AI Use & Limitations Statement
| Field | Value |
|---|---|
| Document ID | NXW-PUB-AI-USE-AND-LIMITATIONS |
| Version | 1.0 |
| Issue Date | 2026-01-01 |
| Next Review | 2027-01-01 |
| Owner | Chief Information Security Officer (CISO), in coordination with the Data Protection Officer (DPO) |
| Classification | Public |
| Applies to | The Aram platform in all deployed modalities — text, voice, and video |
1. Purpose and Scope
This statement describes how Nexwift's Aram platform uses artificial intelligence (AI), the inherent limitations of AI-generated output, and the respective responsibilities of Nexwift and the customer organisation (Data Controller) with respect to AI content across text, voice, and video channels.
It is a public, customer-facing statement intended for prospective and current customers, their compliance teams, and end beneficiaries of the customer's services. It does not replace the Master Service Agreement, the Data Processing Agreement, the Service Level Agreement, or any Acceptable Use Policy, all of which continue to govern the commercial and legal relationship between Nexwift and the customer.
2. Inherent Limitations of AI Output
AI systems, including those used within Aram, are probabilistic. They produce responses on the basis of statistical patterns and available context, not verified fact. Customers and beneficiaries should assume that AI-generated output may:
- Contain factual inaccuracies or fabricated statements (commonly referred to as "hallucinations").
- Reflect information that is outdated relative to the current state of the customer's knowledge base, catalogue, pricing, policies, regulations, or the real world.
- Fall outside the intended scope of the deployed use case, particularly where the beneficiary steers the conversation towards adjacent or unrelated topics.
- Vary in phrasing, tone, or detail between otherwise similar interactions.
- Be affected by upstream provider changes, model updates, and transient service conditions.
- Reflect statistical bias present in underlying training data, and produce outputs that may be unfair, non-representative, or otherwise problematic in specific demographic, linguistic, cultural, or contextual circumstances. Nexwift makes no representation that AI output is free of bias.
- Vary in accuracy across languages, dialects, and registers. Support for Modern Standard Arabic (MSA), Gulf and other regional Arabic dialects, code-switched Arabic-English input, transliteration, and domain-specific terminology is provided on a best-effort basis and is not warranted to any specific accuracy threshold.
- Be susceptible to adversarial input, including prompt injection, jailbreak attempts, and social-engineering patterns embedded in beneficiary messages or retrieved content. The safety and scope controls listed in Section 4 are applied on a best-effort basis and cannot be guaranteed to defeat every attack.
AI output produced by Aram is informational and advisory only. It is not a substitute for human judgement, professional advice, or authoritative source data.
3. Not Professional Advice; Not an Emergency Service
AI-generated content produced by Aram must not be relied upon as, and does not constitute:
- Medical, clinical, pharmaceutical, or public-health advice or diagnosis.
- Legal advice, legal opinion, or a substitute for consultation with a qualified lawyer.
- Financial, investment, tax, or accounting advice.
- Engineering, safety-critical, or other regulated professional advice.
AI voice agents provided through Aram do not constitute an emergency service. They are not a replacement for emergency numbers, medical services, law-enforcement services, crisis lines, or any other emergency response capability. The customer is responsible for configuring appropriate fallback behaviour — including but not limited to redirecting beneficiaries to the correct emergency number, providing hand-off to a human operator, and displaying or reading a suitable notice — for any deployment where a beneficiary may reasonably attempt to reach an emergency service.
Aram is not a medical device. It is not intended for the diagnosis, cure, mitigation, treatment, or prevention of any disease or health condition, and it has not been evaluated or approved by any medicines, medical-device, or health regulator in any jurisdiction. The customer must not deploy Aram in a manner that would cause it to function as, or be represented as, a regulated medical device or diagnostic aid.
4. Safety Controls Available to the Customer
Aram provides the following controls, which the customer is responsible for configuring appropriately for its use case and risk profile:
| Control | Description |
|---|---|
| Scope restriction | System-prompt-level constraints defining the topics the agent may address and the topics it must redirect. |
| Sensitive-topic handling | Configurable redirection for topics such as politics, religion, legal/medical/financial advice, and harm-related content. |
| Prompt-injection defences | Separation of system instructions from user input and refusal to follow instructions embedded in retrieved documents or beneficiary content. |
| Human hand-off | The ability for the agent to hand the conversation to a human operator, in real time, through the supervision dashboard. |
| Kill-switch | The ability for authorised customer staff to stop AI responses on a conversation, a channel, or the entire tenant. |
| Approval-before-publication | For public-channel replies (e.g., replies to public comments and mentions), staff review before publication, unless the customer expressly waives this in writing. |
| Audit trail | Logging of inputs, outputs, retrieval references, and guardrail triggers, retained per the customer's configuration and Data Processing Agreement. |
For high-risk domains — including any domain touching health, safety, legal rights, financial exposure, or vulnerable individuals — the customer must configure scope restriction, sensitive-topic handling, human hand-off, and staff-review controls conservatively, and must maintain the kill-switch as an operational safeguard.
5. Customer Responsibilities
The customer, acting as Data Controller, is responsible for:
- Configuring the agent, its persona, its scope restrictions, its sensitive-topic behaviour, and its hand-off rules.
- Providing accurate, current, complete, and lawfully-obtained knowledge-base content, and maintaining that content as the underlying facts change.
- Reviewing AI-generated content — either before publication (approval workflow) or after publication (audit and correction), as configured — and correcting or retracting any content that is inaccurate, unlawful, misleading, or off-scope.
- Any decision affecting a beneficiary that is taken on the basis of AI output, including but not limited to service delivery, eligibility, pricing, prioritisation, or referral.
- Informing beneficiaries, in the customer's own privacy notice and channel-specific disclosures, that AI is used, what categories of data are processed, and how the beneficiary may request human assistance.
- For voice and video channels: obtaining any consent required under applicable law for recording, transcription, and analysis, and for the beneficiary interacting with an AI system rather than a human. Recording and transcript retention are optional and customer-configurable; the customer is responsible for aligning them with its consent basis.
6. Data Ownership and Handling
The customer owns its customer data, agent configurations, knowledge-base content, conversation transcripts, voice and video recordings (where enabled), and generated summaries. Nexwift owns the Aram platform, its models, and aggregated telemetry that does not identify individuals.
Only the minimum data required to generate a response is transmitted to AI inference provider(s). Logging and telemetry exclude personal data by default.
Audit trails of AI interactions — including inputs, outputs, retrieval references, and guardrail triggers — are retained per the customer's configuration and the schedule set out in the Data Processing Agreement.
7. Model, Provider, and Configuration Updates
Nexwift may update the AI inference provider(s), models, model versions, prompts, guardrails, retrieval pipelines, and safety configurations used within Aram, in order to improve safety, quality, accuracy, cost-efficiency, and compliance. Where a change is expected to materially affect the customer's use of the service, Nexwift will notify the customer in advance where feasible.
Emergency changes made in response to a safety, security, or continuity concern may be applied as soon as practicable, with notification following without undue delay.
8. No Warranty; Limitation of Liability
To the maximum extent permitted by applicable law, Nexwift provides AI-generated output on an "as-is" basis and makes no warranty, express or implied, that any AI-generated output is accurate, complete, current, non-infringing, non-defamatory, free of bias, or fit for any particular purpose.
Nexwift is not liable for any damages — direct, indirect, incidental, consequential, or otherwise — arising from:
- Over-reliance on AI-generated output by the customer, its staff, its agents, or any beneficiary.
- AI-generated content that the customer has published, transmitted, or otherwise acted upon.
- Third-party platform outages or degradations affecting AI inference provider(s), messaging channel platform(s), telephony provider(s), or WebRTC/media infrastructure provider(s).
- Force majeure events.
Nexwift's aggregate liability is capped as set out in the Master Service Agreement. Service credits, where applicable under the Service Level Agreement, are the customer's sole financial remedy for availability shortfalls, without prejudice to termination rights for sustained material breach.
9. Governing Law and Jurisdiction
This statement is governed by the laws of the Kingdom of Saudi Arabia. Any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the competent courts and authorities of the Kingdom of Saudi Arabia.
10. Changes to This Statement
Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.
11. Contact
| Purpose | Contact |
|---|---|
| Data protection questions and requests | info@nexwift.com (attn: Data Protection Officer) |
| Security matters | info@nexwift.com (attn: Chief Information Security Officer) |
| Trust Center and general enquiries | info@nexwift.com |