and who approved it. A reviewer can reconstruct why a specific output happened without asking us to explain it after the fact.

Accuracy

A number in the contract, not a promise on a website

The ICO’s own guidance tells buyers to decide an acceptable level of accuracy before procurement, and to put accuracy-based measures into the supplier contract. Most suppliers wait to be asked. We bring it to the table.

Before a workflow goes live we measure it on your real cases and agree two numbers: the share that completes without a person, and the error rate on the rest. Both are written into the engagement with what happens if they are missed.

We quote the build only after that measurement, never before. An exception rate is not knowable from a conversation, and a fixed price quoted blind is a price with a guess inside it — ours to carry, but yours to pay for.

Data protection

Where your data goes, in plain terms

Where does our data actually go?

Into your systems and ours only for as long as a workflow run needs it. Documents and records are processed in the run and are not retained as a training corpus. Nothing is used to train or fine-tune a model — not ours, not a vendor's.

Which third parties touch it?

A model provider, and whatever systems your workflow already runs on. You get the specific list in writing before the first run, and written notice before it changes. There is no undisclosed sub-processor.

Where is it processed?

Model processing may involve a transfer outside the UK. Where it does, the transfer route is named in the agreement rather than assumed, and UK or EU hosting is available where a workflow needs it. We will not tell you the question is settled — international transfer rules are genuinely in flux right now.

What happens at the end?

You keep the workflow. Code, configuration and documentation are yours, and there is a defined exit with your data returned in a portable format. Leaving does not require our cooperation to be quick.

Automated decisions, and the right to object

Where a workflow affects a person, UK data protection law gives them a route to information about the decision, to make representations, to obtain human intervention and to contest the outcome. We build that route into the workflow rather than describing it in a policy. Most target workflows also warrant a Data Protection Impact Assessment — we will write yours as part of the engagement.

Where we stand

What we can prove today, and what we cannot

Stated plainly, because you will check.

NeoMigrate is early. There is no certification wall on this page because there is nothing yet to put on it, and a supplier who implies otherwise is telling you something about how the rest of the engagement will go.

What you get instead is a written data-processing agreement, a named sub-processor list, a Data Protection Impact Assessment for your workflow, an accuracy standard in the contract, professional indemnity cover, and a clean exit. Certification is on the roadmap and will appear here when it is held, not when it is started.

You will also be dealing with one person throughout. That is a genuine limit on how much work can run at once, and it is the reason engagements are scoped one workflow at a time rather than sold as a programme.

Regulation

Where the EU AI Act actually stands

Transparency obligations and enforcement powers commence on 2 August 2026. The high-risk obligations most people are bracing for have moved: the Digital Omnibus on AI pushed Annex III systems — employment, credit, essential services — back to 2 December 2027, and product-embedded systems to 2 August 2028.

Whether any of it reaches you depends on where your output is used and what the workflow decides. A UK-only workflow processing your own supplier invoices sits in a very different place from a recruitment screen used in the EU. We will tell you which one you are, including when the answer is “none of this applies to you”.

This is how we read the current position, not legal advice. Where it matters commercially, get it confirmed by a solicitor — and be careful with anything written before July 2026, which will still quote the superseded dates.

Still have a question we missed?

Send it. If the answer is that we are not the right fit, that is a faster and cheaper thing for both of us to find out now.

Or write to pavel@neomigrate.ai