THE HARLEY ACADEMY AI GOVERNANCE & ETHICS POLICY
Group-wide policy | Last updated: September 2026
1. PURPOSE AND SCOPE
This policy establishes the ethical, legal and operational framework for artificial intelligence used by or on behalf of companies within the Harley Academy group, including Harley Academy Limited and Harley Academy AI Limited (the “Group”). It applies across all current and future AI-enabled products, services, platforms, portals, internal tools and business processes, regardless of technology, interface or delivery channel.
It should be read with the Group Privacy Policy, Information Security requirements, Acceptable Use Policy and any service-specific terms, privacy notice, instructions or risk assessment. Service-specific documents may add controls but do not replace this policy.
2. GOVERNANCE PRINCIPLES
- Lawfulness and accountability: AI must be used for a defined, lawful purpose with a responsible business owner, proportionate governance and documented decisions.
- Human agency and oversight: AI supports people; it must not displace professional responsibility. Oversight must be proportionate to the use, foreseeable harm and regulatory classification.
- Transparency: Users must be told when they are interacting with AI or receiving material AI-generated content, together with relevant limitations and controls.
- Accuracy and robustness: Outputs and system behaviour must be tested and monitored to a level proportionate to the risk. Known limitations must be communicated.
- Fairness and accessibility: Design, testing and monitoring must consider discrimination, representative performance and accessibility for affected user groups.
- Privacy and security by design: Only data necessary for the defined purpose may be processed, with appropriate access, retention, security and supplier controls.
3. PERMITTED PURPOSES AND USER RESPONSIBILITY
AI may be used to support education, assessment, simulation, presentation coaching, content creation, operational efficiency, research, quality improvement and professional development where approved through the applicable governance process.
Unless expressly approved and regulated for that purpose, Group AI services do not provide medical diagnosis or treatment, legal advice, or decisions about patient care. Users must check material outputs, apply appropriate professional judgement and must not rely on AI as the sole basis for a clinical, legal, employment, educational or other consequential decision.
4. RISK ASSESSMENT AND APPROVAL
- Each AI use must have a named owner and a documented purpose, users, data flows, suppliers, limitations and foreseeable harms.
- A proportionate risk assessment must be completed before launch and repeated after material changes. This includes a Data Protection Impact Assessment where processing is likely to create a high risk to individuals.
- The owner must determine whether the use is prohibited, high-risk or subject to special transparency, safety or record-keeping duties under applicable law.
- Higher-risk uses require enhanced testing, human oversight, incident controls, legal or compliance review and formal approval before deployment.
5. DATA PROTECTION AND MEDIA PROCESSING
Depending on the service and user choices, AI-enabled processing may include account and profile data, user inputs, audio, transcripts, images or video streams, derived measurements, scores, feedback, generated outputs, usage data and progress records. A clear notice must explain what is collected, the purpose, who may receive it, retention and available controls.
No blanket assumption may be made that a Group service uses only synthetic data or never processes real-world media. Where media is processed only on a user’s device and is not uploaded or stored, the service notice and technical implementation must accurately reflect that position. Derived metrics linked to an account or session must be treated as personal data unless they have been irreversibly anonymised.
Special-category, biometric or patient-identifiable data must not be used unless the purpose, lawful basis, additional legal condition, safeguards and approvals have been documented. Users must be instructed not to enter patient-identifiable information unless the service is specifically designed and approved for it.
6. TRANSPARENCY, OUTPUTS AND HUMAN OVERSIGHT
- Material AI-generated interactions, feedback, simulations, images, audio or other content must be clearly identified as AI-generated or AI-assisted.
- Notices must state that outputs may be inaccurate, incomplete, biased or out of date and explain the level of independent checking expected.
- Human review must be designed around the risk. It is not necessary for every low-risk educational output to be reviewed before a user sees it, but qualified review, sampling, escalation or override must be available where needed.
- AI must not make a solely automated decision producing legal or similarly significant effects unless the use has been specifically approved, is lawful and includes required safeguards and rights.
7. TESTING, MONITORING AND RECORDS
Before release and after material change, systems must be tested for intended performance, security, foreseeable misuse, hallucination or fabrication, harmful content, bias, accessibility and failure modes appropriate to the use. Monitoring and periodic review must continue in production.
Records must be sufficient and proportionate to demonstrate the system version, material configuration, approval, testing, incidents and corrective action. Interaction content must not be logged by default merely for traceability; logging must follow the applicable privacy notice, access controls and retention schedule.
8. THIRD-PARTY PROVIDERS
AI suppliers must be assessed before use and governed by appropriate contracts, data-processing terms, security measures and international-transfer safeguards. Supplier claims about training use, retention, model behaviour and security must be verified for the relevant service and configuration and reviewed when terms or architecture change. Public consumer AI tools must not be used for confidential, personal or proprietary information unless specifically approved.
9. INCIDENTS, FEEDBACK AND ACCOUNTABILITY
Users and staff must have a clear route to report inaccurate, unsafe, discriminatory or inappropriate outputs, privacy concerns and security incidents. The responsible owner must investigate, contain and document material issues, notify relevant internal teams, customers, partners, individuals or regulators where required, and suspend or withdraw a system where risk cannot be adequately controlled.
Questions or concerns may be sent to privacy@harleyacademy.com. Individual services may provide an additional in-product reporting or feedback route.
10. TRAINING, REVIEW AND ENFORCEMENT
Personnel who design, procure, configure, operate or oversee AI must receive training appropriate to their role. Compliance with this policy is mandatory. Breaches may result in access restriction, corrective action or disciplinary action in accordance with applicable policies and law.
This policy will be reviewed at least annually and sooner following a material legal, regulatory, technical or operational change or a significant incident.
Download our full prospectus
Browse all our injectables, dermal fillers and cosmetic dermatology courses in one document
By submitting this form, you agree to receive marketing about our products, events, promotions and exclusive content. Consent is not a condition of purchase, and no purchase is necessary. Message frequency varies. View our Privacy Policy and Terms & Conditions
Attend our FREE open evening
If you're not sure which course is right for you, let us help
Join us online or in-person at our free open evening to learn more
Our Partners
















STAY INFORMED
Sign up to receive industry news, careers advice, special offers and information on Harley Academy courses and services