Concepts
How HRS uses AI
Where AI appears in HumanRisk Shield, which provider it uses, what it can and can't see, and the limits around it.
HumanRisk Shield uses AI to help people find answers, draft content and sort reported email faster. It doesn't make decisions about people. In HRS Learn, anything the AI proposes that would send, schedule or change something waits for an admin to approve it; HRS Triage acts on its own only within limits an admin sets.
Where you will meet it
| Feature | What the AI does |
|---|---|
| Ask HRS AI | Answers questions about the page you are on, in HRS Learn and in HRS Triage. In HRS Learn, employees get a learning coach that only sees their own learning, and admins get answers about their organization. See Ask HRS AI in Triage. |
| Reported email | Gives a first verdict on an email someone reported: malicious, spam, safe or unknown. In HRS Triage it supports the analyst's decision. See How a reported email becomes a case. |
| Content drafting | Drafts training content, policies and practice phishing for an admin to edit and approve. |
| HRS Exposure | Writes a short summary of a domain's exposure. If AI is unavailable, a fixed summary is used instead. |
Who provides the model
Anthropic, listed on the sub-processor register. Data sent to it is used only to return the answer to you. HRS doesn't let its AI providers use customer personal data to train or improve general models, and doesn't do so itself.
What it can see
Ask HRS AI works with the same permissions as the person asking. An employee's question can only draw on their own learning; an admin's can draw on their organization; nobody's can reach another organization.
What it can't do on its own
- In HRS Learn, Ask HRS AI can't send, schedule or run anything. Proposed actions wait for an admin to approve them.
- It doesn't make decisions about people. Risk scores come from what people actually did, not from a model's opinion of them.
- In HRS Triage, automated actions are bounded by the mode, scope and permissions an admin sets. See AI settings, your own AI key and cost control.
Limits
To keep cost and misuse in check, Ask HRS AI in HRS Learn allows up to 20 questions per person per hour and 200 per organization per day by default. HRS can switch it off for everyone at once if it ever needs to.
Using your own key
HRS Triage can send its AI requests to your own Anthropic account instead of HRS's. HRS Learn has a Your own AI keys page at /admin/settings/ai-keys; if it says key storage isn't configured yet, contact support.
The website chat
The chat on humanriskshield.com is a separate assistant for visitors. It also uses Anthropic, strips email addresses, phone numbers and card numbers before anything is sent, and HRS keeps no transcripts.