Liferay Trust Center /

Responsible AI

As a provider of products and services designed to help our customers create digital experiences, we are excited about the potential of AI to drive innovation and create value.

Responsible AI

Responsible AI

As a provider of products and services designed to help our customers create digital experiences, we are excited about the potential of AI to drive innovation and create value. We also recognize, however, that the development and deployment of AI technologies comes with significant ethical considerations and potential risks.

Liferay is committed to conducting business ethically and in full compliance with the relevant regulations. We have identified Responsible AI as an additional key focus area for our compliance efforts, with the ultimate goal of ensuring that Liferay harnesses AI responsibly and in alignment with our values and applicable laws.

To this end, Liferay has implemented an AI Management System (AIMS) that has undergone a verification by external auditors and received an ISO42001 certification. The AIMS provides a structured approach to risk-based compliance and responsible conduct in AI -related activities, reflecting Liferay's commitment to the core principles of Responsible AI, and applicable regulatory frameworks, including the EU AI Act and data protection laws.

Core Principles of Responsible AI

Liferay's Responsible AI Program is guided by the following principles that apply across the entire AI lifecycle and are embedded into risk assessments, controls, and operational procedures:

Environmental and Societal Wellbeing

We consider sustainability and the social impact of our AI use.

Fairness

We promote ethical, inclusive, and non-discriminatory AI operations.

Transparency and Explainability

We strive to give preference to AI Systems with traceable outputs that inform users of their use.

Human Oversight

We ensure that AI supports human decision-making and remains subject to proper oversight.

Robustness, Safety, and Security

We ensure that the AI systems we use are designed to be technically sound, resilient, and protected against threats.

Data Protection

We adhere to the privacy-by-design principle and comply with all data protection laws.

Respect for Intellectual Property

We ensure that the design, eventual training, and use of AI systems do not infringe on third-party intellectual property and that Liferay's own IP is protected.

Prevention of Misuse

We deploy continuous monitoring, access controls, and training to prevent intentional or unintentional misuse.

Accountability

We assign clear roles, responsibilities, and maintain extensive documentation to ensure compliance.

Key Operational Measures for AI Systems

To put these core principles into action, Liferay has implemented rigorous procedures across the AI system lifecycle:

Risk and Impact Assessments

Formal AI Risk and Impact Assessments are conducted by an inter-disciplinary team of experts in all relevant areas for all AI Systems prior to deployment to identify the level of risk and potential impact on Liferay and other interested parties. Systems are classified, their potential risks and impacts are assessed and mitigating measures are implemented.

AI Use Case Registry

We maintain a centralized registry of approved AI systems, documenting their purpose, classification, business owner and applicable risk level.

Working Instructions

Binding instructions are provided to all employees detailing the approved AI systems, their permitted use cases, and limitations to ensure compliance with the Core Principles of Responsible AI.

Vendor Assessments

AI Vendors undergo due diligence, which includes reviewing their compliance documentation and contractual safeguards before acquisition.

Data Management Protocols

Rigorous procedures ensure data quality, bias detection and mitigation, privacy-enhancing techniques, and robust access controls for all data used in AI systems.

Training and Awareness

We deliver a company-wide training program on responsible AI to ensure everyone at Liferay is aware of the policies, procedures, and their specific responsibilities.

Incident Response

A clear policy and team are in place to manage, triage, and respond to AI incidents promptly and transparently.

Communication and Transparency

Internal updates and external disclosures regarding AI use, including risk disclosures and disclaimers, are managed through defined workflows and channels like the Trust Center to maintain transparency with all stakeholders.

Continuous Monitoring and Reassessment

Approved AI systems are subject to regular performance and compliance reviews, and a mandatory reassessment is triggered by new features, changes in purpose, or an AI Incident.

Review and Remediation

A crucial part of the AIMS is the commitment to assurance and continuous improvement, which includes regular reviews and auditing. The AIMS is subject to periodic reviews of the AIMS effectiveness, which include regulatory developments, emerging risks, program metrics, and audit results.

Internal audits are conducted annually. Furthermore, the comprehensive set of policies, procedures, and controls that constitute Liferay's AIMS is specifically designed to support external audit and certification, aligning with international standards for AI Management. 

Liferay’s AIMS framework is certified in accordance with the ISO 42001 standard (a recognized international standard for AI Management Systems), which demonstrates Liferay's externally validated commitment to responsible and compliant AI development, design and use. 

AI in Liferay Offerings

Liferay's strategy focuses on a "Bring Your Own AI" (BYO-AI) model rather than providing AI systems as part of its offerings. Liferay enables integrations with customers’ own AI systems, as further outlined in our documentation. That being said, for the purposes of these integrations, the customer is responsible for its own use of any AI systems the customer chooses to integrate with Liferay offerings. 

Liferay will notify customers of any upcoming product releases that might involve integrated AI capabilities or features provided by Liferay in advance.

Liferay only leverages AI offerings of reliable industry leaders that come with enterprise grade privacy and security assurances. Liferay does not (and does not allow any third parties) to use any data that customers provide to Liferay to train AI models without customers’ permission.     

Questions or Concerns?

Reach out to us via ai@liferay.com.

Liferay Trust Center / Responsible AI

As a provider of products and services designed to help our customers create digital experiences, we are excited about the potential of AI to drive innovation and create value.

Responsible AI

As a provider of products and services designed to help our customers create digital experiences, we are excited about the potential of AI to drive innovation and create value. We also recognize, however, that the development and deployment of AI technologies comes with significant ethical considerations and potential risks.


Liferay is committed to conducting business ethically and in full compliance with the relevant regulations. We have identified Responsible AI as an additional key focus area for our compliance efforts, with the ultimate goal of ensuring that Liferay harnesses AI responsibly and in alignment with our values, applicable laws, and terms governing our AI Offerings.

 
To this end, Liferay has implemented and maintains an AI Management System (AIMS) that has undergone verification by external auditors and received an ISO 42001 certification. The AIMS provides a structured approach to risk-based compliance and responsible conduct in AI-related activities, reflecting Liferay's commitment to the core principles of Responsible AI, and applicable regulatory frameworks, including the EU AI Act and data protection laws.
 

AI in Liferay Offerings

 

Liferay defines clear frameworks governing the use and integration of Artificial Intelligence and AI agents across its solutions:


Covered Materials: AI used to assist Liferay in generating code or materials to be provided to the customer.

 

Covered Subscription Benefits: AI integrated to support core services such as support, maintenance, customer portal, or other web-based or cloud services.

AI Features: Native AI capabilities built directly into Liferay’s product offerings either as part of the services already used by the customer or as a stand-alone offering such as Liferay AI Hub.

 

Customer AI: AI that is not provided by Liferay but is chosen by the customer and its integration is enabled through supported APIs, allowing customers to connect their own or third-party AI models. In case of Customer AI, the customer is responsible for the integration, security, performance, and the cost of Customer AI and for complying with the third-party model terms applicable to the AI they chose.

 

Free Services: Non-production AI offerings that are not intended for commercial or production use but provided for trial or previews "as is" using synthetic data only, prohibiting the use of real personal data, public output disclosure, or third-party AI agent exposure. Standard contractual commitments regarding security, data protection, data retention, warranties, availability and support do not apply.

 

Liferay will notify customers of any upcoming product releases that might involve integrated AI capabilities or features provided by Liferay in advance.

 

Liferay only leverages AI offerings of reliable industry leaders that come with enterprise-grade privacy and security assurances. Liferay does not (and does not allow any third parties to) use any data that customers provide to Liferay to train AI models without customers’ permission.

 

Core Principles of Responsible AI

 

Liferay's Responsible AI Program is guided by the following principles that apply across the entire AI lifecycle and are embedded into risk assessments, controls, and operational procedures:

Environmental and Societal Wellbeing

We consider sustainability and the social impact of our AI use.

 

Fairness

We promote ethical, inclusive, and non-discriminatory AI operations.

 

Transparency and Explainability

We strive to give preference to AI Systems with traceable outputs that inform users of their use. We establish transparency by clearly marking AI-generated code, designating communication channels fully relying on AI or involving AI agents providing responses or actions generated by AI without human intervention, announcement and labeling of offerings and features integrating or enabling integration of AI or AI agents; and providing clear documentation and instructions to support compliance with the use of AI Features.

 

Human Oversight

We ensure that AI supports human decision-making and remains subject to proper oversight. Through our Human-In-The-Loop framework, all AI-generated code is reviewed, tested, and validated by human developers before being incorporated into our products and solutions.

 

Robustness, Safety, and Security

We ensure that the AI systems we use are designed to be technically sound, resilient, and protected against threats.

 

Data Protection

We ensure that our use of personal data in the context of the AI systems we use are designed to ensure compliance with the applicable data protection laws. Liferay does not (and does not allow any third parties to) use customer’s personal data or content, confidential information or proprietary source code to train, refine, or improve AI models without explicit permission.

 

Respect for Intellectual Property

We ensure that the design, eventual training, use of AI systems and Liferay software and deliverables created or modified with the assistance of AI do not infringe on third-party intellectual property, and that Liferay's own IP is protected. Customers fully own or receive usage rights for all AI-generated code in deliverables, and Liferay backs eligible AI code and outputs with IP assurances and indemnification against third-party claims.
For Covered Subscription Services inputs submitted by customers remain under the ownership of their original owners, while Liferay owns generated outputs and grants customers a royalty-free license to use them throughout their subscription term. For AI Features and Customer AI, inputs remain under the ownership of their original owners, while outputs generated by AI Features or Customer AI are customer content. 
 

Prevention of Misuse
We deploy continuous monitoring, access controls, and training to prevent intentional or unintentional misuse, ensuring compliance with Liferay’s AIMS and alignment with our Acceptable Use Policy (AUP). Customers are also required to comply with the AUP, which remains subject to updates as regulatory requirements evolve.

 

Accountability

We assign clear roles and responsibilities, maintaining comprehensive logging of AI tools used, identified risks, implemented controls, and Human-In-The-Loop reviews conducted.


Key Operational Measures for AI Systems

 

To put these core principles into action, Liferay has implemented rigorous procedures across the AI system lifecycle:

 

Risk and Impact Assessments

Formal AI Risk and Impact Assessments are conducted by an inter-disciplinary team of experts in all relevant areas for all AI Systems prior to deployment to identify the level of risk and potential impact on Liferay and other interested parties. Systems are classified, their potential risks and impacts are assessed and mitigating measures are implemented.

 

AI Use Case Registry

We maintain a centralized registry of approved AI systems, documenting their purpose, classification, business owner, and applicable risk level.

 

Working Instructions

Binding instructions are provided to all employees detailing the approved AI systems, their permitted use cases, and limitations to ensure compliance with the Core Principles of Responsible AI.

Vendor Assessments

AI Vendors undergo due diligence, which includes reviewing their compliance documentation and contractual safeguards before acquisition.

 

Data Management Protocols

Rigorous procedures ensure data quality, bias detection and mitigation, privacy-enhancing techniques, and robust access controls for all data used in AI systems.

 

Training and Awareness

We deliver a company-wide training program on responsible AI to ensure everyone at Liferay is aware of the policies, procedures, and their specific responsibilities.

 

Incident Response

A clear policy and team are in place to manage, triage, and respond to AI incidents promptly and transparently.

 

Communication and Transparency

Internal updates and external disclosures regarding AI use, including risk disclosures and disclaimers, are managed through defined workflows and channels like the Trust Center to maintain transparency with all stakeholders. 

Continuous Monitoring and Reassessment

Approved AI systems are subject to regular performance and compliance reviews, and a mandatory reassessment is triggered by new features, changes in purpose, or an AI Incident. While Liferay monitors the performance of AI and AI agents utilized in generating Liferay software or deliverables, customers are responsible for monitoring the performance of the AI features integrated into Liferay’s offerings and Customer AI deployed by the customer.

Review and Remediation

A crucial part of the AIMS is the commitment to assurance and continuous improvement, which includes regular reviews and auditing. The AIMS is subject to periodic reviews of the AIMS effectiveness, which include regulatory developments, emerging risks, program metrics, and audit results.
Internal audits are conducted annually. Furthermore, the comprehensive set of policies, procedures, and controls that constitute Liferay's AIMS is specifically designed to support external audit and certification, aligning with international standards for AI Management.
Liferay’s AIMS framework is certified in accordance with the ISO 42001 standard (a recognized international standard for AI Management Systems), which demonstrates Liferay's externally validated commitment to responsible and compliant AI development, design, and use.
 

Questions or Concerns?

Reach out to us via ai@liferay.com.