Version 1.0. Last reviewed July 2026. Reviewed every six months or when our systems materially change, whichever comes first.
Why this policy exists
OCC Research builds institutional memory infrastructure for governments. Artificial intelligence is part of how our systems work, so our clients and the public deserve a plain statement of what AI does inside our products, what it is not allowed to do, and how we handle the data it touches. This page is that statement.
Where we stand on AI
We use AI and we do not fully trust it. Both things are true, and pretending otherwise would be dishonest.
Language models are built on the accumulated labor and records of people who were never asked. They are controlled by a small number of companies whose incentives are scale and lock-in, not the health of the institutions adopting them. The question that matters with any AI system is not what it can do but who controls it, who is accountable when it is wrong, and who benefits from its adoption.
Governments should be especially skeptical of vendors pushing AI on them. Much of what is sold to the public sector as intelligence is automation of judgment: systems that generate conclusions no one can trace, score people and decisions on logic no one can inspect, and promise efficiency while quietly moving authority from public officials to a vendor’s model. A government that cannot explain its own decisions has not been made more efficient. It has been made less accountable, and it has usually paid for the privilege.
These concerns are not a disclaimer on our work. They are the reason our systems are designed the way they are. We confine AI to the one task where it is useful and checkable, extraction from documents, and we keep every conclusion deterministic, inspectable, and traceable to a public record. If we ever ask a client to trust a model’s judgment instead of their own record, this policy has failed and so have we.
How AI is used in our products
Our systems turn messy public and institutional records (minutes, resolutions, contracts, budgets, transcripts, scanned documents) into structured, queryable memory. AI has one job in that pipeline: extraction. Depending on the source, a language model either reads the document directly and pulls out structured facts, such as a resolution number, a dollar amount, a vendor name, or a deadline, or writes the parsing code that does the same. In both modes, the output is structured data checked against validation rules, and a fact that cannot be traced to a source is rejected.
Everything downstream of extraction is deterministic. Metrics, findings, and comparisons are computed from the structured record, not generated by a model. The same inputs produce the same outputs, and every number can be re-derived.
What AI is not allowed to do
The model does not write conclusions. It does not decide whether a commitment was fulfilled, whether spending was documented, or whether an issue is recurring. Those determinations come from computation over extracted records.
The model does not predict. Our systems describe what happened in the record. They do not forecast outcomes, score future behavior, or recommend decisions.
The model does not invent. If a fact is not in a source document, it is not in our system. Extracted records that cannot be traced to a source are rejected, not filled in.
Traceability and accuracy
Every fact in our systems carries a citation to the source document it came from, and a flag stating whether it was directly observed in the record or inferred from it. Anyone reviewing a finding can follow it back to the underlying minutes, contract, or resolution.
Extraction is imperfect, and we treat it that way. Extracted data is validated against structural rules before it enters the record, findings are reviewed by a human before they are delivered to a client or published, and we maintain test datasets to measure extraction accuracy over time. When a client or member of the public identifies an error, we correct the record and the correction is traceable like everything else. Errors can be reported to othman@occresearch.org.
Data handling
Public deployments are built entirely from records that are already public. Client engagements may add internal records under a written agreement that defines scope, access, and retention.
We do not use client data or ingested records to train AI models, and we do not permit our AI providers to do so. Model calls run under commercial terms that exclude our data from provider training.
Client data is never shared with, or visible to, any other client. Where our products offer cross-institution comparisons, participation is opt-in and only aggregated, anonymized patterns are shared. No institution’s underlying records are exposed to another.
The model layer in our architecture is interchangeable by design. Where a client has data residency or sovereignty requirements, extraction can run on models that meet those requirements without changing the rest of the system.
AI in our own operations
OCC Research uses AI tools in day-to-day work, including drafting, research, and software development. All external-facing material is reviewed by a human before release. AI-assisted research is verified against primary sources before it is relied on or shared. Personally identifiable information and data covered by client agreements are not entered into general-purpose AI tools outside the controls described above.
Questions
This policy is maintained by OCC Research LLC. Questions and error reports: othman@occresearch.org.
Governance that remembers. Institutional Memory as a Service.
Have thoughts or feedback on this research?
Othman@occresearch.org