Responsible Use & Compliance
Last reviewed: July 15, 2026
PeachBot develops human-supervised AI systems for biology, digital health, agriculture, environmental intelligence, and edge computing. This statement explains the compliance posture we design toward, the limits of our platforms, and the responsibilities of users, customers, partners, and deploying institutions.
1. Important Legal Position
This page is a governance and responsible-use statement, not legal advice, regulatory approval, medical approval, a conformity assessment, or an ISO certificate. Compliance depends on the exact product configuration, intended purpose, jurisdiction, user role, data category, risk classification, deployment environment, and contractual controls. Deploying organizations must obtain their own legal, clinical, cybersecurity, privacy, ethics, biosafety, and regulatory review before production use.
2. Product Boundaries
- No autonomous final decisions: PeachBot systems are designed for decision support, analysis, monitoring, and workflow assistance. Human review is required.
- No emergency reliance: PeachBot does not replace emergency services, public authorities, hospital triage, disaster warning agencies, or licensed professionals.
- No medical-device claim unless expressly cleared: Health-related software must not be treated as a medical device, diagnostic tool, treatment system, or clinical authority unless the exact product and use have received required approvals.
- No wet-lab execution: PeachBot Bio is in-silico only and does not provide laboratory protocols, synthesis instructions, organism engineering, or biological execution.
- No guaranteed outcomes: Agricultural, health, environmental, and research outputs are probabilistic or advisory and must be validated locally.
3. India Alignment
For India-facing activities, PeachBot designs toward the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 for lawful processing, notice, consent or other permitted grounds, data principal rights, security safeguards, breach response, children-related obligations where applicable, and data fiduciary accountability. Health integrations may also require attention to the ABDM Health Data Management Policy when connected with the Indian digital health ecosystem.
Health or telemedicine use must remain under qualified healthcare professionals and applicable professional rules, including Indian medical ethics and telemedicine guidance. If a feature is intended for diagnosis, treatment, monitoring, prediction, or clinical decision-making, Indian medical-device and software-as-medical-device analysis under CDSCO and the Medical Devices Rules may be required before deployment.
4. Singapore Alignment
Singapore deployments should be assessed under the Personal Data Protection Act and Personal Data Protection Commission guidance, including advisory guidance on personal data in AI recommendation and decision systems. PeachBot also considers Singapore AI governance practices such as AI Verify and model governance expectations for transparency, explainability, robustness, accountability, and human oversight.
Medical workflows must remain subject to Singapore healthcare licensing, registered medical practitioner obligations, clinical governance, and the Singapore Medical Council's ethical code and guidance where applicable.
5. UAE Alignment
UAE deployments should be assessed under Federal Decree-Law No. 45 of 2021 on Personal Data Protection, related executive regulations and UAE Data Office guidance, plus any sector-specific, free-zone, cybersecurity, consumer, health, or media rules that apply. DIFC or ADGM rules may apply to entities or processing inside those zones. AI deployments should also consider the UAE National Strategy for Artificial Intelligence as policy context.
6. EU and EEA Alignment
EU and EEA-facing deployments should be assessed under the GDPR, ePrivacy rules where relevant, the EU AI Act, cybersecurity obligations such as NIS2 where applicable, and medical-device regimes including the MDR and IVDR when software has a medical purpose. The EU AI Act may classify some AI uses as prohibited, high-risk, transparency-regulated, or general-purpose AI related depending on the use case.
PeachBot design reviews therefore consider intended purpose, risk classification, human oversight, technical documentation, logging, data governance, accuracy and robustness, transparency, post-market monitoring, incident handling, and user instructions where a regulated AI or medical use may exist.
7. Standards and Frameworks Considered
PeachBot may use the following standards and frameworks as design references where relevant. References to a standard do not mean certification unless a certificate is expressly issued by an accredited body for the named scope.
- AI governance: ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, ISO/IEC 42006, ISO/IEC 38507, NIST AI RMF, OECD AI Principles, and responsible AI lifecycle controls.
- Information security and privacy: ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27701, security-by-design, access control, encryption, audit logging, vendor review, and incident response.
- Medical and health software: ISO 13485, ISO 14971, IEC 62304, IEC 62366-1, IEC 82304-1, clinical evaluation, usability engineering, traceability, validation, and post-market monitoring where applicable.
- Cloud, edge, and software assurance: secure SDLC, OWASP ASVS, OWASP Top 10, OWASP LLM guidance, SBOM practices, vulnerability management, backup, availability, and change control.
- Data interoperability: HL7 FHIR, structured data governance, provenance, retention controls, and role-based access where health data integrations are used.
8. Responsible AI Controls
- Documented intended use, prohibited use, foreseeable misuse, and user instructions.
- Dataset provenance checks, consent and licensing review, data minimization, and retention controls.
- Bias, performance, robustness, cybersecurity, drift, and failure-mode evaluation appropriate to risk.
- Human oversight, explainability, confidence signaling, trace logs, escalation paths, and override mechanisms.
- Incident reporting, corrective action, model update control, and post-deployment monitoring.
9. User and Partner Responsibilities
Users and partners must ensure lawful data collection, adequate consent or other legal basis, role-based access, local validation, professional review, institutional approvals, and regulatory filings where required. They must not use PeachBot outputs to bypass clinicians, ethics committees, biosafety committees, regulators, public authorities, or emergency response processes.
10. Updates
AI, privacy, medical, biosafety, and cybersecurity regulation is evolving quickly. PeachBot may update this statement as laws, standards, product capabilities, and deployment contexts change. Questions may be sent to [email protected].