AI
AI Governance
How we build and operate Merlin, our AI coach, in a responsible, transparent, and secure way.
Last reviewed: July 2026
Merlin is the AI coach within the Risely platform. This page describes how we develop and operate our AI capabilities in a responsible, transparent, and secure way. It covers all AI and large language model functionality in Risely’s products.
Our principles
- Transparency: users always know they are interacting with an AI coach, not a human.
- Defined purpose: Merlin provides leadership and professional-skills coaching. It does not provide medical, mental health, legal, or HR-policy advice, and it is designed to redirect users to appropriate human resources for matters outside its scope.
- Privacy by design: we use the minimum personal data necessary in AI processing, in line with our Privacy by Design and Data Protection policies.
- No foundation-model training on customer data: customer data is not used by Risely or its LLM providers to train foundation models.
- Human oversight: coaching quality and safety are monitored by Risely staff through session-level quality metrics and user feedback.
How Merlin is built
Merlin is built on commercial large language models, currently provided by OpenAI, Anthropic, and Google, accessed via their enterprise APIs. Voice interactions also use speech-to-text (OpenAI) and text-to-speech (Google) services. These models are orchestrated within Risely’s proprietary coaching framework, which includes structured session arcs, an 83-skill framework with defined behavioral indicators, user memory and context, and organization-level configuration. Our engineering team evaluates any change of model version or provider for coaching quality and safety before rollout.
Output quality and safety
We measure coaching sessions through quality metrics such as engagement integrity, reflective depth, and action specificity. Users can flag unhelpful or inappropriate responses, and those reports are reviewed. The coaching framework constrains AI outputs to the coaching domain and to the organization’s configured values and frameworks.
Data handling in AI processing
Conversation data is processed to deliver and improve the coaching experience for the user. Administrators of customer organizations receive AI-generated session summaries and engagement metrics; they do not receive raw conversation transcripts. Data shared with LLM providers is limited to what is necessary to generate coaching responses, and it is governed by our Vendor and Subprocessor Management Policy.
AI incidents
Incidents involving AI outputs, including reports of harmful, biased, or materially inaccurate coaching responses, are handled under our Incident Management Policy and Procedure, and are triaged by our security team together with the engineering team.
Regulatory awareness
We monitor the evolving regulatory landscape that applies to AI systems, including the EU AI Act and related guidance, and we update our practices as requirements develop.
Questions
If you have any questions about this policy, contact us at [email protected].
Questions about this policy? [email protected]
