| ▸AI surface |
Widget chat, WhatsApp handoff, generated media export, public text generator, avatar/synthetic voice, or admin AI helper. |
Name the exact product surface and link the design/code artifact. |
Identified AI Surfaces — 9 total
| Surface | Engine | Exposure | Disclosure State |
| Chat widget | OpenAI via api/chatbot.js | Visitor-facing | Default ON (2026-07-06) |
| WhatsApp channel | Same engine via api/whatsapp/webhook.js | Visitor-facing | Auto-prepended |
| AI Review | OpenAI via utils/hea/heaReviewAgent.js | Admin only | Labeled "AI Review" |
| Opportunity Scout | OpenAI via utils/outpost/opportunityScout.js | Admin only | N/A |
| Brief/Content Engine | OpenAI via utils/outpost/briefEngine.js | Admin drafts | No AI label on output ⚠️ |
| Foundry enrichment | OpenAI via enrichment utilities | Internal RAG | N/A |
| CRM enrichment | Explorium / AI classification | Admin only | N/A |
| Infirmary email case classifier | OpenAI via utils/infirmary/emailCaseClassifier.js | Admin / Infirmary operators only | Operator-only classify; Ward shows machine-ingested unverified candidate; no public visitor disclosure |
| Workbench Chief of Staff | OpenAI via utils/workbench/cosRuntime.js + draftRuntime.js + draftEnrichProposal.js (reply drafts + Enrich propose B) + composeRuntime.js (new-thread compose generate) | Admin only | Quiet permanent disclosure line under the chat input (2026-08-12); AI-drafted badge on every AI-generated reply draft until send, downgrading to "AI-assisted — edited by you" after first owner edit (N3-a, 2026-08-13). Enrich is a new operator action: proposed alternative is labeled as drafted from published HEA knowledge; existing badge stays; A is unchanged until Use enriched. S1 Direction on the draft card is operator text — not a new AI surface. 2026-08-21: compose generate is the same Workbench surface / new trigger — badge until send; no sent-body footer; not a new AI family. |
|
| ▸User exposure |
End-user, HEA owner, HEA compliance operator, HEA-World admin, or mixed audience. |
Confirm who sees or is affected by the AI output. |
Exposure Audit
9 AI surfaces identified. 2 are visitor-facing (chat widget + WhatsApp). 7 are admin/internal only. Mixed audience surface: none.
|
| ▸Direct AI interaction |
Yes/no and rationale for whether a user is directly interacting with an AI system. |
Short written decision attached to the launch row. |
Direct Interaction Assessment
- Chat widget: YES — visitors directly interact with AI.
- WhatsApp: YES — same engine.
- AI Review / Scout / Brief: NO — admin tools, users are aware they're using AI features.
- Foundry / CRM enrichment: NO — background processing.
- Workbench Chief of Staff: NO — admin-only operator tool; the owner knowingly uses an AI assistant (quiet permanent disclosure line under the chat input). Reply drafts (N3-a): AI-generated content the owner reviews/edits before any send — badge persists until send ("AI-drafted" → "AI-assisted — edited by you" after first owner edit).
|
| ▸Disclosure location |
Header, welcome text, handoff copy, export metadata, page footer, or modal. |
Screenshot, copy file, or UI selector showing the disclosure. |
Active Disclosure Points
- Chat widget: Welcome message disclaimer (configurable text, default ON).
- WhatsApp: First-message disclaimer auto-prepended.
- Widget menu: "Powered by HEA-World" (hardcoded).
- Widget menu: "Privacy terms" link (hardcoded).
- Site footer: "Powered by AI, guided by humans." (hardcoded).
- Privacy page: States "you're interacting with an AI system" (static).
- FAQ: States AI interaction is disclosed (static).
|
| ▸Removability |
Whether normal HEA customization can weaken or remove the platform AI disclosure. |
Must be no for platform baseline before launch. |
Removability Controls
| Control | Default | Guardrail | Status |
show_data_disclaimer toggle |
Default: true |
Editor shows Article 50 warning modal on toggle-off |
✅ Remediated |
data_disclaimer text |
Default: "This is an AI-powered assistant." |
Can be changed but default is clear |
✅ Verified |
intro_message text |
Default includes "AI assistant" |
Redundant — data_disclaimer already covers AI disclosure |
✅ N/A |
| WhatsApp disclaimer |
Auto-prepended |
Low risk |
✅ Verified |
|
| ▸Generated/manipulated content |
Whether the feature creates generated text, generated media, synthetic voice/avatar, or manipulated content. |
Mark current scope, planned scope, or out of scope. |
Generated Content Assessment
Content Engine generates publishable drafts (LinkedIn posts, emails, articles) and Canteen hero images for operator use. Each generated content card shows an ✨ AI-generated — review before publishing badge on text. Generated hero images show an on-image AI badge; crop/filter edits auto-label as AI-generated — human-edited. Downloaded hero PNGs embed C2PA Content Credentials with machine-readable provenance (Article 50).
✅ Remediated — text + image human-visible badges + C2PA at download (2026-07-07)
|
| ▸Machine-readable marking |
Yes/no/unknown decision for metadata or provenance controls. |
Unknown decisions stay as dashboard gaps. |
Machine-Readable Provenance
Text outputs (current): Content Engine text outputs (LinkedIn posts, emails, articles) are delivered via copy-paste. No machine-readable provenance standard applies to plain-text clipboard content today. Human-visible AI badge added to all outputs (2026-07-06).
✅ Text — covered by human-visible badge
Image outputs (current Canteen hero images) / video outputs (future):
- Embed C2PA / Content Credentials on hero PNG download — ✅ `serveCanteenImage?download=1` (2026-07-07)
- Show AI-generated badge on every generated image card — ✅ on-image badge in Canteen (2026-07-07)
- If user applies filters or edits, mark as AI-generated, human-edited — ✅ in-app crop + filter editor auto-labels (2026-07-07)
- Only full manual upload (user's own photo) removes the AI label — not yet supported in Canteen v1
✅ Canteen hero downloads — C2PA embedded with dev/test signer (Trust List cert optional via ENV)
|
| ▸Human review |
Whether generated public-interest or publishable content needs review before release. |
Owner and review path, not only a verbal agreement. |
Human Review Controls
- Content Engine drafts: Require admin review before publishing.
- Chat responses: Generated in real-time without human review.
- AI Review suggestions: Require admin action (Apply button) before taking effect.
|
| ▸Launch decision |
Allowed, blocked, or allowed with follow-up. |
Decision date, owner, and linked Compliance Dashboard requirement. |
Dashboard Status Recommendations
| Requirement | Status | Summary |
AI-ACT-50-1 |
✅ Verified |
data_disclaimer is non-removable baseline; show_data_disclaimer toggle has Art. 50 warning modal on disable |
AI-ACT-50-2 |
✅ Remediated |
AI-generated badge on Content Engine text; on-image badge + auto human-edited marking on Canteen heroes; C2PA Content Credentials on hero PNG download (2026-07-07) |
AI-ACT-50-4 |
🔵 Planned |
Future media / avatar / synthetic voice features |
AI-ACT-50-5 |
✅ Verified |
Content Engine is copy-paste only (no direct publish); boundary explicit in UI |
AI-ACT-50-6 |
✅ Verified |
Checklist enforced as policy gate via AGENTS.md (AI Act Article 50 Compliance Gate) |
|