
ARTIFICIAL INTELLIGENCE (AI) POLICY & DISCLOSURES
Last Updated: July 22, 2026
Generative AI (Reactive)
Agentic AI (Proactive)
Physical & Embodied AI (Active)
AI integrates advanced technology to optimize services and elevate your digital experience. This document covers our Artificial Intelligence (AI) practices, your data privacy rights under global frameworks (including GDPR and CCPA) and our protocols for automated website access.
Generative AI (Reactive)
- How it works: You provide a strict prompt and the AI produces a single, one-off output (e.g., writing an essay or summarizing an article).
- The limit: It stops immediately after completing the task and requires you to write a new prompt for the next step.
- Transparency in Our Use of AI
To ensure full disclosure, QZZON Group outlines the following uses of AI technologies across our digital platforms:
- Interactive Support: We may utilize AI-powered virtual assistants or chatbots to handle initial customer inquiries and provide immediate support.
- Content and Media: Some informational, educational, or visual content on our platforms may be generated or optimized with the assistance of AI tools. All such content undergoes internal human review for accuracy and quality.
- Service Optimization: We use analytical AI tools to study website traffic patterns and user preferences to continuously improve our digital infrastructure.
- GDPR Compliance & European Union Disclosures (EU Residents)
In accordance with the EU General Data Protection Regulation (GDPR) and the EU AI Act, QZZON Group ensures the following rights and protections:
- Legal Basis for Processing: Any personal data processed by our AI systems is based on your explicit consent or our legitimate interest in providing efficient customer support.
- Right to Human Intervention: We do not use fully automated decision making or profiling that produces legal or similarly significant effects on you. You maintain the right to request that a human representative from QZZON Group review any AI-driven interaction or decision.
- Data Subject Rights: You retain the full right to access, rectify, restrict, or delete any personal data that has been inputted into or processed by our AI integrations.
- CCPA/CPRA Compliance & California Disclosures (California Residents)
In accordance with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), QZZON Group discloses the following:
- No “Sale” or “Sharing” of AI Data: QZZON Group does not sell your personal information, nor do we share your AI chat histories, inputs, or prompts with third-party AI companies to train public models.
- Right to Opt-Out of Automated Decision-Making: You have the right to request information regarding and opt-out of, our use of automated decision-making technology and profiling.
- Limitation of Sensitive Data: Any sensitive personal information you provide to our AI tools is strictly used to fulfil the immediate request (e.g., answering a customer service query) and is not retained for secondary purposes.
- Automated Data Scraping & AI Training Restrictions (Opt-Out Notice)
All intellectual property, proprietary data, text, layouts and imagery on QZZON Group websites are the exclusive property of QZZON Group.
- Strict Prohibition: We explicitly prohibit the use of automated scrapers, web crawlers, data-mining tools, or bots to harvest content from our website for the purpose of training machine learning or AI models.
- Legal Reservation of Rights: This clause serves as an express reservation of rights and an explicit opt-out of text and data mining under Article 4 of the EU Digital Single Market Directive and all corresponding global copyright frameworks.
- Enforcement: We reserve the right to deploy technical blocks (such as robots.txt modifications and IP blocking) and pursue legal remedies against any entity violating these terms.
Further information can be found on the Privacy Statement.
Agentic AI Governance & Usage Policy
Agentic AI (Proactive)
- How it works: You assign a high-level goal (e.g., “Research and book the cheapest flight to Tokyo under $400”).
- The limit: The AI breaks the goal into steps, uses tools, compares options and executes the actions on your behalf without requiring your approval at every stage.
1. Purpose & Scope
This policy outlines how QZZON Group (“we,” “our,” or “us”) deploys and governs autonomous AI agents on our website and digital platforms. This policy applies to all users, clients and visitors interacting with our automated systems.
2. Core Pillars of Our AI Governance
Pillar 1: Defined Risk Bounds & Limits
Our AI agents are built with strict operational boundaries.
- Authorized Capabilities: Our agents are authorized only to perform specific tasks, such as (e.g., answering customer inquiries, scheduling appointments, routing support tickets).
- Prohibited Actions: Our agents are strictly forbidden from modifying user account security settings, processing unauthorized financial transactions, or accessing sensitive personal data without explicit user consent.
- System Limits: If a request falls outside an agent’s technical boundaries or requires complex contextual judgement, the agent will immediately pause the operation.
Pillar 2: Meaningful Human Oversight (Human-in-the-Loop)
We do not allow AI agents to operate entirely without supervision.
- Escalation Thresholds: Any task involving high consequence decisions including (e.g., legal agreements, final billing adjustments, data deletion) requires mandatory human review.
- Human Intervention: Users can request a transfer to a human representative at any point during an AI interaction by (e.g., typing “operator”, clicking the “Talk to a Human” button).
- Accountability: QZZON Group retains ultimate responsibility for the actions and outputs generated by our deployed AI agents.
Pillar 3: Technical Control, Logging & Safety
We maintain rigorous technical guardrails to ensure our AI systems remain secure, reliable and predictable.
- Continuous Logging: Every action, decision and output generated by our AI agents is recorded in a secure audit trail.
- Anomaly Detection: We use automated monitoring systems to detect unexpected agent behaviours or system errors, allowing us to safely shut down or reset the agent if a failure occurs.
- Data Security: Our agents handle user data in strict compliance with our Privacy Statement (Policy) and relevant global data protection regulations.
Pillar 4: Transparency & User Empowerment
We believe users have a right to know when they are interacting with autonomous systems.
- Clear Disclosures: We provide clear visual cues and notifications on our user interface to identify when a system or chat interaction is powered by an AI agent.
- User Instructions: Where necessary, we provide simple instructions to help users understand how to interact effectively and safely with our autonomous tools.
Physical & Embodied AI Governance & Usage Policy
Physical & Embodied AI (Active)
- How it works: You embed digital intelligence into a physical structure, allowing the AI to continuously sense its environment, plan adjustments and execute physical actions in the real world (e.g., a humanoid robot sorting inventory or a self-driving car navigating a street).
- The limit: It operates in a continuous, physical loop that cannot simply be paused by pressing “enter,” requiring strict safety overrides, hardware redundancies and human-in-the-loop kill switches to prevent real-world harm if a sensor or model fails.
1. Objective & Scope
This Policy establishes the governance, safety frameworks and operational requirements for developing, deploying and managing Physical and Embodied AI technologies.
Regulatory frameworks for Physical and Embodied AI span multiple interlocking regions, product safety laws, cybersecurity mandates and sector-specific codes. Because embodied AI operates directly in the physical world, it is regulated based on its functional application and hardware safety rather than just its code.
Scope
- Embodied AI Systems: Digital intelligence embedded in physical structures (e.g., humanoid robots, autonomous mobile robots, smart manufacturing systems).
- Autonomous Transit: Self-driving vehicles, drones and automated guided vehicles (AGVs).
- Cyber-Physical Systems: Connected infrastructure and machinery that perceive, process and act upon the real world.
- Applicability: Applies to all employees, contractors, vendors and third-party partners interacting with these systems.
2. Core Governance Principles
Human Oversight & Intervention (Human-in-the-Loop)
- Ultimate Authority: Human operators must retain the ability to override, halt, or safely shut down any physical AI system at any moment.
- Clear Responsibility: Final accountability for the actions and outcomes of physical AI systems rests with the designated human operators and business owners.
Safety & Physical Harm Prevention
- Zero Harm Harm Minimization: Systems must prioritize human physical safety above operational efficiency, speed, or financial optimization.
- Risk Boundaries: Systems must operate within strictly defined, deterministic safety envelopes to prevent unauthorized or dangerous physical movements.
Accountability & Traceability
- Continuous Logging: Systems must maintain comprehensive, tamper-evident logs of all sensory inputs, internal decisions and physical outputs.
- Incident Attribution: Logs must provide sufficient data to perform root-cause analysis in the event of hardware failure, property damage, or physical injury.
3. Operational Requirements
Perception & Data Security
- Real-World Sensing: Systems must continuously validate environmental data (computer vision, LiDAR, haptics) to ensure high-fidelity situational awareness.
- Edge Processing: Where feasible, sensor data should be processed locally on the edge to minimize latency and protect privacy.
- Environmental Privacy: Systems operating in public or shared spaces must obscure or anonymize personally identifiable information (PII), such as faces or license plates, unless explicitly authorized.
Closed-Loop Action Limits
- Fail-Safe Defaults: If a sensor fails or network connectivity drops, the physical AI must default to a predictable, zero-energy safe state (e.g., dynamic braking or locking joints).
- Predictive Collision Avoidance: Actuators must utilize independent safety microcontrollers to halt motion if a collision risk is detected, bypassing the main AI processing unit if necessary.
4. Risk Validation & Testing
Sim-to-Real (S2R) Validation
- Virtual Prototyping: All physical AI models and control policies must undergo extensive simulation testing prior to physical deployment.
- Edge-Case Stressing: Simulations must evaluate system performance under extreme conditions, including sensor degradation, unexpected obstacles and adversarial environments.
- Transfer Thresholds: A model must achieve verified safety benchmarks in simulation before receiving authorization for physical hardware testing.
Hardware-in-the-Loop (HIL) Testing
- Physical Verification: Control loops must be validated using physical hardware sub-components linked to simulated environments.
- Redundancy Audits: Regular mechanical and electrical stress tests must ensure that physical backup systems (e.g., mechanical brakes, secondary power supplies) deploy correctly during primary AI failures.
5. Compliance & Enforcement
Regular Audits
- Physical AI assets must undergo mandatory bi-annual hardware inspections and software compliance audits.
- AI training datasets and reward functions must be reviewed to prevent emergent, unsafe physical behaviors.
Non-Compliance
- Any unauthorized modification of physical AI parameters, bypassing of safety overrides, or failure to report a physical anomaly will result in immediate system deactivation and disciplinary action.
Frameworks
1. European Union (EU) Frameworks
The EU utilizes an interconnected “umbrella” regulatory strategy, meaning a single physical robot or automated system must comply with multiple overlapping laws simultaneously.
The EU AI Act (Regulation (EU) 2024/1689)
- Risk Categorization: Physical AI used in industrial machinery, medical devices, or public transit is heavily classified under High-Risk AI Systems.
- Explicit Logging: Systems must feature explicit logging, human oversight mechanisms and certified robustness before entering the market.
The Machinery Regulation (EU) 2023/1230
- Dual Compliance: Works in tandem with the AI Act.
- Physical Safety: Mandates physical risk assessments covering mechanical, electrical and software failures across the machine’s entire lifecycle. Requires a formal CE marking to prove safety conformity.
The Cyber Resilience Act (CRA)
- Connected Hardware: Targets all physical AI systems functioning as IoT or internet-connected products.
- Mandatory Reporting: Physically active AI must have continuous cybersecurity patch pathways.
The Revised Product Liability Directive (Directive (EU) 2024/2853)
- Strict Liability: Legally categorizes AI and software as physical “products”.
- Shifted Burden: Eases the burden of proof for individuals injured by complex physical automation, placing liability on the manufacturers, importers and distributors if a system malfunctions.
2. United States Frameworks
The US approaches physical AI through sector specific agency mandates combined with an emphasis on protecting physical infrastructure.
Executive Order 14409: Advanced AI Innovation & Security
- Infrastructure Focus: Prioritizes protecting national security and critical physical infrastructure (like power grids and utilities) from autonomous threats.
- Voluntary Testing: Establishes a voluntary 30 day pre-release framework for “frontier models” powering automated networks, introducing the Gold Eagle Initiative to clear critical cybersecurity vulnerabilities.
Sector-Specific Agency Regulations
- Autonomous Transit: Governed by the National Highway Traffic Safety Administration (NHTSA) through its Automated Vehicle (AV) Framework, which establishes rules for robotaxis and vehicles operating without physical steering wheels or human controls.
- Workplace Safety: Supervised by OSHA, managing safety envelopes, proximity sensors and emergency stop mechanics for industrial cobots (collaborative robots) interacting with workers.
- Medical Robotics: Governed strictly by the Food and Drug Administration (FDA) under medical device validation laws
3. International Safety & Technical Standards
When local legislation is absent, courts and global compliance officers default to established, binding engineering standards.
- ISO 26262 (Functional Safety): The ultimate standard for identifying, mitigating and validating safety risks in the electrical and electronic systems of physical transit.
- ISO 21434 (Automotive Cybersecurity): Mandates secure development lifecycles to protect connected mechanical assets from kinetic hacking threats.
- ISO 10218 & ISO/TS 15066: Direct safety standards specifically written for industrial robots and collaborative work environments, outlining maximum allowable physical impact force limits for machines
Cross-Border Policy Addendum
Transatlantic Safety & Compliance Alignment
This addendum establishes the operational framework for resolving variances between European Union (EU) and United States (US) regulations governing Physical and Embodied AI assets. Where an AI system is deployed across both jurisdictions, or developed in one region for deployment in another, the stricter of the overlapping standards shall apply to the baseline hardware and software architecture.
1. Technical Documentation & Risk Assessment Harmonization
- Unified Technical File: Every physical AI asset must possess a centralized technical dossier that concurrently satisfies the compliance documentation requirements of Article 11 of the EU AI Act and the risk mitigation reporting framework under the US Executive Order on Advanced AI Innovation and Security.
- Pre-Deployment Safety Testing: Prior to physical deployment in any market, models must undergo safety testing that validates both the EU Machinery Regulation essential health and safety requirements (EHSR) and the adversarial testing guidelines set by US agencies like NHTSA or NIST.
2. Lifecycle Cybersecurity & Patch Management
- Vulnerability Disclosure: In accordance with the EU Cyber Resilience Act (CRA), all internet-connected physical AI assets must feature continuous software bill of materials (SBOM) tracking. Critical vulnerabilities that could lead to unauthorized kinetic control or physical malfunction must be documented and patched within 24 hours of discovery.
- Infrastructure Protection: For assets deployed within US critical infrastructure or corporate environments, patch deployment workflows must align with federal security directives, ensuring that over-the-air (OTA) updates do not inadvertently override established physical safety parameters or trigger emergency-stop failures.
3. Operational Safety Envelopes & Liability Alignment
- Human Oversight (Human-in-the-Loop): Systems must be designed with physical kill-switches and operational overrides that comply with both OSHA industrial safety envelopes and the human-oversight mandates of the EU AI Act.
- Strict Product Liability Readiness: To manage the strict liability provisions under the Revised EU Product Liability Directive, all cross-border systems must maintain an unalterable, continuous digital ledger (black box) recording sensor inputs, localized edge decisions and actuator outputs to facilitate rapid root-cause analysis in the event of property damage or physical injury.
Regional Adjustments & Local Law
This information applies globally, but your local statutory rights always take precedence.
Policy Updates
As AI technology and international governance frameworks evolve, we will periodically update this Policy. Any changes will be reflected on this page with an updated revision date.
For questions regarding our AI governance practices, please contact us.
- Email: a3priority@gmail.com

© 1999 – 2026 QZZON Group
Legal & Resources
Privacy Statement
Refund & Warranty Policy
Terms of Service
Do Not Sell or Share My Personal Information