Virtually Myself

Responsible AI and Governance Statement

Last updated: August 2026

Virtually Myself® is an Australian-built, human-guided AI platform that helps experts and organisations capture, protect and apply their knowledge and intellectual property.

We recognise that responsible AI requires more than technical capability. It requires clear accountability, appropriate controls, informed human judgement and ongoing review throughout the life of an AI system.

This statement applies to the Virtually Myself® platform and to this website.

What we commit to in every case

The sections that follow describe controls that vary with the use case. These do not. They apply to every customer, on every plan.

  • Vault data is hosted in Australia, supporting Australian data residency and sovereignty requirements.
  • Vault content is excluded from public AI model training. Your material is used to provide the Virtually Myself® experience within your authorised environment and according to the applicable account terms.
  • Your source material and intellectual property remain yours.
  • Customer knowledge is held within private Vault environments, with access determined by the permissions attached to the user and environment.
  • Virtually Myself® identifies the source material supporting a response, so users can check the original context before relying on it.
  • You remain responsible for reviewing and approving outputs before you use them. Reviewing that work is not part of platform access, and we do not design workflows that remove human judgement. If your plan or agreement includes editorial or quality-control support from our team, that will be stated in it.

Further detail on each of these is set out on our security and data sovereignty page.

Accountability

Accountability for AI governance sits with our founders, Alex Hagan and Nina Christian. They are responsible for approving new AI capabilities, overseeing risk assessments and reviewing this statement.

Our governance direction

Our AI governance programme is being developed with reference to ISO/IEC 42001, the international standard for artificial intelligence management systems.

We are undertaking training and progressively developing the policies, responsibilities, risk processes, documentation and review practices associated with that standard.

Virtually Myself® does not currently hold ISO/IEC 42001 certification. References to the standard describe the direction and structure of our governance work. They do not constitute a claim of certification, formal compliance or independent assurance.

Our principles

Human responsibility

Virtually Myself® supports human judgement rather than replacing it. The person using the platform, and the organisation they work for, remain responsible for reviewing, approving and acting on AI-generated or AI-assisted outputs.

To be plain about where that line sits: we build the tools and the review points into the workflow, but checking the work produced in them is not part of platform access. Reviewing outputs before they are used is the customer’s responsibility, unless a plan or agreement expressly says otherwise.

We design workflows with human review points appropriate to the purpose, audience and level of risk. Higher-risk applications may require source verification, specialist review, formal approval or escalation to an authorised person.

Defined purpose

AI systems should have a clear intended purpose, user group and operating boundary.

For custom and organisational applications, we work with clients to define:

  • The problem being addressed
  • The intended users
  • The information the system may access
  • The tasks it may support
  • The decisions that remain with people
  • The circumstances requiring review or escalation
  • The measures used to assess performance

Risk-based design

The level of governance should reflect the context and consequences of use.

We consider factors including:

  • The sensitivity of the information involved
  • The potential impact of inaccurate or incomplete outputs
  • The people who may be affected
  • Applicable legal, regulatory and contractual obligations
  • The need for professional or specialist judgement
  • The possibility of bias, misuse or unintended use
  • The suitability of external AI models and service providers
  • Requirements for records, traceability and review

Higher-risk use cases require stronger controls and a more detailed assessment before implementation.

Privacy and data governance

We consider privacy, access and appropriate information handling throughout system design and operation.

Beyond the commitments set out above, controls appropriate to a particular use case may include:

  • Role-based access
  • Separation of personal, shared and organisational knowledge
  • Defined source collections
  • Information retention and deletion requirements
  • Restrictions on sensitive or regulated information
  • Review of third-party processing arrangements

Customers remain responsible for confirming that their use of Virtually Myself® meets their own privacy, legal, regulatory and contractual obligations. Our Privacy Policy sets out how we handle personal information.

Transparency

Users should understand when they are interacting with an AI-supported system and the purpose for which it has been configured.

Where appropriate, we provide information about:

  • The intended purpose of the system
  • The sources or knowledge collections it can use
  • Relevant limitations
  • Human review requirements
  • The use of external AI models
  • Escalation or contact pathways

Source references help users check the original context and assess the response.

Security and data sovereignty

Virtually Myself® is Australian owned, Australian managed and Australian hosted.

We consider the security and data-handling implications of our infrastructure, external technology providers and customer configurations. Organisational and sensitive applications may require a more detailed security, privacy and procurement review before implementation.

Australian hosting does not remove every privacy or security risk. Each use case should be assessed according to the information involved, the technology selected and the client’s obligations.

Model and supplier assessment

Virtually Myself® uses a vendor-agnostic approach, allowing different AI models and supporting technologies to be selected for different tasks. The external models we use are named in our Terms of Service.

We consider factors such as:

  • Model capability and suitability
  • Privacy and data-processing terms
  • Data location and transfer
  • Security practices
  • Training and retention policies
  • Reliability and known limitations
  • Availability of suitable controls
  • Changes to provider terms or model behaviour

Model selection may change as technologies and requirements develop.

Accuracy and appropriate reliance

AI systems can misunderstand source material, omit context and produce inaccurate information.

Users should verify important facts, claims, quotations, names, dates and recommendations before relying on an output. Legal, medical, financial, regulatory, clinical and other higher-consequence work requires review by appropriately qualified people.

We support source-aware workflows and human review to reduce risk. We do not represent AI-generated outputs as infallible or suitable for unreviewed professional decisions.

Fairness and potential bias

AI outputs may contain bias originating from models, source material, system design or user instructions.

Where relevant to the use case, we consider:

  • Who may be affected by the system
  • Whether the source material is sufficiently representative
  • Whether outputs create unfair or inappropriate outcomes
  • Whether testing should include different users, situations or perspectives
  • Whether specialist, cultural or community advice is required
  • How concerns can be raised and reviewed

Monitoring and improvement

AI governance continues after a system is released.

We use testing, customer feedback, incident review and changes in technology or regulation to inform ongoing improvements. Depending on the system, review may include:

  • Output quality
  • Retrieval accuracy
  • Source relevance
  • User feedback
  • Unexpected behaviour
  • Access and permission issues
  • Changes to models or suppliers
  • Emerging risks
  • Continued suitability for the intended purpose

Custom workflows

Virtually Myself® can capture a client’s proprietary processes and build custom workflows around their knowledge, standards, decision points and approval requirements.

For custom workflows, governance may include:

  • Defined scope and intended users
  • Approved knowledge sources
  • Access permissions
  • Required inputs
  • Review criteria
  • Human approval points
  • Escalation pathways
  • Restrictions on use
  • Testing with realistic scenarios
  • Documented responsibilities
  • Monitoring after implementation

The appropriate controls depend on the use case and the possible consequences of error or misuse.

Customer responsibilities

Responsible AI is a shared responsibility.

Customers are responsible for:

  • Providing information they have the right to use
  • Applying suitable permissions
  • Reviewing outputs before use
  • Protecting account access
  • Complying with applicable laws and professional obligations
  • Assessing the suitability of the platform for sensitive or regulated information
  • Informing authorised users about relevant requirements
  • Raising suspected errors, security issues or inappropriate behaviour

Governance enquiries

Questions about our AI governance approach, and reports of suspected errors, security issues or inappropriate behaviour, can be directed to nina@virtuallymyself.com, or through our contact page.