Responsible AI Policy
Governing the design, deployment, and oversight of artificial intelligence and machine learning
1. Purpose and Scope
This policy states how Baseline Telematics Inc. (“Baseline”) designs, deploys, monitors, and discloses artificial intelligence and machine learning (“AI/ML”) capabilities within its products. It applies to every current and future AI/ML feature Baseline builds or integrates, today, this means the Citycare Video AI capabilities built around the vehicle-mounted, front-facing camera, and to every employee, contractor, and sub-processor involved in designing, training, deploying, or operating those capabilities.
This policy exists for three reasons. First, Baseline now has real, in-production computer-vision AI, on-device TensorFlow models detecting bin presence, road defects, missing signage, and streetlight outages, with server-side AI and client-augmentable models (via Roboflow) following close behind, and that capability needs a governance framework, not just a per-deal explanation. Second, Baseline's customers are municipalities, and municipal buyers increasingly expect a documented AI governance posture as a condition of doing business, the AI Vendor Fact Sheet format the City of Worcester used to evaluate Baseline is itself modeled on the GovAI Coalition's vendor disclosure standard, now used by dozens of local governments across North America. Third, publishing this policy is the honest next step after Baseline's own fact-sheet answers repeatedly flagged the absence of one as a gap.
This policy does not apply to Baseline's use of general-purpose AI tools for internal productivity (e.g., coding assistants, drafting tools) unless and until those tools are given access to production customer data; that use is covered separately under Baseline's internal acceptable-use guidelines.
2. Guiding Principles
Baseline's AI principles are adapted from the OECD AI Principles (updated May 2024) and the trustworthiness characteristics defined in the NIST AI Risk Management Framework (AI RMF 1.0), scaled to fit a company of Baseline's size. They are not aspirational marketing language, each one maps to a concrete practice described later in this policy, and Appendix A shows that mapping explicitly.
- Human oversight and accountability. No Baseline AI feature takes an autonomous action against a person, a property, or a municipal record. Every detection is a suggestion that a named human reviews before it becomes an official record, and a named individual at Baseline is accountable for the AI program (Section 3).
- Transparency and explainability. Every AI-enabled deployment is accompanied by a plain-language AI Fact Sheet describing what the system does, what data it uses, and what its limitations are, before the feature is turned on, not after. Every individual detection carries the evidence (photo, short video clip, GPS coordinate, timestamp) a human needs to judge it.
- Fairness and bias management. Baseline acknowledges, rather than hides, that camera-based detection can perform unevenly across neighborhoods, lighting conditions, and hardware. Baseline commits to building bias-monitoring tooling, to disclosing the absence of a study honestly until one exists, and to not deploying a feature into any enforcement-linked or high-stakes context without a bias/impact assessment first.
- Privacy and data minimization. Camera-based features are opt-in per city and per route, capture image/video only (never audio), and are governed by the same Data Processing Agreement that covers the rest of the platform, client data is never used for a purpose outside delivering and improving the contracted service.
- Security and robustness. AI features inherit Baseline's existing application and cloud security program (see Baseline's IT Security Policies), encrypted data in transit and at rest, least-privilege access to training data and models, and a tested software release process for every model update.
- Purpose limitation. AI features are built to solve a specific, named operational problem (a missed bin, a pothole, an unlit street), not built as general-purpose surveillance, and not repurposed for a new use without a fresh review under this policy.
- Continuous improvement, honestly tracked. Where Baseline has a gap, no bias study, no formal accuracy benchmarks published, no WCAG accessibility audit, this policy names the gap and commits to a plan, rather than staying silent (Appendix B).
3. Governance and Accountability3.1 Policy owner
Paul-André Savoie, President & CEO, is the accountable owner of this policy and of Baseline's AI program until Baseline formally designates a dedicated AI governance role. This mirrors Baseline's existing security governance model, where the CEO is the sponsor of the information security program described in Baseline's IT Security Policies.
3.2 Review and approval of new AI features
Before any new AI/ML capability is built or a new detection category is added to an existing capability, it must be reviewed against this policy, specifically:
- What decision or record does the output feed into, and is a human required to review it before it takes effect?
- What data trains or informs the model, who owns it, and does the client's contract cover this use?
- Could the feature perform unevenly across a protected class or a geographic/demographic proxy for one, and has that been considered before launch, not just after a complaint?
- Does the feature capture anything (imagery of people, license plates, private property, audio) that raises a jurisdiction-specific privacy, surveillance-ordinance, or wiretapping concern, and has that been checked for the deploying jurisdiction?
- What is the plan if the model is wrong, how is a bad detection corrected, and does that correction improve the model?
3.3 Client-facing transparency artifact
Every prospective or existing client evaluating an AI-enabled Baseline deployment receives a completed AI Vendor Fact Sheet (or the client's own equivalent form) before the camera-based features are enabled on their account, not on request only. Baseline treats the fact sheet as a living document: it is updated whenever the underlying capability changes materially (a new detection category, a move from edge-only to server-side inference, a change in whether client imagery trains shared models).
4. Baseline's AI/ML Systems
This section is the authoritative, plain-language inventory of what AI Baseline actually runs. It should be the source of truth for every future fact sheet, RFP, or security questionnaire, if a description elsewhere in a Baseline document conflicts with this section, this section governs.
4.1 Citycare Video AI
Citycare Video AI is the umbrella name for Baseline's computer-vision capability built around an optional vehicle-mounted, front-facing camera. It is opt-in per city and per route; a Citycare deployment with the camera feature off has no AI/ML component active.
- Edge AI (in production). On-device TensorFlow / TensorFlow Lite computer-vision models run locally on the field device in real time, without a constant server round-trip, consistent with Citycare's offline-capable, store-and-forward architecture.
- Server-side AI (rolling out). Heavier computer-vision workloads for the same camera pipeline, run on Google Cloud, are rolling out to complement the edge models.
- Detection use cases live or in near-term rollout:
- Residential waste pickup verification, bin present/absent at a collection stop.
- Patrol/road-condition detection, potholes and road-surface defects.
- Infrastructure inventory, street signs visible in imagery but not yet logged in the city's asset system.
- Night-time streetlight outage detection.
- Client-augmentable and custom models. A “survey mode” captures a photo roughly every 10 seconds along a route; images upload to Roboflow, where a client can label imagery to refine Baseline's existing models or train an entirely new detection category. The City of Montreal's graffiti-on-buildings detection model, trained on Montreal's own route imagery, is the working example of this workflow.
4.2 What Citycare Video AI is not
- It is not facial recognition and is not designed or intended to identify a specific individual person.
- It does not take an automatic enforcement, billing, or citation action, every detection is a suggested record subject to human review (Section 6).
- It does not capture audio.
4.3 Other AI capacity in Baseline's environment
Baseline's underlying Google Cloud environment provides access to additional AI/ML services (for example, Gemini, Vertex AI, DialogFlow CX, Cloud Vision) that are not part of Citycare Video AI and are not in active production use in the core platform today. Any future use of these services in a customer-facing feature is subject to this same policy and requires the review described in Section 3.2 before launch, it is not automatically in scope just because the underlying cloud account has access to it.
5. Data Governance for AI5.1 Training data provenance
Baseline's own detection models (bin presence, potholes, missing signage, streetlight outage) are trained by Baseline's ML team. Client-specific/custom models are trained or fine-tuned using that client's own route imagery, labeled via Roboflow by the client and/or by Baseline on the client's behalf, and are added to on an ongoing basis as new routes are driven and new annotations are made. All training imagery originates from a client's own contracted vehicle routes, captured under that client's service agreement, Baseline does not source training imagery from any other channel.
5.2 Data ownership and use for model improvement
Route imagery captured by a client's vehicles is that client's data under Baseline's Data Processing Agreement, exactly as with the rest of the Citycare platform. This is the one meaningful exception to Baseline's general “customer data is never used to improve anything outside that customer's own account” posture elsewhere in the product: when a client uses the Roboflow-based workflow, their imagery may be used to improve Baseline's shared detection models, benefiting all clients running that model, this is disclosed to the client directly (as it was to Worcester) rather than left as a default buried in boilerplate terms.
5.3 Retention and minimization
Captured imagery and short video clips are retained to support the human-review workflow and, where the client's Roboflow-based workflow is in use, to support model training/refinement. Baseline has not yet published a fixed retention schedule specific to this imagery, separate from the platform's general data-retention terms (Section 3, Baseline IT Security Knowledge Base), this is called out in Appendix B as an item to formalize, particularly given the residential bin-detection use case involves imagery near private homes.
5.4 Personally identifiable content in imagery
Baseline has not yet published a definitive policy on whether captured imagery may incidentally include identifiable people, faces, or license plates, or whether any blurring/redaction is applied. This is treated as an open item (Appendix B) rather than glossed over, and should be resolved, with a documented technical and contractual answer, before this capability is scaled into any jurisdiction with a strong biometric-privacy statute.
6. Human Oversight and the “Learning Mode” Model
Every Citycare Video AI detection, a missing bin, a pothole, an unlisted sign, a dark streetlight, a graffiti flag, is generated in what Baseline calls learning mode: a City supervisor or inspector reviews, confirms, or dismisses each detection inside Citycare's normal task/inspection workflow before it becomes an official record. No detection is wired to an automatic enforcement or billing action.
This human-in-the-loop requirement is the primary control Baseline currently relies on to catch model error in production, in place of a published accuracy benchmark (Section 7). Dismissed or corrected detections can be fed back into the Roboflow annotation pipeline to improve future model versions, though today that feedback loop is manual and periodic rather than fully automated.
Baseline does not currently have a documented, criteria-based process for when a detection category could graduate from mandatory human review toward a higher degree of automation. Before Baseline would ever propose reducing human review for any detection category, this policy requires, at minimum: a completed bias/accuracy assessment for that specific model (Section 7), at least one full season/cycle of production learning-mode data, and explicit client sign-off, not a unilateral Baseline decision.
7. Fairness and Bias Management
No independent bias, accuracy, or disparate-impact study has been conducted on any Citycare Video AI model as of this policy's effective date. Baseline states this plainly rather than implying otherwise. The realistic risk is not hypothetical: false-negative rates could plausibly vary by neighborhood or street type (tree cover and parked vehicles obstructing the camera's view, non-standard bin styles or placement), by lighting and weather conditions, and by camera/vehicle hardware quality, all of which can correlate with neighborhood demographics even without any intent to discriminate.
Baseline's current and planned mitigations:
- Every detection passes through mandatory human review before becoming a record (Section 6), which is the primary safeguard today.
- Bias-monitoring tooling, to detect and help correct for uneven detection rates across neighborhoods, is in development for an upcoming release.
- Before any Citycare Video AI model is used in a context tied to enforcement, fines, or a service-eligibility decision (as opposed to a purely operational lead for city staff), Baseline commits to completing or commissioning a bias/disparate-impact assessment first, and to sharing the methodology and results with the affected client.
- Baseline will not describe a model as “bias-tested” or “validated” in any future client communication unless a specific study backs that claim.
8. Security and Robustness
Citycare Video AI inherits Baseline's existing application and infrastructure security program rather than operating under a separate standard, see Baseline's IT Security Knowledge Base and IT Security Policies for the full program. Relevant specifics for AI features:
- Captured imagery and detection metadata are encrypted in transit (TLS 1.2/1.3) and at rest (AES-256), consistent with the rest of the platform.
- Access to training imagery, annotation tooling (Roboflow), and model artifacts is restricted on a least-privilege basis to authorized Baseline personnel and, where applicable, the client's own authorized annotators.
- Model updates, whether an edge model pushed to a field device or a server-side model release, follow Baseline's standard change-management and CI/CD process (Baseline IT Security Knowledge Base, Section 3), including staged rollout.
- Clients may elect to remain on a prior model version and will receive advance notice before that version is deprecated, rather than being force-migrated without warning.
9. Transparency, to Customers and the Public
Baseline commits to the following transparency practices for any AI-enabled feature:
- Fact sheet before activation. A completed AI Vendor Fact Sheet is provided before a camera-based AI feature is enabled for a client, describing purpose, data use, limitations, and known gaps, modeled on the disclosure categories used by the GovAI Coalition's municipal vendor fact sheet standard, which is the format Worcester itself used to evaluate Baseline.
- Evidence with every detection. Each detection carries its source photo, a short video clip (roughly five seconds before and after the triggering frame), GPS coordinate, and timestamp, so a human reviewer can see exactly why the system flagged something.
- No silent scope creep. A new detection category or a shift from edge-only to server-side/automated processing is treated as a material change requiring a fact-sheet update and, per Section 6, is never a path to removing human review without client sign-off.
- Honest gaps over polished silence. Where Baseline does not yet have an answer, quantified accuracy metrics, a bias study, a WCAG accessibility audit, that gap is stated directly in client-facing materials rather than omitted (Appendix B).
10. Privacy and Legal/Regulatory Considerations
Capturing imagery of the public right-of-way from a city vehicle is standard municipal practice, but Citycare Video AI's residential bin-detection use case specifically involves photographing the curb and front of private homes, which can implicate local privacy expectations beyond a typical dashcam use case. Baseline's current posture and open items:
- Only image/video is captured, never audio, which is intended to keep two-party-consent wiretapping statutes (including Massachusetts') out of scope; this should be confirmed with counsel before the feature is represented as compliant in any specific jurisdiction.
- A number of municipalities, including some in Massachusetts, have adopted surveillance-technology oversight ordinances requiring public notice or council approval before a new camera-based detection system is deployed. Baseline does not independently track every client jurisdiction's ordinance status, confirming applicability (e.g., for Worcester specifically) is the deploying client's and Baseline's shared responsibility before a route goes live, and should be checked explicitly rather than assumed clear.
- Data processing terms (Privacy Policy, Cookie Policy, Data Processing Agreement) apply to AI-captured imagery exactly as they do to the rest of the platform; PIPEDA and GDPR-aligned principles govern cross-border handling where relevant.
- Sector-specific regimes Baseline has consistently found not triggered by its product, PCI DSS, FERPA, COPPA, CIPA, HIPAA, CJIS, should be re-confirmed per deal rather than assumed to extend automatically to a new AI use case.
11. Third-Party AI Tools and Sub-processors
Baseline's AI/ML supply chain currently consists of:
- Google Cloud Platform, hosting for both edge-model distribution and the rolling-out server-side inference, plus optional access to Google's AI/ML services (Section 4.3), governed by Google's own SOC 2 / ISO 27001 / ISO 27017 / ISO 27018 certifications.
- Roboflow, used for image annotation and for training/fine-tuning client-augmentable and custom detection models.
Any new AI/ML sub-processor is subject to the same vendor due-diligence Baseline applies to its existing supply chain (Baseline IT Security Knowledge Base, Section 3, Supply Chain Management), and is disclosed to affected clients consistent with Baseline's Data Processing Agreement.
12. Incident Reporting and Issue Escalation
A client or an individual detection can be flagged or corrected through the same channels Baseline uses for any platform issue: 24/7 in-app live chat, the support portal, and email-based ticketing, all tracked as Support Cases through resolution. In addition, any single AI detection can be corrected or dismissed directly by city staff within the Citycare workflow at the point of review, no separate AI-specific reporting channel is required to make a correction that affects that detection.
An AI-specific issue that suggests a systemic problem (a pattern of false negatives in a specific area, a possible bias signal, a privacy concern raised by a resident or city council) is escalated internally to the policy owner (Section 3.1) rather than handled only as an individual support ticket, and is logged as an input to the bias-monitoring and model-improvement work described in Section 7.
13. Review, Monitoring, and Continuous Improvement
- This policy is reviewed at least annually, and immediately upon any material new AI capability (a new detection category, a move to server-side/automated processing, a new sub-processor).
- Appendix B tracks open commitments with an owner and target; it is reviewed at the same cadence and updated as items close.
- Baseline benchmarks its practices informally against the NIST AI RMF, ISO/IEC 42001, the OECD AI Principles, and the GovAI Coalition's municipal vendor disclosure standard (Appendix A) rather than pursuing formal certification at this stage, formal certification (e.g., ISO/IEC 42001) is a candidate future step as Baseline's AI footprint grows, flagged here for leadership's ongoing consideration rather than committed to on a fixed date.
This table shows how Baseline's practices map to the trustworthiness characteristics in the NIST AI Risk Management Framework (AI RMF 1.0) and the value-based principles in the OECD AI Principles (2024 update), the two most widely referenced AI governance frameworks in North America. It also is the frame municipal AI-governance bodies like the GovAI Coalition use when evaluating vendor disclosures such as the AI Vendor Fact Sheet Baseline completed for the City of Worcester.
|
Framework characteristic / principle |
Source |
Where Baseline addresses it |
|---|---|---|
|
Valid & reliable |
NIST AI RMF |
Human-review gate on every detection (Section 6); planned bias/accuracy assessment before any enforcement-linked use (Section 7). |
|
Safe |
NIST AI RMF |
No automatic enforcement/billing action from any detection (Section 4.2, 6). |
|
Secure & resilient |
NIST AI RMF |
Encryption, least-privilege access, staged model releases (Section 8). |
|
Accountable & transparent |
NIST AI RMF / OECD |
Named policy owner (Section 3); AI Fact Sheet provided before activation (Section 9). |
|
Explainable & interpretable |
NIST AI RMF / OECD |
Photo + short video clip + GPS + timestamp accompany every detection (Section 9). |
|
Privacy-enhanced |
NIST AI RMF / OECD (human rights & privacy) |
Opt-in per route, image/video only (no audio), DPA governs use, retention/PII items tracked openly (Section 5, 10, Appendix B). |
|
Fair, harmful bias managed |
NIST AI RMF / OECD |
Bias risk stated explicitly, mitigations and roadmap in Section 7. |
|
Human rights & democratic values |
OECD |
Human-in-the-loop by design (Section 6); jurisdiction-specific surveillance-ordinance check before deployment (Section 10). |
|
Robustness, security & safety |
OECD |
Section 8; inherits Baseline's broader IT security program. |
|
Inclusive growth & well-being |
OECD |
Detections framed as operational leads that improve service delivery (e.g., faster pothole repair, more reliable pickups), not as resident-facing enforcement tools. |
Sources and Further Reading
This policy was informed by the following external frameworks and resources, current as of August 2026:
- NIST AI Risk Management Framework (AI RMF 1.0), airc.nist.gov/airmf-resources/airmf/0-ai-rmf-1-0/
- OECD AI Principles (2024 update), oecd.ai/en/ai-principles
- ISO/IEC 42001:2023, AI management systems, iso.org/standard/42001
- GovAI Coalition municipal vendor fact sheet and governance resources, the format underlying the AI Vendor Fact Sheet the City of Worcester used to evaluate Baseline.