AI Transparency
Last updated: August 4, 2026
This page explains, in one place, how Do GRC uses AI: which features are AI-powered, how AI-generated output is labelled to you, and what we record about it. It sits alongside the Disclaimer (which covers accuracy) and the Privacy Policy (which covers what data is sent to our AI provider and why).
You are always interacting with an AI, never a person
No feature on Do GRC is staffed by a human responding to you in real time. Every conversational or graded feature — GRC Coach, Role Play, Interview Prep, Exam Prep, AI Check and AI Assist, scenario marking, and the GRC Toolkit AI helpers — is an AI system.
Role Play deliberately keeps its practice partners in character, since the exercise only works if the persona holds. That is a simulated character, not a real person, and never a human on the other end. Every message from a role-play partner is labelled AI in the transcript for exactly this reason.
Which features use AI
- GRC Coach chat and AI-generated learning journeys.
- AI Check and AI Assist on case-study, learning-path and scenario questions.
- Scenario submission marking.
- Role Play conversational practice scenarios.
- Exam Prep and Interview Prep question generation and grading.
- Resume Point Generator.
- Play Arcade AI-generated rounds and AI deep-dive explanations.
- GRC Toolkit AI helpers — AI Fill, AI Example, AI Draft, AI Review, AI Populate, AI Practice Scenario, AI Root Cause Analysis, AI Executive Summary, and AI-suggested related items.
- Text-to-speech audio synthesis.
- The generation of core site content — learning paths, rooms, case studies, scenarios and question banks.
How AI output is labelled
We label AI output in three places:
- Before you use a feature — an on-page notice appears on every AI-powered screen, before you trigger any generation.
- On the output itself — AI-generated panels, scores, feedback and drafts are marked as AI-generated where they are displayed.
- In the record — when an AI helper creates a record in your GRC Toolkit, we store which AI model produced it against that record.
Machine-readable provenance
Records created by an AI helper carry an ai_model field recording the model that generated them. Records you wrote yourself have no value in that field. This is a logging mechanism: it lets us — or you — establish after the fact whether a given record originated from an AI system, and which one.
This provenance travels with your data when it leaves the platform. CSV exports include an “AI Generated (model)” column, printed and PDF exports carry an AI notice, and the data download in your privacy settings includes the field.
We do not watermark generated text. Text watermarks do not survive ordinary editing, and the EU's Code of Practice on Transparency of AI-generated Content accepts logging as the alternative where watermarking is not reliable. Records created before we began capturing provenance have no value recorded — we have not guessed retrospectively, because a wrong guess would be worse than an honest gap.
EU AI Act
Article 50 of the EU AI Act (Regulation (EU) 2024/1689) sets transparency obligations for AI systems that interact with people or generate synthetic content. Those obligations have applied since 2 August 2026. The measures described on this page — disclosure at the point of interaction, labelling of AI output, and machine-readable provenance logging that survives export — are how we meet them.
If you believe an AI feature on this platform is inadequately labelled, please tell us at hello@dogrc.com and we will correct it.
What AI output is not
AI output on Do GRC is a study aid. It is not professional legal, audit, compliance, or risk management advice, it is not human-reviewed, and it can be confidently wrong — including inventing controls, clauses and citations that do not exist. See the Disclaimer for the full position, and the Terms of Service (AI-Powered Features) for usage limits and liability.
Your controls
You can object to AI training-eligible processing from your privacy settings. You keep access to every feature — we route your inputs through the non-training path instead. The Privacy Policy sets out exactly which features send what to our AI provider.