Home

Responsible AI

Last reviewed: 2 September 2026 ยท Privacy policy

Journey's model-backed AI is available only to Journey Advanced providers after provider configuration and the required DPIA and release approvals. It fails closed unless the provider, tenant entitlement and applicable production controls are configured.

Responsible AI means using artificial intelligence to assist people rather than replace their judgement. Journey uses model-backed assistance for programme-bound OTJ/evidence work: learner evidence drafts, tutor and assessor feedback drafts, and proposed knowledge and skill links for review. It also provides four fixed, read-only Director Insight views. It is never used to make high-stakes decisions on its own.

Where Journey uses AI

  • Preparing learner evidence drafts and tutor or assessor feedback for the authorised user to review and adapt.
  • Proposing knowledge and skill links from submitted evidence for staff to accept, reject or amend.
  • Supporting clear, evidence-based descriptions; the provider's existing human workflow remains the source of record.
  • Preparing a source-linked, read-only Director view for one of four fixed questions: provider performance, funding exposure, operational status or selected learner-support facts.

It is not a general learner or staff chat service. It has no web browsing, tools, database access, notification-sending or autonomous action capability.

Journey Insight for Directors

Journey Insight is not an open-ended chatbot. An authorised Director selects one of four defined operational views. Journey prepares a minimised snapshot from records that role may access, returns a source-linked observation and leaves the source data unchanged.

The output supports leadership review; it is not a funding decision, inspection judgement, safeguarding decision or learner-status decision. A person checks the cited records and decides what happens next.

What Journey's AI never does

  • It does not compute or decide funding figures, which are calculated server-side against published, versioned funding-rule packs.
  • It does not decide gateway, EPA or compliance outcomes, which are confirmed by people and rules.
  • It does not automatically mark evidence, change KSB progress, change learner status, or verify behaviours. Behaviour evidence requires attributable workplace evidence and any required employer verification or sign-off.

Human in the loop

AI output is a draft or suggestion for a person, not an automated decision. The assessor retains the authority to disagree, amend or reject it while viewing the underlying evidence and can continue without AI. Staff review AI-assisted content before it informs a decision, and controlled audit history records the actions people take.

Privacy by design

For an authorised evidence or feedback request, bounded learner-authored workflow content may be processed for that purpose. Journey applies pattern-based redaction to direct identifiers it detects and excludes credentials, payment data, raw signatures and document bytes. Redaction cannot guarantee that all personal data is removed, so the DPIA and authorised workflow boundary remain required controls. Tenant-scoped helpers verify that any referenced record belongs to the user's organisation before a call is made.

Governed and metered

Every AI call is metered and recorded in an AI usage ledger that stores compact metadata, not raw prompt content. A configured application-side spend reservation cap is checked before a request; Vercel AI Gateway's API-key budget is a separate soft, defence-in-depth control. Unknown pricing or a control failure prevents the call rather than bypassing the cap.

Provider data handling and challenge

Journey sends minimised content through Vercel AI Gateway to OpenAI with store: false. OpenAI API data is not used for training by default, but default abuse-monitoring retention may be up to 30 days unless OpenAI approves a different arrangement. There is no absolute guarantee that a model cannot be manipulated, so Journey combines server-side scope checks, minimisation, closed output validation and human review. A learner or staff member can ask their provider data-protection lead to challenge a draft or suggestion, correct the source record or restrict further AI use.

Validated and safe to fail

AI responses are validated against an expected shape before use. If a model is unavailable or returns something unexpected, Journey reports that the assisted action is unavailable and leaves the underlying record unchanged rather than guessing.

If Journey suspects a provider, minimisation or instruction-handling incident, it is designed to disable the governed-AI runtime path, revoke its dedicated provider credential and preserve minimised audit evidence for security and data-protection review before any re-enable.

Frequently asked questions

What is responsible AI in apprenticeship software?

Responsible AI means using artificial intelligence to assist people rather than replace their judgement, with clear limits on what data it sees, what decisions it can influence and how its use is recorded. In Journey, Advanced AI prepares programme-bound OTJ/evidence drafts and K/S suggestions for human review; implemented funding, gateway, EPA and compliance controls remain deterministic and require authorised human confirmation.

What learner data can Journey Advanced AI process?

For an authorised evidence or feedback request, only persisted programme-bound workflow content needed for that request may be sent through Vercel AI Gateway to OpenAI. Journey applies pattern-based redaction to direct identifiers it detects, but cannot guarantee all personal data is removed; credentials, payment data, raw signatures and document bytes are excluded. Tenant-scoped checks verify that the user may access the referenced record before a call is made.

What can Journey Insight tell a Director?

An authorised Journey Advanced Director can request one of four fixed, read-only views: provider performance, funding exposure, an operational snapshot or selected learner-support facts. Journey uses a minimised snapshot, links observations to their source and changes no record. A person reviews every output before acting.

Can AI make a funding or compliance decision on its own?

No. AI output is a draft or a suggestion for a person. Funding figures, gateway and EPA readiness, and compliance outcomes are computed server-side against versioned rules and confirmed by staff โ€” never decided by a model.

How is AI use kept within budget and monitored?

Every AI call is metered and recorded in an AI usage ledger that stores compact metadata, not raw prompt content. Journey applies a configured application-side spend reservation cap before a request; the separate Vercel AI Gateway key budget is a soft defence-in-depth control. Unknown price data or an unavailable control fails closed.

What happens if the AI model is unavailable?

The assisted action reports that it is unavailable and leaves the underlying learner, evidence and assessment records unchanged. Users can continue the normal human workflow without an AI result.


Journey is independent software. It is not endorsed by, affiliated with, or approved by Ofsted, the Department for Education or any other public body. References to frameworks and funding rules describe the standards Journey is built to support.

Contact

Questions about how we use AI? Email support@journeyapp.co.uk.