wayworks.space Sign in

view / AI governance

Sign in Request early access

AI governanceMYNA, governed

What the model does. What it never decides.

wayworks is an AI-native product, which places obligations on us and on the organisations that deploy it. This page states what those are, where we sit in the EU AI Act's scheme, and the line we hold between a system that drafts and a person who decides.

Last reviewed 13 September 2026

The rule we build to

A model drafts. A person decides.

There is no ISO standard for "AI-native", and the phrase is used to mean almost anything. Here it means one specific thing: intelligence is a layer with governance attached, rather than a model bolted onto a database.

  • You are told when it is AI

    Article 50 of the EU AI Act has applied since 2 August 2026 and requires that people know when they are interacting with an AI system. Assistant answers are identified as such. We do not dress a model up as a colleague.

  • It works inside existing permissions

    An agent holds named capabilities and a list of people it may act as. It cannot read what the person behind it could not read, and it cannot grant itself more.

  • No solely automated decisions about people

    The product is not built to make final decisions about hiring, pay, discipline or termination without a person. It drafts, routes, finds and explains. GDPR Article 22 exists for a reason and we do not design around it.

  • Everything is attributed

    Which agent ran what, on whose behalf, and what changed — in an append-only log, beside the work.

  • Your data is not training data

    confirm: customer data is not used to train models, and name any exception

Where this sits in the AI Act

Said precisely, because it matters.

The EU AI Act classifies by use, not by technology, so the honest answer depends on what a customer switches on. Here is the reasoning rather than a reassurance.

  • Nothing here is a prohibited practice

    The prohibitions in Article 5 — social scoring, emotion inference at work, manipulative techniques — have applied since 2 February 2025. The product does none of them, and emotion inference in the workplace in particular is something we will not build.

  • Transparency obligations apply to us now

    Article 50 has applied since 2 August 2026, alongside the AI Office's enforcement powers. Systems already on the market have until 2 December 2026 for Article 50(2).

  • Some deployments will be high-risk

    Annex III names employment, worker management and access to essential services. A customer using the recruiting or workforce modules to influence hiring or promotion is deploying in a high-risk area. Those obligations apply from 2 December 2027 for standalone systems, and 2 August 2028 where AI is embedded in an already-regulated product.

  • What that means in practice

    Where a deployment is high-risk, the customer carries deployer obligations — human oversight, input data governance, monitoring, record-keeping — and we carry the provider-side duty to give them what they need to meet them. We would rather say this plainly before a contract than discover it during one.

  • AI literacy

    Article 4 has required since February 2025 that staff operating these systems have sufficient understanding of them. It is a duty on your organisation, and we will support it.

classified by use,
not by technology

The models

Which ones, and what they can reach.

  • Providers

    model providers used, and the regions they run in — also listed on the subprocessor page.

  • Retention by the provider

    confirm zero-retention or abuse-monitoring terms with each provider

  • Your own assistant

    When you add wayworks to Claude or ChatGPT as a connector, that assistant is your relationship, under its own terms, and what it retains is governed by them. We supply a bounded endpoint; we do not control the model at the other end. Worth knowing before a security review asks.

  • Evaluation

    how model changes are evaluated before release

If something goes wrong

Tell us. We would rather know.

If the system produced something wrong, unfair, or that looks like a decision it should not have made on its own, write to hello@debuginit.com. Serious incidents are logged, investigated, and reported where reporting is required. We would rather hear it from you than read it later.

— intelligence without governance is just automation with risk