1. Purpose
Promethean is an accountability substrate for AI decisioning in regulated products. This policy describes the categories of use we will not sign and the conduct that may result in workspace suspension or termination.
2. Prohibited use cases
You may not use Promethean to evidence AI decisions made in any of the following contexts:
- EU AI Act Article 5 prohibited practices. Social scoring by public authorities; subliminal manipulation materially distorting behaviour; exploitation of vulnerabilities of specific groups; untargeted scraping of facial images to build recognition databases; real-time remote biometric identification in publicly accessible spaces for law enforcement (except as narrowly permitted by Art. 5(1)(h)); emotion recognition in the workplace or in education; biometric categorisation inferring sensitive attributes.
- Autonomous weapons systems or AI components intended for lethal targeting decisions.
- Coercive surveillance. AI used to monitor individuals in violation of their human-rights protections under the Charter of Fundamental Rights of the European Union.
- Decisions made without meaningful human oversight where Art. 22 GDPR or AI Act Art. 14 requires it. The reviewer-gate primitive exists for this reason; bypassing it to "evidence" automated decisions in contexts requiring human intervention misuses the substrate.
- Decisions that would otherwise be illegal in the deployment jurisdiction. Promethean's audit chain does not legalise an underlying illegal decision; signing it does not transform it.
2a. EU AI Act Art. 50 + 52 — operator transparency obligations
Promethean's substrate evidences AI decisions; it does not substitute for the operator's own transparency duties. You remain responsible for your obligations as a provider or deployer under AI Act Article 50 (transparency for natural persons interacting with AI systems, including chatbot disclosure and machine-readable marking of synthetic content) and Article 52 (deployer obligations for emotion-recognition, biometric-categorisation, and deepfake systems where permitted).
The substrate's L12 receipt chain captures the spec hash that binds your disclosure language to every decision — so a regulator can verify which disclosure was active over which period — but the operator chooses + ships the disclosure itself.
3. Prohibited conduct
- Reverse engineering the Service or attempting to bypass tier limits, rate limits, or authentication controls.
- Injecting falsified receipts into your L12 chain (post-anchoring, this is detectable and constitutes fabrication of evidence).
- Sharing API keys across legally separate entities to evade tier pricing.
- Creating multiple workspaces or sub-accounts to evade tier limits or pricing structure of a single underlying product.
- Use of the Service in or for the benefit of any person or entity subject to EU, UN, US, or UK sanctions, including parties on the EU consolidated sanctions list, the US OFAC Specially Designated Nationals list, or equivalent.
- Using the Service to send unsolicited bulk communications, to host or distribute malware, or to launch network attacks.
- Impersonating another person or entity, or misrepresenting your affiliation with one.
- Using the Service in any way that violates applicable EU, national, or international law including sanctions and export controls.
4. Enforcement
Suspected breaches should be reported to legal@promethean.software. We may investigate, request information, and — for serious or repeated breaches — suspend or terminate the workspace. Where legally required, we will cooperate with competent authorities.
5. Notice and cure
Except for breaches that are clear-cut prohibited use cases or that pose an immediate risk to third parties or the Service, we will give written notice and a reasonable opportunity to cure before suspending or terminating a workspace.
6. Changes
Material changes to this AUP will be announced by email at least 30 days before they take effect for in-period workspaces.