Reflected Networks AI Acceptable Use Policy

1.1 Definitions

“AI System” means any artificial intelligence, machine learning, generative AI, or large language model application, agent, pipeline, or model (whether pretrained, fine-tuned, or trained from scratch) that Customer develops, deploys, hosts, trains, fine-tunes, or operates using the Services, including any associated training data, prompts, embeddings, weights, and Outputs.

“Outputs” means any content, code, decision, prediction, image, audio, video, or other material generated, produced, or returned by an AI System. This definition includes any third-party AI agent, assistant, or tool (e.g., Claude, Gemini, ChatGPT, or similar agentic or coding/operations tools) that Customer installs, enables, or grants access to operate on, connect to, or interact with the Services, whether running locally on the Services or connecting to them remotely (e.g., via API, an MCP (Model Context Protocol) server, plugin, browser extension, or similar integration).

1.2 Customer Sole Responsibility

Customer is solely responsible for: (i) the legality, licensing, and provenance of all data used to train, fine-tune, retrieve, or prompt an AI System, including obtaining any consents or licenses required for personal data, copyrighted works, or biometric data; (ii) compliance with all Laws applicable to the AI System's design, training, and use, including data protection and privacy law (e.g., GDPR, CCPA/CPRA, HIPAA), sector-specific regulation (e.g., financial services, healthcare, employment), export control and sanctions law as applicable to models, weights, or datasets, and AI-specific regulation where applicable (e.g., the EU AI Act); and (iii) the accuracy, appropriateness, and legality of all Outputs and any decision made or action taken in reliance on them.

1.3 Prohibited AI Uses

In addition to the prohibitions in the Prohibited Use Section of the AUP (located at reflected.net/aup.php), an AI System must not be used to:

a) Generate, process, or distribute child sexual abuse material, including AI-generated or AI-altered (“deepfake”) depictions of minors; RN will treat such Content the same as CSAM under the AUP, including mandatory reporting to NCMEC and law enforcement;

b) Generate non-consensual intimate imagery or other “deepfake” content depicting a real person without that person's consent as otherwise set forth on RN’s NCIVD Notice and Takedown Policy (located at reflected.net/NCIVDPolicy.php);

c) Impersonate, or clone the voice, image, or likeness of, a real person for purposes of fraud, deception, or harassment;

d) Generate malware, exploits, phishing content, or disinformation/spam campaigns, or otherwise automate conduct that the AUP already prohibits when done manually;

e) Circumvent rate limits, security controls, or Content moderation of any third-party model, API, or platform accessed through the Services in violation of that provider's terms.

f) Attempts to escalate privileges, break out of, or otherwise access resources beyond the environment, account, or container provisioned to Customer, including RN’s underlying infrastructure, host, or hypervisor, or the environment of another RN customer;

g) Performs reconnaissance, scanning, probing, credential harvesting, or other unauthorized access attempts against RN’s network, another customer’s environment, or any local, connected, or third-party network, device, or system that the AI System is able to reach through its tool-use, code-execution, browsing, or API/network-access capabilities.

Because AI Systems - particularly autonomous or agentic systems with tool-use, code-execution, or network-access capabilities - may take actions their operator did not explicitly intend (including as a result of prompt injection, misconfiguration, or emergent behavior), Customer is responsible for such conduct to the same extent as if Customer had performed the action directly. This is consistent with, and does not narrow, the AUP’s general rule that a violation committed unintentionally or without Customer’s authorization remains a violation, and RN’s discretion to treat any other abuse of the Services as an AUP violation even where not specifically enumerated above.

1.4 No RN Review, Endorsement, or Warranty

RN does not review, moderate, monitor, or endorse Customer's AI System, its training data, or its Outputs, and has no obligation to do so, notwithstanding any administrative or managed-service access RN personnel may have to Customer's environment for infrastructure purposes (e.g., patching, backups, uptime monitoring). RN makes no representation, warranty or guarantee regarding the accuracy, reliability, safety, fitness for purpose, or legality of any AI System or its Outputs, and disclaims liability for any decision, harm, or loss arising from Customer's or any User's or third party's reliance on such Outputs.

1.5 No Assumption of Data Controller/Processor Role

Managed hosting services (including any administrative access, monitoring, patch management, or technical support RN provides) do not, by themselves, make RN a controller, processor, or sub-processor of any personal data processed within Customer’s AI System. If Customer’s use of the Services requires RN to process personal data on Customer’s behalf within the meaning of applicable data protection law, the parties will execute a separate data processing agreement (DPA); absent such an agreement, Customer represents and warrants that no such processing role is required or requested of RN.

1.6 Resource Use, Metering, and Suspension

AI training and inference workloads (particularly GPU-bound or high-throughput workloads) may be metered, capacity-planned, or subject to a dedicated/isolated hosting plan at RN's discretion where they materially affect shared infrastructure, backup windows, or other Customers' use of the Services. RN may throttle, rate-limit, or suspend an AI System without prior notice where RN reasonably believes it is degrading network or service performance, and SLA credits do not apply to any interruption attributable to Customer's AI workload exceeding its provisioned capacity.

1.7 Intellectual Property and Indemnification

Customer represents and warrants that it holds all rights, licenses, and consents necessary to use its training data, inputs, and any third-party models incorporated into its AI System. Customer will defend, indemnify, and hold harmless RN from and against any third-party claim, loss, liability, or expense (including reasonable attorneys' fees) arising out of or related to: (i) Customer's training data or inputs; (ii) Customer's AI System or its configuration; (iii) any Output; or (iv) Customer's or any User's violation of this Rider or the AUP.

1.8 Third-Party AI Agents and Remote Access Tooling

This Rider applies equally where Customer installs, enables, or grants access to a third-party AI agent, assistant, or coding/operations tool (including products such as Claude, Gemini, ChatGPT, or similar agentic tools) to operate on the Services, or where Customer or a third party connects such an agent to the Services remotely via API, an MCP (Model Context Protocol) server, plugin, browser extension, or similar integration (“Third-Party AI Agent”). Customer is responsible for a Third-Party AI Agent’s access and conduct to the same extent as for any AI System under this Rider, including under Sections 1.2, 1.3, and 1.7.

Customer must scope any credentials, API keys, or account access granted to a Third-Party AI Agent to the minimum access necessary for its intended purpose, and must not grant a Third-Party AI Agent administrator, root, or other privileged credentials to the Services unless necessary and subject to Customer’s own monitoring.

Traffic, requests, or actions originating from or directed by a Third-Party AI Agent are subject to the AUP’s Security Violations, Network Abuse, and Vulnerability Testing provisions to the same extent as traffic from any other source, regardless of whether the underlying conduct was autonomous, agent-initiated, or the result of the agent’s own troubleshooting or exploration rather than a deliberate instruction from Customer. RN may rate-limit, quarantine, or suspend access attributable to a Third-Party AI Agent, and may treat resource exhaustion or repeated triggering of RN’s security controls caused by such an agent as a violation of this Rider and the AUP, without any obligation to first distinguish well-intentioned agent activity from malicious activity.

Customer acknowledges that a Third-Party AI Agent’s operator (e.g., the agent’s model or platform provider) may receive, process, log, or retain information about Customer’s environment - including file contents, configuration, credentials inadvertently exposed to the agent, or network topology - as part of the agent’s normal operation, over which RN has no visibility or control. Customer is solely responsible for evaluating that exposure against its own security and confidentiality obligations before granting a Third-Party AI Agent access to the Services.

Effective Date: September 7, 2026


Managed Hosting
Custom Solutions
Our Company