AI disclosure
Cortex Foundation trains and publishes its own models, and serves them in products. This page states plainly what those models do, what they do not do, what happens to the text you send them, and which uses we refuse. It is written to be checked against our behaviour, not to reassure you.
This is the version in force since [À REMPLIR PAR MATHIS : date de cette version]. Earlier versions are available on request; the date at the top of this page is the one that applies.
1 What the models do
Cortex Mini 1 is the default model in Cortex Chat. It generates text and code in response to a prompt. Cortex also offers image generation and origin checking as product features.
These are generative statistical models. They predict a continuation; they do not consult a database of verified facts, and they have no access to a source of truth unless a product explicitly gives them one — which is what Deep Research does when it cites the pages it read.
Each model card states the architecture, the parameter count, the training data window, the context length and the evaluation results. It is the authoritative description of that model, and it prevails over this page.
2 What the models do not do
They do not know anything that happened after their training window, unless a product gives them a retrieval tool with the current date in it. They do not verify a claim they have not been asked to verify. They do not have memory of a conversation you closed, unless you saved it and the product reads it back.
They do not act on the world on their own. Cortex Code and Cortex CLI write files and run commands only where you have pointed them and only with the permission you granted. Cortex Security reads a repository and reports; it does not modify it in the course of a review.
They are not a doctor, a lawyer, an accountant or an engineer of record. An output is a draft. The judgment, the verification and the signature remain with a human.
3 Training data
The models are trained on [À REMPLIR PAR MATHIS : composition réelle du corpus — parts de données publiques, de données sous licence, de données produites en interne, et de retours utilisateurs, avec leurs ordres de grandeur].
User conversations are not used for training by default. Where a conversation is used for training, it is because the user turned that option on, for that conversation or for their account, and the consent can be withdrawn at any time from the same place. We do not treat "continued use of the service" as consent to train on your content.
We respect robots directives and the licensing terms attached to a source. Publishing a work openly does not place it in the public domain, and we do not treat it that way.
Rightholders can obtain [À REMPLIR PAR MATHIS : mécanisme réel — liste des sources, filtrage a posteriori, retrait des données], and can request removal of their work by writing to [À REMPLIR PAR MATHIS : adresse e-mail de contact droits d'auteur]. Those requests are answered by a person, and the answer states what was actually removed.
4 Prompt retention
Your prompts and the generated outputs are stored while the conversation exists, so that you can reopen it, and they are used to keep your account working and to detect abuse.
| Data | Retained | Used for training |
|---|---|---|
| Prompts and outputs, training disabled (default) | life of the account, then [À REMPLIR PAR MATHIS : délai de purge] | no |
| Prompts and outputs, training enabled | [À REMPLIR PAR MATHIS : durée] | yes, until consent is withdrawn |
| Prompts on a service used without an account | [À REMPLIR PAR MATHIS : durée] | no |
| Abuse and security logs | [À REMPLIR PAR MATHIS : durée, 12 mois par défaut] | no |
| Deleted conversations | [À REMPLIR PAR MATHIS : délai de purge en sauvegarde, 35 jours par défaut] | no |
- Data
- Prompts and outputs, training disabled (default)
- Retained
- life of the account, then [À REMPLIR PAR MATHIS : délai de purge]
- Used for training
- no
- Data
- Prompts and outputs, training enabled
- Retained
- [À REMPLIR PAR MATHIS : durée]
- Used for training
- yes, until consent is withdrawn
- Data
- Prompts on a service used without an account
- Retained
- [À REMPLIR PAR MATHIS : durée]
- Used for training
- no
- Data
- Abuse and security logs
- Retained
- [À REMPLIR PAR MATHIS : durée, 12 mois par défaut]
- Used for training
- no
- Data
- Deleted conversations
- Retained
- [À REMPLIR PAR MATHIS : délai de purge en sauvegarde, 35 jours par défaut]
- Used for training
- no
You can delete a conversation from the interface, and it stops being readable immediately. We do not promise that it is off our disks in the same second; that is what the retention column above means.
5 Accuracy, limits and hallucinations
A generative model produces fluent text whether or not it is correct. The failure mode — a confident, well-formed, false statement — is called a hallucination, and it is a property of the method, not a bug that a later version will remove.
Expect it especially on: citations and references, exact figures, dates, the content of a document the model has not been given, and API signatures. Treat every citation as unverified until you have opened it.
Every model we publish comes with an evaluation report that states where the model fails, not only where it succeeds. Those reports are published even when they are unflattering, and they are published before the weights. Read them before choosing a model.
What reduces the risk: giving the model the source document rather than asking it to recall one; asking it to quote; asking for its uncertainty; and having a person check anything that will be acted on. What does not reduce the risk: a confident tone. Fluency is not evidence.
6 Prohibited high-risk uses
Under Article 5 of the European AI Act, and under our own terms, the following uses are prohibited outright and are not made lawful by our licence:
- subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause significant harm;
- exploiting a vulnerability of a person or a group because of age, disability or a specific social or economic situation, to distort their behaviour in a way that causes significant harm;
- social scoring by a public or private actor, producing detrimental or unfavourable treatment unrelated to the context in which the data was generated;
- predicting the risk of a natural person committing a criminal offence, on the basis of profiling alone;
- building a facial-recognition database by untargeted scraping of images;
- inferring emotion in the workplace or in an educational setting;
- biometric categorisation to deduce race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation.
Beyond those prohibitions, we refuse — and the terms of service forbid — the uses listed in 2.2.4, and in particular decisions about people's access to employment, credit, housing, healthcare, education or essential public services without qualified human review.
7 Human oversight
A deployed AI system that a person relies on must leave that person able to understand it, to contradict it and to stop it.
In our own products this means: the model states its uncertainty rather than smoothing it over; every claim from Deep Research carries a citation you can open; an action that modifies your files is shown for confirmation before it runs; and there is always a way to do the task without the model.
In your own deployments, put a named human in the loop wherever an output affects someone's rights or access to a service, and record who reviewed what. The person who signs remains accountable; the model is not a shield.
8 Reporting a problem
Report a harmful output, a security issue in a Cortex service, or a model that behaves in a way its card does not describe, to [À REMPLIR PAR MATHIS : adresse e-mail de signalement]. For security reports, do not open a public issue first: use [À REMPLIR PAR MATHIS : canal de divulgation, ou l'adresse dédiée].
We acknowledge a report, we tell you what we found, and we publish the fix in the changelog. Where a report reveals a systematic failure — a class of prompt that defeats a safeguard, a gap in an evaluation — we say so in the model card of the affected version. A model that fails is not withdrawn from the record; it is annotated.
9 Alignment with the European AI Act
Cortex Foundation acts as a provider of general-purpose AI models within the meaning of Regulation (EU) 2024/1689, and as a provider of an AI system for its own products.
| Obligation | Where it is discharged |
|---|---|
| Technical documentation of the model, including training and evaluation process | model cards and evaluation reports, on the Models and Research pages |
| Information for downstream providers | the model card and its licence, published with the weights |
| Copyright policy, including a template for reservations of rights | section 2.4.3 of this document, and [À REMPLIR PAR MATHIS : emplacement de la politique droits d'auteur] |
| Publicly available summary of the training content | [À REMPLIR PAR MATHIS : emplacement de ce résumé] |
| Serious-incident reporting to the AI Office | procedure held by [À REMPLIR PAR MATHIS : fonction responsable], reportable through 2.4.8 |
| Transparency towards users of an AI system | sections 2.4.1, 2.4.2 and 2.4.5 of this document |
| Prohibited practices | section 2.4.6 |
- Obligation
- Technical documentation of the model, including training and evaluation process
- Where it is discharged
- model cards and evaluation reports, on the Models and Research pages
- Obligation
- Information for downstream providers
- Where it is discharged
- the model card and its licence, published with the weights
- Obligation
- Copyright policy, including a template for reservations of rights
- Where it is discharged
- section 2.4.3 of this document, and [À REMPLIR PAR MATHIS : emplacement de la politique droits d'auteur]
- Obligation
- Publicly available summary of the training content
- Where it is discharged
- [À REMPLIR PAR MATHIS : emplacement de ce résumé]
- Obligation
- Serious-incident reporting to the AI Office
- Where it is discharged
- procedure held by [À REMPLIR PAR MATHIS : fonction responsable], reportable through 2.4.8
- Obligation
- Transparency towards users of an AI system
- Where it is discharged
- sections 2.4.1, 2.4.2 and 2.4.5 of this document
- Obligation
- Prohibited practices
- Where it is discharged
- section 2.4.6
Where a Cortex model is integrated into a product placed on the market by someone else, that provider carries the obligations of the AI system and Cortex Foundation carries those of the model. We supply the documentation needed for that, and we ask integrations to keep the provenance markers intact.
This section describes our reading of the regulation in force at the date at the top of this page. It is not legal advice, and it does not replace the regulation.
Frequently asked questions
No, not by default. Training on user conversations is off, and it stays off until you enable it for a conversation or for your account. Enabling it is a consent you can withdraw, and withdrawing it stops future training without affecting what was already learned.
Yes. Your account settings export your data in a machine-readable format and delete your account. The Privacy policy states how long each category is kept and how long backups take to roll off.
The one written in that model's card, and it prevails over this page. Model cards are published with the weights, before the weights, together with the evaluation report.
The other documents
Read the other three documents.
Each one is dated at the top; the version in force is the one you are reading.
Legal notice
Who publishes this site, who is responsible for what it says, and under which licences the models are released.
Terms of service
These terms govern your use of cortex.foundation and of the Cortex services reachable from it.
Privacy policy
This policy explains which personal data Cortex Foundation collects, why, on which legal basis, for how long it is kept, and how you exercise your rights over it.