Skip to content
CHINOOKRequest early access

Responsible AI

In a cooling plant, a confident wrong answer can cost more than no answer. CHINOOK uses AI where it helps, such as reading documents, drafting explanations and answering questions, and keeps it away from the decisions that matter. This page explains where that line sits and how we enforce it.

Code decides, models explain

Whether a sensor is wrong, whether a test passed and whether a finding is raised are decided by deterministic checks: physics, statistics and the test specs your team approved. The same data always gives the same answer, and every rule has a version.

Language models do the work that benefits from reading and writing:

Language models doLanguage models don't
Extract sequences of operation from project documentsDecide whether a sensor is trustworthy
Propose what a point is, with their reasons, for an engineer to approveApprove a mapping, test spec or report
Draft explanations of findings for different readersChange a finding's verdict or severity
Answer questions about a site, citing evidenceSend commands to plant systems

Every claim cites evidence

Everything an assistant says passes an evidence gate before you see it. Each statement must point to something you can check: a finding, a data window, a test run or a page of a project document. If a statement can't be backed, it isn't shown. If nothing can be backed, the assistant says it doesn't know.

AI-written text is always labelled as such and shown after the evidence plot, never instead of it.

People stay accountable

Mappings, test specs and reports need a named person to approve them. Agents have a fixed set of tools and an explicit list of what they may do; approving is not on it.

Where a site chooses to let CHINOOK recommend or eventually adjust setpoints, autonomy is earned one level at a time. Each level has written gates, each gate records who signed it off, and some actions can never be automated at any level. See safety and autonomy.

Inputs are treated as untrusted

Project documents, vendor data and messages from connected systems may contain text that looks like instructions. CHINOOK passes that text to models as quoted data, never as instructions, and the tools an agent can call are limited regardless of what the text says. This limits what a malicious or malformed document can do.

Your data and model training

  • Models trained on one customer's data are never served to another customer.
  • Contributing anonymised fault patterns to a shared fault library is opt-in, per customer, and can be withdrawn.
  • When a task uses a third-party language model, only the data that task needs is sent. The providers we use are named in your agreement.
  • New models run in shadow for 30 days and are promoted only if they beat both the current benchmark and the findings confirmed at that site.

Limits we want you to know about

  • CHINOOK supports engineering judgment; it doesn't replace it. Findings are evidence for your engineers to act on, not instructions.
  • CHINOOK is not a safety system and must never be relied on as one.
  • Checks can only be as good as the data they see. Where data is missing or too coarse, CHINOOK says “inconclusive” rather than guess.
  • Language models make mistakes. The evidence gate stops unsupported claims from being shown, but you should still read the evidence behind anything you act on.

Tell us when we get it wrong

If CHINOOK produced a finding or an explanation that was wrong, we want to know. Write to chinookintelligence@gmail.com. Confirmed corrections feed back into the rules and models for your site.