VoidLens AI Disclosure · v0.3 · last updated 2026-07-31 · draft
AI Disclosure
AI is the product — and it is governed
VoidLens exists to let you run AI agents on real work safely. AI is not a hidden ingredient here; it is the thing you are buying. What makes us different is that every AI action on the instrumented paths is recorded before it happens, gated against a set of immutable red lines, and earns its autonomy through a forty-eight-hour shadow window. You supervise; you don't prompt.
1. How the product uses AI
- Agents act under governance. Each agent has a capability allowlist, a budget, and a supervision tier. Actions outside that allowlist are refused at the capability gate on the instrumented paths, and every attempt is logged.
- Audit-before-effect on the instrumented paths. An agent logs its intended action and clears the safety gate before the gated action happens.
- Human-in-the-loop where it matters. On the instrumented paths, the default configuration holds actions touching money, customers, contracts, or sensitive data for your approval before they take effect. This is a configurable default, not a guarantee that every possible path is intercepted: you set the capability allowlists (see Terms, Section 7), and the fully enforced policy plane that would close the gap between the two is Phase 1 on our published roadmap and is not shipped — see Section 7 below. The red lines in the next bullet are the separate, non-configurable layer.
- Immutable red lines. Moving money, permanent deletions, unapproved external submissions, security-permission changes, and credential handling are forbidden by policy system-wide, and are not configurable by you or by an agent. Be clear on what that buys today: on the instrumented paths the capability gate refuses the action and logs the attempt; away from those paths the red line is a policy commitment, not a mechanism we can promise will stop the action. The policy plane that closes that gap is Phase 1 on our roadmap and has not shipped, and nothing on this site is described as "enforced" until it does.
2. Which models we use, and where they sit
For transparency, here are the models involved and where each sits relative to your data:
- Your chosen provider (primary), via your key. The reasoning runs on the model provider whose API key you supply — for example Anthropic's Claude. Your prompts and outputs flow between your infrastructure and that provider under your agreement with them. VoidLens is not in that path.
- A local fallback brain, on your hardware. If your primary provider is unavailable, the runtime can fall back to local models you run yourself (open-weight models via an Ollama-class runtime) — today one shared local model; larger deployments are planned to support standalone local models per division (a roadmap enterprise configuration). No prompt leaves your infrastructure on that path.
- An independent reviewer, in our own operations. Inside our development and governance — not in your data path — we use a different, independent model to adversarially review our own work. It never sees your data; it reviews VoidLens.
3. Bring your own keys (BYOK)
You connect your own model-provider API key. Your prompts and the model's outputs flow between your infrastructure and your provider under your agreement with them, including their AI terms. VoidLens governs and audits these actions; it is not the model and does not sit in the inference path.
4. We don't train on your data
VoidLens does not use your data — operational data, prompts, outputs, audit logs, or account data — to train, fine-tune, or improve any AI model. Whether your chosen provider may use your prompts is governed by your agreement with that provider, which you control. See the Privacy Policy for detail.
5. Automated processing & your control
VoidLens can take automated actions on your behalf within the envelope you configure — on the instrumented paths the gate refuses and logs actions outside it — and you can pause or stop an agent at any time through the controls the Runtime exposes. Because the Runtime governs the paths it instruments, stopping an agent stops the work that runs through those paths; it is not a representation that we can interrupt activity the Runtime does not observe. For higher-stakes work the system proposes and you decide. You are responsible for the allowlists you set and for reviewing the proposals surfaced to you.
6. Accuracy & limitations
AI can be wrong, and language models can produce confident errors. That is precisely why everything here is gated and audited — the safety architecture assumes the model can err and is built to contain it. VoidLens does not guarantee any AI output is correct; the audit trail exists so you can verify, not so you can stop checking entirely on high-stakes calls.
7. Transparency, human oversight & the EU AI Act
The Act is in force. We do not call it “emerging.” Regulation (EU) 2024/1689 — the EU AI Act — entered into force on 1 August 2024 and applies in stages set by Article 113. As enacted, those stages are: the prohibited-practice rules (Article 5) and the AI-literacy duty (Article 4) from 2 February 2025; the general-purpose-model chapter and most of the penalty regime from 2 August 2025; the Article 50 transparency duties and the Annex III high-risk regime from 2 August 2026; and high-risk AI embedded in regulated products (Article 6(1)) from 2 August 2027. The EU sets that timetable and can amend it. We publish it as enacted rather than as a trend — but the dates that bind you are the ones in the Official Journal on the day you read this, and you should confirm them with your own counsel rather than with a vendor's website.
What the software actually does. The VoidLens runtime is deterministic. On the instrumented paths it records an intended action before it happens, applies the capability limits you configure, and refuses what falls outside them — with the fully enforced policy plane on the published roadmap and not shipped today. The runtime contains no model of its own: the reasoning runs either on the model provider whose API key you supply or on a local model you run on your own hardware (Section 2). We did not develop those models and we do not supply them to you. What we will not do is tell you on a website how the Act's definitions land on that architecture. Whether the runtime is an “AI system” within Article 3(1), and what role — provider, downstream provider, or deployer — any party occupies under Articles 3, 25 and 26, are legal conclusions on a regime being applied for the first time. We have set the facts out precisely so that your counsel can reach that conclusion on your side and ours can reach it on ours. Nothing on this page is our determination of anyone's status under the Act, including our own.
Your obligations stay yours. If you deploy AI agents on work that falls within Annex III, you are the deployer and the Article 26 duties are yours — including human oversight under Article 14 and the retention, under Article 26(6), of the automatically generated logs contemplated by Article 12. The record VoidLens produces on the instrumented paths is designed to be the kind of evidence duties like those call for. It does not discharge them. Using VoidLens does not make you compliant with the AI Act, the GDPR, or anything else; it does not determine whether your system is high-risk; and note that under Article 25 you can become a provider in your own right — by putting your name or trademark on a high-risk system, by substantially modifying one, or by changing a system's intended purpose so that it becomes high-risk — whatever tooling sits underneath it. We make no representation about your regulatory status, and nothing here is legal advice. Retain your own counsel.
Our own use, stated plainly. We run AI agents inside our own company, under the same supervision architecture we sell, and we hold ourselves to it as a matter of practice rather than because we have concluded that any particular obligation of the Act reaches a US company with no EU establishment. That question is on the list for counsel, along with the rest of this page.
8. AI on this website
Some copy and assets on this marketing site were drafted with AI assistance and reviewed by a human. The system figures shown on the site (agents, audit rows, specs, red lines) are measured from the operating system and published from a snapshot we refresh by hand, with velocity-sensitive counts bucketed rather than exact.
9. Contact
Questions about how AI is used here: contact us. VoidLens · Bloomington, Illinois, USA · voidlens.io.