AthenaLegal & Transparency

Athena Beta · Evaluation Sandbox

AI Use Disclosure

What Athena is, what it cannot be trusted to do, and what we require of you when you use it. Athena is a generative AI system: it produces plausible text, not verified fact.

Version 0.1 (draft) Status Draft — pending legal review Applies to Athena beta (evaluation sandbox)
The core limitation

Athena will sometimes be confidently wrong

Athena generates responses by predicting likely text. It has no internal mechanism for distinguishing a true statement from a false one. It can and does invent facts, statistics, dates, quotations, case citations, legislative provisions, standards numbers and academic references — and it presents them in the same assured tone it uses for correct answers.

Every output must be independently verified by a competent human before it is relied on, quoted, forwarded, published, or used to inform a decision. This applies with particular force to anything you would put in front of a minister, a committee, a court, or the public.

1. Do not use Athena for these

2. Specific failure modes you should expect

Fabricated sources

Athena is instructed to cite sources, and it will produce citations that look correct — author, year, journal, DOI, URL — for material that does not exist. Check that every source is real and that it says what Athena claims it says.

Stale knowledge

The underlying models were trained on data with a cut-off date and do not know about events after it. Athena is told the current date, but knowing the date is not the same as knowing what has happened. Assume anything time-sensitive — current office holders, current law, current prices, current policy — is out of date unless it came from a live web search result shown to you in the conversation.

Prompt injection

If you paste in a document, web page or email, any instructions hidden in that content may be followed by the model as though you had typed them. This can be used to make Athena ignore its instructions, produce misleading output, or attempt to reveal other content from the same conversation. Athena includes defences against this: user messages are scanned against a blocklist of known injection patterns before they reach the model (blocked attempts are logged), user-provided content is wrapped in randomised boundary markers so the model can distinguish data from instructions, and the system prompt carries a hardened preamble that instructs the model to treat fenced content as data and to refuse override attempts. These defences are pattern-based and raise the cost of an attack, but no current defence is complete. Treat untrusted content as untrusted.

Data poisoning and model provenance

Athena runs models obtained from third parties. We did not train them and cannot fully characterise their training data, embedded biases, or any behaviour deliberately introduced upstream. The orchestration harness — the session management, redaction pipeline, audit logging, memory graph and provider routing — is Aristos’s own intellectual property. The underlying model weights are not.

We do not publish the specific model identifiers, parameter counts, serving framework or quantisation format used in production. That detail is operationally sensitive and changes as we evaluate replacements; publishing it would be a maintenance burden and a thin attack-surface map for no reader benefit. What we do publish, and what actually matters for your risk assessment, is on the Data Flows page: which providers process your prompts, in which jurisdiction, under what terms, and what leaves Aristos-controlled infrastructure.

Optional Frontier Access models are provided by third-party providers through OpenRouter under each provider’s own licence and terms. When a Frontier Access model is selected, the request leaves Aristos-controlled infrastructure — that flow is disclosed in the Data Flows register and the in-product model selector makes the provider boundary visible at the point of use.

Bias

Outputs can reflect and amplify biases present in training data, including in ways that are not obvious. Do not treat Athena's framing of a contested question as neutral.

Non-determinism

The same question can produce different answers on different occasions. Athena's output is not reproducible and should not be treated as an authoritative record. If a result matters, record the output you actually relied on.

3. What we require of you

  1. Keep a human in the loop. A competent person reviews output before it is used for anything.
  2. Disclose AI involvement where your own agency's policy requires it. Several Commonwealth and state frameworks require disclosure of AI use in the preparation of official material; complying with those is your responsibility.
  3. Do not present Athena's output as your own verified analysis without actually verifying it.
  4. Tell us when it gets things wrong. During a beta this is the most useful thing you can do: support@aristosai.com.

4. Where we sit on the Voluntary AI Safety Standard

Australia's Voluntary AI Safety Standard (Department of Industry, Science and Resources) sets out ten guardrails for organisations deploying AI. We are working towards those guardrails. We want to be precise about what that does and does not mean:

No assessed conformance

No independent party has assessed Athena against the Voluntary AI Safety Standard, and we claim no conformance with it. The Standard is voluntary and has no certification scheme. Statements below are our own self-assessment, offered so you can judge the gap for yourself rather than take a marketing claim on trust.

GuardrailOur current position
Accountability & governance Named accountable owner: Vishaal Singh (CTO). No formal AI governance policy documented yet.
Risk management Not yet formalised. A written AI risk assessment against the Voluntary AI Safety Standard will be completed and published here before any government beta cohort is admitted.
Data governance Data flows documented — see Data Flows. Retention and deletion practices are documented in Data Handling but not yet independently verified.
Testing & monitoring Functional testing only. No systematic model evaluation, red-teaming or bias testing has been performed.
Human oversight Required of users by these terms. Athena does not act autonomously: it produces text and images in response to a user, and takes no action in any external system without a user initiating it.
Transparency to end users This document set, plus in-product notices about where processing occurs.
Contestability Users can report inaccurate output and request deletion of their data. No formal appeal process, because Athena makes no decisions about people.
Supply chain transparency Subprocessors listed in Data Flows. Model provenance is partially documented — see “Data poisoning and model provenance” above. Specific model identifiers and serving framework are not published; the provider boundary and jurisdiction are.
Records Conversation history, usage logs and an authentication audit trail are retained. A codebase change ledger records every modification to the application.
Stakeholder engagement This beta is itself the engagement mechanism. Feedback: support@aristosai.com

5. Automated decision-making

Athena does not make automated decisions about individuals, and we do not offer it for that purpose. If a future version does, this disclosure will be updated before that capability is released, and the transparency obligations introduced by the 2024 amendments to the Privacy Act 1988 (Cth) will apply.

6. Intellectual property in outputs

Generative models can reproduce material resembling their training data. We make no warranty that any output is free of third-party rights, and copyright in AI-generated material is unsettled in Australian law. As between you and Aristos, you own the outputs Athena generates from your prompts, to the extent they are capable of being owned, and you may use them for any lawful purpose. Because outputs may not be unique and may resemble material given to others, we do not indemnify you against third-party claims arising from use of an output during the beta, and you should verify that outputs are suitable before relying on them commercially.