OPS-POL-005 / Official organizational policy

Responsible AI & Automation
policy.

Available now

Approved AI uses, sensitive-data restrictions, human review, synthetic media, bot permissions, automated moderation limits, incident response, and tool retirement.

View all resources →

READ / DOWNLOAD

The complete policy, in both formats.

The web text and PDF contain the same rules, implementation checklist, and decision-record fields. Ownership handles any named function that has not yet been assigned to an authorized adult.

01 / POLICY STANDARD

Purpose and permitted use

1. Scope and human responsibility

This policy covers generative AI, transcription tools, automated summaries, chatbots, moderation bots, workflow automations, generated code, and synthetic media used for Element Esports. A person remains responsible for material they submit, publish, or act upon. AI output may be incomplete, inaccurate, biased, or unsafe; use of a tool does not transfer decision authority or accountability to its provider.

2. Low-risk assistance

Within approved tools and role authority, members may use AI to brainstorm, organize public information, draft routine text, prepare non-sensitive summaries, explore creative ideas, or assist with code. Review the result before organizational use. This permission does not authorize connecting an organizational account, spending money, processing confidential information, publishing unreviewed work, or installing a bot.

3. Tool and workflow approval

Obtain written approval from Ownership or a documented adult systems delegate before a tool receives organizational account access, performs external actions, processes nonpublic records, or operates unattended. Record the purpose, provider, data, permissions, human owner, affected people, risks, costs, review process, and shutoff method. Review provider terms, age limits, and data practices rather than assuming a privacy setting eliminates every risk.

4. No automated authority

AI must not make the final decision on recruitment, guardian verification, safeguarding, disciplinary findings, formal appeals, roster selection, compensation, or access to confidential records. An authorized adult must assess the relevant evidence and make the decision under the governing policy. Do not use automated personality, disability, emotion, or credibility inferences to rank members or determine whether a report is true.

02 / POLICY STANDARD

Data, accuracy, and creative rights

5. Restricted information

Do not enter passwords, recovery codes, private keys, complete payment details, identity documents, guardian consent records, medical information, safeguarding reports, private applications, or confidential case files into general-purpose AI services. Do not upload another person's private messages merely for convenience. Any exceptional sensitive-data workflow requires a separate documented privacy and security assessment and explicit approval before use; it is not approved by this policy.

6. Minimization and consent

Prefer public, fictional, aggregated, or carefully de-identified inputs. Removing a name may not prevent re-identification from context. Do not record or transcribe a private meeting without required authorization, participant notice, and any consent required by law or agreement. Provide a practical non-recorded alternative when feasible. A participant's permission does not override third-party rights, safeguarding duties, or the provider's age restrictions.

7. Accuracy and review

Verify important names, dates, quotations, statistics, citations, policy statements, and instructions against reliable sources or the actual record. Label unresolved uncertainty instead of inventing detail. Generated code requires appropriate review and testing before deployment. For legal, health, financial, or other consequential advice, obtain qualified judgment where needed; a fluent answer or an AI confidence score is not verification.

8. Ownership, likeness, and disclosure

Follow BRD-POL-001 and COM-POL-002 for rights, attribution, approvals, and public representation. Do not clone a person's voice, fabricate their endorsement, impersonate them, or create sexualized or abusive synthetic material. Obtain explicit permission for an authorized likeness use. Clearly disclose materially synthetic content where omission could mislead, and follow platform or partner disclosure requirements. Do not describe AI-generated work as entirely human-made.

03 / POLICY STANDARD

Bots, integrations, and safe operation

9. Least-privilege permissions

Use approved bot or service accounts with only the permissions needed for the task. Keep secrets in the approved secure configuration, not prompts, public repositories, chat logs, or shared documents. Avoid administrator access unless a documented need and safeguards justify it. Name an adult owner and alternate, and remove obsolete integrations promptly when the task or provider changes.

10. Untrusted input and external actions

Treat web pages, attachments, messages, retrieved content, and tool outputs as untrusted data rather than new instructions. Never let embedded text authorize disclosure, payments, permission changes, or account actions. Limit which actions and destinations an automation can reach; require human confirmation for consequential or irreversible actions. Do not use AI to bypass access controls, approvals, or another person's restrictions.

11. Automated moderation boundaries

Approved bots may flag content, filter obvious spam, or apply narrowly defined temporary protective controls with a prompt human-review route. Their rules, duration limits, logging, and reversal process must be documented before use. Permanent bans, contested findings, and formal sanctions require an authorized human decision under COM-POL-001 and GOV-POL-003. A model score or keyword match alone is not proof of misconduct.

12. Testing and deployment

Test a proposed automation using synthetic or appropriately authorized data and a restricted environment before production access. Check false positives, failure modes, costs, accessibility, permissions, and whether it stops safely. Start with limited scope, set review intervals, and retain a human override. Approval to run one workflow is not approval for a later expansion into private channels, minors' data, financial actions, or additional services.

04 / POLICY STANDARD

Participant protections and lifecycle

13. Minors and competition

Do not require an eligible minor to create an account that violates a provider's age terms or obtain private AI coaching through an unobservable adult-minor channel. Guardian approval and the established creator/development restrictions still apply. AI or automation must not provide prohibited live competitive assistance, cheat, manipulate matches, evade anti-cheat controls, or impersonate a player. Check the applicable game and tournament rules before use.

14. Logging and transparency

Record material approvals, workflow versions, consequential actions, human reviews, and known limitations at an appropriate level. Do not log unnecessary full conversations, secrets, or sensitive personal data. Tell affected participants when an organizational bot or automated workflow materially handles their interaction. Explain the human contact and review route without exposing security details that could enable abuse.

15. Incident response and correction

Pause or disconnect a workflow that exposes data, sends unauthorized messages, repeatedly misclassifies people, or takes unexpected actions. Preserve appropriate evidence and notify the adult systems owner and Ownership under OPS-POL-001. Correct harmful public output through the communications process and review affected decisions. Do not conceal an incident by deleting relevant logs or quietly replacing a misleading statement without necessary notice.

16. Review and retirement

Review tools when their terms, capabilities, access, cost, or organizational purpose changes and at the scheduled review date. Revoke unused permissions, stop renewals, transfer needed records, and seek deletion from the provider where appropriate under approved retention practices. Complaints, access concerns, and disputed automated actions may be raised through the existing reporting and appeals routes without retaliation.

05 / IMPLEMENTATION

Put the standard into practice.

  • Classify the use, inputs, affected people, and possible external actions.
  • Approve the provider, adult owner, permissions, cost, and review route.
  • Exclude restricted inputs and verify required notice or permission.
  • Test accuracy, false positives, failure modes, and safe shutdown.
  • Require human review of consequential decisions and public output.
  • Monitor incidents, reassess changes, and revoke retired integrations.

Decision-record fields

Use these fields in an approved, access-controlled internal record. This page does not collect or submit responses. Record only what is necessary; keep sensitive information out of public channels.

  • Tool/provider and workflow purpose
  • Adult owner, alternate, and approval
  • Data categories and retention settings
  • Permissions, connected accounts, and allowed actions
  • Test results and known limitations
  • Human review and participant notice
  • Incident and shutdown procedure
  • Review date and retirement record

06 / ADMINISTRATION

Accountability and review.

This organizational policy supplements the Staff & Player Handbook. It does not create employment, union, collective-bargaining, or public-sector rights. It does not replace applicable law, binding external rules, or completed agreements.

Raise questions with an uninvolved lead, Ownership, or Report a Concern. Bypass a conflicted or unavailable person. Good-faith reports, support requests, and participation in review are protected from retaliation. Temporary protective restrictions are not automatic findings of misconduct.

Formal findings and corrective action follow Discipline & Appeals. Preserve relevant records with need-to-know access under the Privacy and Information Security policies. Review this policy annually and after material incidents or organizational changes; record approvals and revisions under GOV-POL-005.

Related standards

Source notes

NIST: AI Risk Management Framework ↗ — Voluntary risk-management guidance informing the review-and-monitor approach; not a certification or an automatic legal requirement.

Version 1.0 · Initial publication: August 28, 2026. Review due: August 28, 2027. An overdue review does not automatically retire the policy.