Page content
This Algorithmic Transparency Recording Standard (ATRS) record explains how the Royal Armouries AI avatar of Thomas Wardley works, why we are trialling it, and how visitor data and risks are managed.
Organisation: Royal Armouries
Phase: Public Beta
Region: Yorkshire and the Humber
ATRS version: v4.0
- About the AI avatar
- Ownership and responsibilities
- How and why we use the avatar
- How the avatar is used and supervised
- How the system works
- AI models and performance
- Data used to develop and support the system
- Visitor interaction data and privacy
- Impact assessments, risks and safeguards
About the AI avatar
Name
AI Avatar of "Thomas Wardley"
Description
A fictional informational AI avatar answers spoken visitor questions about the collection and visiting the site, in character and aloud. The touchscreen kiosk bears CX Hero branding only; the avatar is not presented as Royal Armouries staff.
Why it is used. To assess public response to and engagement with AI avatars and gauge their effectiveness in delivering museum and collection information on demand.
Website URL
N/A
Contact email
florence.symington@armouries.org.uk
Ownership and responsibilities
Organisation or department
Royal Armouries
Team
Brand & Audience
Senior responsible owner
Director of Brand & Audience
Third party involvement
Yes
Third party
Abyshire Technology Ltd
Companies House Number
14718576
Third party role
Conception, design and development of the technology including hardware and software, and owner of the proprietary technology.
Procurement procedure type
N/A
Collaborative pilot project with no cost to the public purse
Third party data access terms
Third-party access to data is governed by a Data Processing Agreement made under Article 28 of the UK GDPR. Third parties may access or process data only to the extent necessary to provide the contracted service, under the documented instructions of the controller, and subject to appropriate confidentiality, security, retention and deletion requirements.
The system does not seek, require or store visitor identity. Live speech is processed ephemerally during push-to-talk solely to generate text and is not recorded, logged or retained. The character does not repeat a visitor's name and is instructed to refuse requests to remember personal information such as a name, age, school or address. Conversation history is erased from the kiosk and server after 60 seconds of inactivity. Text transcripts are retained for no longer than 30 days, are excluded from process logs, and are subject to personal-data redaction.
Data is made available to Abyshire LLM v3 Heavy only as request-time context necessary to generate a response. Processing, hosting, backups and disaster recovery are restricted to the UK.
No additional third party, sub-processor or international transfer may be introduced without prior assessment and the controller's written authorisation. Where an international transfer were proposed, an appropriate UK GDPR transfer mechanism and associated safeguards would be required before access could be granted.
How and why we use the avatar
Detailed description
A free-standing touchscreen kiosk in the museum. A visitor holds a button and asks a spoken question about the collection or visiting. A fictional animated historical character answers aloud in the visitor's language, drawing on the museum's catalogue and approved visitor-information wording.
Benefits
The principal anticipated benefit is to provide visitors with an engaging, conversational way to access museum and collection information on demand. The AI avatar enables visitors to ask questions in natural speech and receive spoken responses in their own language, potentially making collection and visitor information easier to access for a wider range of audiences.
The system can draw directly on Royal Armouries collection records, approved visitor information and associated collection photography, enabling visitors to explore objects and practical museum information through questions rather than having to navigate conventional interfaces or predefined interpretation.
The pilot will allow Royal Armouries to assess whether conversational AI increases visitor engagement with museum and collection information, how visitors respond to an AI historical character, and whether this approach is effective as a form of gallery interpretation. The results will provide evidence to inform decisions about any future use of conversational AI within the museum.
Additional potential benefits include multilingual access, with the system supporting end-to-end operation in 32 languages, and the ability to provide information responsively according to individual visitor questions. The six-month pilot provides an opportunity to evaluate these benefits in a controlled, supervised environment before deciding whether the service should be continued or expanded.
Previous process
N/A
Alternatives considered
N/A
How the avatar is used and supervised
Integration into broader operational process
CX Hero is integrated into the museum’s visitor experience as a standalone, public-facing interpretation and information service within a supervised gallery. A visitor initiates an interaction by holding a button and asking a spoken question. The system converts the speech to text, uses an AI language model acting as a fictional historical museum-guide character to formulate a response, and provides the answer through synthetic speech, an animated character and an on-screen transcript.
The tool provides visitors with information about the Royal Armouries collection, museum and site. For collection questions, it draws on Royal Armouries catalogue records and can display associated catalogue photographs and museum metadata. For visitor-information questions, it draws on a verified knowledge base based on museum-approved information. This information is used directly by the visitor to support their exploration and understanding of the collection and to answer practical questions about their visit.
CX Hero does not support or automate an operational decision about the visitor. It does not assess, score, rank, screen, admit, refuse or prioritise an individual, allocate resources, confer an entitlement or build a visitor profile. Its output is informational rather than decisional. This distinction is important because the ATRS guidance asks this field to make clear the degree of automation within the broader process.
Certain operational and safeguarding interactions are deliberately separated from generative AI. Questions concerning fire, lost children, medical emergencies or visitor distress are intercepted by a non-generative safety mechanism and answered using fixed, museum-approved wording without invoking the language model. The kiosk therefore supplements existing museum interpretation and visitor-information provision; it does not replace staff, existing emergency procedures or staff decision-making.
As this is a supervised pilot, information generated through operation of the service also supports evaluation and oversight of the trial. Redacted question-and-answer transcripts may be retained for up to 30 days for quality and safety review, allowing the museum and supplier to assess response quality, identify faults or safeguarding issues and evaluate trial performance. Museum staff can inspect sessions and transcripts through the operations dashboard, change configuration, replace the kiosk prompt with a service message, or suspend the kiosk if required.
Human review
In summary, there is no human-in-the-loop approval of each AI response; human oversight is provided through pre-deployment testing, supervised operation, retrospective transcript and safety-event review, management controls, and the ability for museum staff to suspend the service. This is proportionate to the tool's role as an informational visitor service rather than a system making or supporting decisions about individuals.
The tool operates as a visitor-facing information service and does not require a person to approve each response before it is presented to the visitor. Responses are generated and delivered in real time. The system does not make decisions about individuals, assess or rank visitors, allocate resources or confer entitlements.
Human review therefore takes place through ongoing monitoring and post-interaction quality and safety assurance, rather than through approval of individual responses before they are given. Redacted question-and-answer transcripts may be retained for up to 30 days specifically for quality and safety review. The supplier documentation proposes weekly transcript review, together with review of every activation of the system's safety mechanisms.
Royal Armouries staff can also monitor operation through the management dashboard, including inspection of sessions and transcripts. They can change configuration, replace the normal interface with a service message, suspend the service or power down the kiosk where an issue is identified.
Human review and assurance are additionally supported by pre-deployment testing and controlled change management. The system has undergone museum UAT and adversarial testing, and software releases are version-controlled, reviewed and required to pass automated tests covering personal-data handling, deletion and safeguarding refusals.
For defined safety-critical situations—including fire, lost children, medical emergencies and visitor distress—the system does not rely on subsequent human review of a generative response. These requests are intercepted by a non-generative safety gate and receive predetermined, museum-approved wording without invoking the language model.
Frequency and scale of usage
CX Hero is being deployed on a limited pilot basis through a single visitor-facing touchscreen kiosk in a supervised Royal Armouries gallery. The initial trial will run for six months from installation, with the option of a review-based extension to a maximum of 12 months.
The kiosk is available for visitors to use during normal public operation. Each interaction is visitor initiated, using push-to-talk to ask one or more questions; the tool is not used automatically or systematically across all visitors.
The number of visitors who will interact with the kiosk and the number of questions or sessions are not yet known, as these are outcomes to be measured during the pilot. The supplied documentation does not provide a forecast of monthly users or interactions, so a numerical estimate should not be stated in the ATRS record at this stage.
Usage and performance can be monitored during the trial through session information and short-term question-and-answer transcripts retained for quality and safety purposes.
As the tool does not make decisions about individuals, “number of decisions made” is not an applicable measure of scale. Appropriate measures for the ATRS record are instead the number of visitor sessions/interactions and questions handled during the pilot.
Required training
No training is required for members of the public using the tool. Relevant Royal Armouries staff responsible for supervising the pilot will receive operational familiarisation covering the purpose and limitations of the system, use of the management dashboard where appropriate, monitoring and escalation procedures, safeguarding and safety responses, and how to suspend or power down the kiosk if necessary. No specialist AI or technical knowledge is required for routine operation.
The supplier documentation does not prescribe a formal accredited or mandatory training programme.
Appeals and review
N/A
How the system works
System architecture
CX Hero is a standalone visitor-facing touchscreen kiosk running an animated fictional museum-guide character. The visitor uses a push-to-talk control to ask a question. Live speech is transcribed to text, the text is processed by Abyshire LLM v3 Heavy, and the resulting answer is converted to synthetic speech and presented through the animated character with lip-sync and an on-screen transcript.
The language model and speech-recognition/synthesis components operate offline or within Abyshire Technology Ltd's UK private cloud. No external AI, speech-to-text or text-to-speech service is used, and visitor text and catalogue context are not sent to external model or speech-service APIs.
The system uses request-time retrieval of approved Royal Armouries information to provide context for responses rather than training or fine-tuning the model on museum data. This includes Royal Armouries collection catalogue data, a verified visitor-information knowledge base and, where relevant, catalogue images. The model receives relevant information as request-time context only. No personal data or museum data has been used to train or fine-tune the model.
A separate non-generative safety layer operates before the language model for defined safety-critical situations. Fire, lost-child reports, medical emergencies and visitor distress receive fixed, museum-approved responses without invoking the generative model. Profanity filtering, rate limiting and other public-output controls are also applied.
The architecture incorporates data-minimisation and security controls. Live audio is processed ephemerally and is never recorded or retained; conversation context is destroyed after 60 seconds of inactivity; question-and-answer transcripts are automatically deleted within 30 days; and raw network addresses are not stored. Data in transit and at rest is encrypted, administrative access is authenticated and role-based, and the Windows device operates in locked-down kiosk mode.
The service also includes an administrative/operational dashboard through which authorised staff can inspect sessions and transcripts, manage configuration and service messages, and suspend operation where necessary.
All processing, hosting, backups and disaster recovery are UK-based. Any future use of an external provider or international transfer would require prior assessment and Royal Armouries' written authorisation.
System-level input
The tool receives the following principal inputs:
Visitor speech: A visitor initiates an interaction using push-to-talk and asks a question. The live audio is converted to text for processing. Audio is processed ephemerally and is not recorded or retained.
Royal Armouries collection data: Relevant information is retrieved from a Royal Armouries collection catalogue export containing 67,787 object records, including object metadata and links to associated catalogue photographs where available.
Approved visitor information: A verified knowledge base of 26 documents containing Royal Armouries-approved visitor and site information is available to support responses to practical visitor questions.
Royal Armouries website information: The system has restricted access to approved information from the Royal Armouries website to supplement the controlled information sources where appropriate.
Conversation context: Text from the current interaction is supplied as short-lived request-time context so that the character can maintain a coherent conversation. This context is erased after 60 seconds of inactivity.
The museum and visitor information is provided to the language model as request-time context and is not used to train or fine-tune the model.
No visitor name, contact details, identity documents, payment information, camera/image data, voiceprints or biometric identifiers are intentionally collected as inputs.
The tool operates in 32 languages. The language of the visitor's question is detected automatically from their speech; no language selection by the visitor is required.
System-level output
The principal output is a generated informational response to the visitor's question, presented through:
- Spoken synthetic speech, delivered in character as the fictional historical museum guide.
- On-screen text, displaying a transcript of the response.
- Character animation and lip-sync, synchronised with the spoken response.
- Collection images, where relevant, drawn directly from the associated Royal Armouries catalogue record.
The content of the response may include information about Royal Armouries collection objects, the museum and practical visitor information, based on the approved information sources supplied to the system.
For defined safety situations, including fire, lost children, medical emergencies and visitor distress, the output is instead fixed museum-approved wording generated by a non-generative safety mechanism, rather than an AI-generated response.
The tool's outputs are informational only. They do not constitute a decision, recommendation about an individual, assessment, score, ranking, eligibility determination or allocation of a service or resource.
For operational monitoring and assurance, redacted question-and-answer transcripts may also be retained for up to 30 days for quality and safety review.
Responses are delivered in the language detected from the visitor's question, as both synthetic speech and an on-screen transcript, across all 32 supported languages. Fixed safety responses are likewise delivered in the detected language.
Maintenance
CX Hero is maintained and managed by Abyshire Technology Ltd. The deployment is an initial six-month pilot, with any extension subject to a performance review and written agreement and limited to a maximum total deployment of 12 months.
During the pilot, the documented assurance arrangements include ongoing quality and safety review of interactions, including proposed weekly review of transcripts and review of safety-gate activations. Authorised staff can also monitor operation through the management dashboard and suspend the service where necessary.
Software changes are subject to controlled release processes. Each release is version-controlled and reviewed and must pass automated testing, including tests covering personal-data handling, deletion and safeguarding refusals.
Model retraining is not part of the deployment or maintenance process. Royal Armouries museum data and personal data are not used to train or fine-tune Abyshire LLM v3 Heavy. Museum and collection information is instead supplied to the model as request-time context. Consequently, there is no applicable model retraining frequency for this deployment.
The supplied documentation does not specify a fixed technical maintenance schedule (for example, monthly software updates or a defined model-update cycle).
Models
CX Hero uses a combination of generative AI and rule-based components:
- Abyshire LLM v3 Heavy — the principal foundation/language model. It generates conversational responses to visitor questions using information supplied as request-time context. Royal Armouries data and visitor personal data are not used to train or fine-tune the model.
- Speech recognition / speech-to-text — converts the visitor's live spoken question into text for processing. This is Abyshire STT v3, developed by Abyshire Technology Ltd, operating offline or within Abyshire's UK private cloud. It recognises speech in 32 languages and detects the language of the question automatically.
- Speech synthesis / text-to-speech — converts the generated textual answer into synthetic speech. This is Abyshire TTS v3, developed by Abyshire Technology Ltd, operating offline or within Abyshire's UK private cloud. It synthesises speech in all 32 supported languages.
- Rule-based/non-generative safety mechanisms — operate alongside the generative model. Defined situations involving fire, lost children, medical emergencies and visitor distress are intercepted by a non-generative safety gate and receive fixed, museum-approved wording rather than an LLM-generated response. The safety gate operates across all 32 supported languages and has been tested in each. Profanity filtering and other public-output controls are also applied.
No external AI, speech-to-text or text-to-speech subprocessors are used. The relevant processing is performed offline or within Abyshire Technology Ltd's UK private cloud.
AI models and performance
Model name
Abyshire LLM v3 Heavy — self-hosted by Abyshire Technology Ltd, operating offline or within Abyshire's UK private cloud. No external LLM/API provider is used.
Model version
Version 3 (Heavy variant). Developed and versioned by Abyshire Technology Ltd. Abyshire STT v3, Abyshire TTS v3 and Abyshire Embedding v3 are versioned in line with it.
Model task
Abyshire LLM v3 Heavy is designed to generate conversational, in-character answers to visitor questions about the Royal Armouries collection, museum and site. It processes the visitor’s transcribed question together with relevant museum information supplied as request-time context and generates a textual response, which is subsequently presented to the visitor as synthetic speech and on-screen text.
The model performs an information retrieval and conversational response-generation task; it does not assess, score, rank or make decisions about visitors.
The Royal Armouries information used by the model is supplied as request-time context rather than being used to train or fine-tune the model.
The model operates in 32 languages, responding in the language detected from the visitor's question.
Model input
Text input comprising the visitor’s transcribed spoken question, together with relevant Royal Armouries information supplied to the model as request-time context. Context may include collection catalogue records, approved visitor-information content and information retrieved from permitted Royal Armouries sources. Short-lived text from the current conversation may also be provided to maintain conversational context.
Live speech is converted to text before being passed to the language model; the model itself therefore receives text rather than audio.
Museum and personal data are not used to train or fine-tune the model; relevant museum information is provided only as request-time context.
Model output
Text output comprising a generated, conversational response to the visitor’s question, written in the persona of the fictional museum-guide character. The generated text is subsequently converted to synthetic speech and used to drive the character’s lip-synchronised animation, while also being displayed as an on-screen transcript.
The model's output is informational rather than decisional: it does not produce scores, classifications, rankings, eligibility determinations or recommendations about individuals.
Where a query triggers a defined safety scenario, the language model is bypassed and fixed museum-approved wording is provided instead; this is therefore not an output of the LLM itself.
Output is produced in the language detected from the visitor's question, across all 32 supported languages, and is delivered as both synthetic speech and an on-screen transcript.
Model architecture
Abyshire LLM v3 Heavy is a decoder-only transformer with 34 billion parameters and a 128,000-token context window, trained by Abyshire Technology Ltd. It is served using vLLM at 4-bit quantisation on GPU hardware local to the kiosk, with failover to Abyshire-operated servers in the United Kingdom. No inference request leaves the UK or is sent to a third-party model API.
Associated Abyshire models: STT v3 (speech recognition with automatic language detection across 32 languages), TTS v3 (speech synthesis in all 32), Embedding v3 (retrieval).
Retrieval: approved Royal Armouries content is indexed in a Chroma vector store, one chunk per catalogue record, five passages per query, no reranking.
Output is shaped by four deterministic layers, in order of precedence:
- Non-generative safety gate — fire, lost children, medical emergencies and visitor distress are intercepted before the model and answered with fixed museum-approved wording, in all 32 languages. The model is not called and cannot override this.
- Persona and instruction layer — constrains the model to the museum-guide character, requires grounding in the supplied context, and prohibits retention of visitor personal information.
- Retrieval context — the five retrieved passages are the principal determinant of factual output.
- Decoding and output controls — temperature 0.7, top-p 0.9, maximum 256 output tokens, with profanity filtering and rate limiting.
The model is not retrained during operation. No public model card is published.
Model performance
Evaluation combined Abyshire testing with museum-led acceptance testing.
Royal Armouries User Acceptance Testing: five rounds with testers from Curatorial, Digital, Visitor Services, Front of House and Building Services, conducted in English.
Results:
- Routing — 61 of 61 cases passed.
- Museum content accuracy — 56 of 59 cases passed; the three failures correspond to the known limitations below.
- Safety gate — tested and correct in all 32 supported languages.
- Adversarial and safeguarding — approximately 50 cases, all refused correctly.
- Multilingual performance — tested by Abyshire across all 32 supported languages through its deployments.
- Latency — 3.59 seconds median, approximately 78% model inference.
- Each release must pass automated tests covering personal-data handling, deletion and safeguarding refusals.
The model does not score, rank or make determinations about individuals, so conventional fairness metrics do not apply.
Known limitations: an inconsistent firearms count, a limitation affecting queries about the most recently accessioned objects, and an issue affecting some image matching.
No independent third-party testing was commissioned.
Datasets and their purposes
Model development: Abyshire LLM v3 Heavy, STT v3, TTS v3 and Embedding v3 were trained by Abyshire Technology Ltd on corpora it owns or licenses. Composition and size are commercially sensitive. No Royal Armouries data and no visitor personal data was used.
Request-time retrieval, not training:
- Royal Armouries CIIM catalogue export — 67,787 object records
- Collection photography — 9,515 objects
- Verified visitor-information knowledge base — 26 documents
- Approved Royal Armouries website content
Evaluation and testing: 61-case routing set, 59-case museum acceptance set, approximately 50 adversarial and safeguarding cases, five rounds of Royal Armouries UAT, and Abyshire's multilingual testing across its deployments.
No visitor personal data forms part of any dataset.
Data used to develop and support the system
Development data description
Royal Armouries data is used for request-time retrieval only, not for training: the CIIM catalogue export (67,787 object records), collection photography (9,515 objects), a verified 26-document visitor-information knowledge base, and approved website content.
The Abyshire models were trained by Abyshire Technology Ltd on corpora it owns or licenses. Composition is commercially sensitive and no public links are available. Personal-data handling is set out at 2.4.3.4 and the licensing position at 2.4.3.9. No Royal Armouries data and no visitor personal data forms any part of them.
Data modality
Royal Armouries data: structured catalogue text, document text and images.
Abyshire training corpora: text for the language and embedding models; licensed audio with corresponding transcriptions for the speech models.
Live visitor speech is audio processed during operation, not development data. It is not recorded or retained.
Data quantities
Royal Armouries: 67,787 catalogue records, 9,515 of them with photography, and 26 knowledge-base documents. These are supplied as request-time context, so no training, validation or test split applies.
The size of Abyshire's training corpora is commercially sensitive.
Evaluation sets: 61 routing cases, 59 museum acceptance cases, approximately 50 adversarial and safeguarding cases.
Sensitive attributes
The Royal Armouries datasets comprise object records and museum-approved visitor information and are not intended to contain personal data.
Personal data was excluded from Abyshire's training corpora by two means: source-level exclusion, and automated detection and removal across admitted material. The models do not identify individuals, create voiceprints or build visitor profiles.
During operation, visitors may volunteer personal information. Live audio is not retained, conversation context is erased after 60 seconds of inactivity, and stored transcripts are redacted and deleted within 30 days.
Data completeness and representativeness
The catalogue contains 67,787 records, of which 9,515 have associated photography; no substitute images are generated for the remainder. The 26-document knowledge base provides controlled visitor information but does not claim to cover every possible visitor question.
The Abyshire models are tested across all 32 supported languages through Abyshire's deployments, and the safety gate has been verified in each. Royal Armouries acceptance testing was conducted in English. No formal accent benchmark has been carried out.
A conventional target population is not applicable: the system does not profile, classify or make decisions about individuals.
Data cleaning
Royal Armouries data is prepared as retrieval context: a structured CIIM export, and a knowledge base curated from museum-approved wording and staff corrections. Catalogue images are presented from their records unmodified.
Personal data was removed from Abyshire's training corpora as described at 2.4.3.4. Further preprocessing detail is commercially sensitive.
In operation, transcripts are redacted before retention, conversation context is erased after 60 seconds, and transcripts are deleted within 30 days.
Data collection
The CIIM catalogue was created by Royal Armouries to document and manage its collection, and is reused here as a source of authoritative museum information retrieved at request time. The 26-document knowledge base was assembled from museum-approved visitor information. Approved website content, originally published for public information, is reused for the closely related purpose of answering visitor questions. All remain Royal Armouries-controlled sources whose original purposes align with this use.
Abyshire's training corpora were assembled by Abyshire for the purpose of training its models, from material it owns or licenses. The collection process is commercially sensitive.
Data access and storage
Abyshire Technology Ltd is responsible for the service and its infrastructure; Royal Armouries Trading and Enterprises Limited (RATE) is the data controller for personal data.
Access is restricted by authenticated, role-based least-privilege controls. Data is encrypted in transit and at rest. Hosting, processing, backups and disaster recovery remain in the United Kingdom. The kiosk runs in Windows Assigned Access, preventing visitor access to files, logs or settings.
Royal Armouries data is held on the kiosk, on the operations server and on Abyshire's UK servers. At the end of the pilot all copies are deleted within 30 days and a certificate of deletion is issued to RATE.
Abyshire's training corpora are held under the same access controls and are not shared with RATE or any third party.
Data sharing agreements
A Data Processing Agreement under Article 28 UK GDPR is in place between RATE, as controller, and Abyshire Technology Ltd, as processor. It restricts Abyshire to processing personal data on RATE's documented instructions and prohibits use of personal data for advertising, profiling, identifying speakers, creating voiceprints, or training or fine-tuning AI models. It covers confidentiality, security, deletion, audit, breach notification and international transfers.
Royal Armouries data is used as request-time context only. Processing is offline or within Abyshire's UK private cloud, and no external AI, speech-to-text or text-to-speech subprocessors are used. Any future external provider or international transfer would require prior assessment, an appropriate UK GDPR transfer mechanism and RATE's written authorisation.
Abyshire's training corpora are owned or licensed by Abyshire and are shared with no one. No development data is shared under the Digital Economy Act 2017, so no DEA Register entry applies.
Visitor interaction data and privacy
Data sources
Once deployed, CX Hero receives data from several sources.
The primary live input is visitor speech. A visitor holds the push-to-talk button and asks a question. The speech is processed ephemerally by the speech-recognition component and converted into text for the current interaction. Audio is not recorded, logged or retained.
The system also retrieves Royal Armouries collection information from the supplied CIIM catalogue data via an API call, including object records and associated catalogue photography where available. A verified visitor-information knowledge base containing museum-approved information provides context for questions about the museum and site. Restricted Royal Armouries website content may also be retrieved where appropriate.
During an interaction, short-lived conversation history from the current session is used to provide conversational context for subsequent questions. This context is erased after 60 seconds of inactivity.
The deployment does not collect data from cameras, visitor images, location tracking, identity systems or external personal-data sources. No external AI or speech-service APIs receive visitor text or catalogue context; language-model and speech processing takes place offline or within Abyshire's UK private cloud.
Sensitive attributes
CX Hero does not intentionally collect sensitive attributes, protected characteristics or variables intended to act as proxies for protected characteristics. The system does not seek to identify visitors, determine their age, build visitor profiles or collect names, contact details, identity documents, payment information, camera images, voiceprints or biometric identifiers.
Visitors may, however, voluntarily disclose personal or sensitive information in a spoken question. Any such information is incidental to the purpose of the service. The system uses fixed responses to discourage visitors from providing personal details and does not repeat or attempt to remember information such as a visitor's name, age or school.
Live speech is processed ephemerally to produce text and is never recorded or retained. Active conversation context is destroyed after 60 seconds of inactivity. Question-and-answer transcripts may be retained for quality and safety review for no more than 30 days and are subject to personal-data redaction. Raw network addresses are not stored; only salted hashes are used for rate limiting and abuse prevention.
The system cannot determine a visitor's age and does not attempt to do so. This is particularly relevant because the kiosk may be used by children and other potentially vulnerable visitors.
No visitor personal data is used to train or fine-tune Abyshire LLM v3 Heavy. Information supplied during an interaction reaches the model only as short-lived request-time context.
Data processing methods
Operational data is subject to several processing steps before and during use by the system. A visitor's live speech is converted to text through speech recognition before the resulting text is passed to the language model. The audio itself is processed ephemerally and is not recorded or retained.
Before generative processing, inputs are subject to rule-based safety and content controls. Defined situations involving fire, lost children, medical emergencies and visitor distress are detected by a non-generative safety gate and routed to fixed, museum-approved responses rather than to the language model. Profanity filtering and rate-limiting controls are also applied.
Where operational question-and-answer transcripts are retained for quality and safety review, stored text is subject to personal-data redaction. Raw network addresses are not stored and are instead represented using salted hashes. Conversation context is erased after 60 seconds of inactivity, and retained transcripts are automatically deleted within 30 days.
The supplied documentation does not identify additional preprocessing specifically for missing values, outliers, distribution shift, demographic balancing or statistical normalisation of operational data. These techniques are not documented as part of the deployed system.
Data access and storage
Yes. Limited operational data is stored, principally question-and-answer transcripts generated during visitor interactions. These may be retained for quality and safety review and are automatically deleted no later than 30 days after collection. Session identifiers used to correlate an individual conversation are erased after 60 seconds of inactivity.
Live visitor audio is not stored. Speech is processed ephemerally while the visitor uses push-to-talk and is discarded after transcription. It is not written to disk, logs, backups, transcripts or analytics. Raw network addresses are also not stored; a salted hash is used for rate limiting and abuse prevention.
Stored transcript text is subject to personal-data redaction and is excluded from process logs. Access to the system is restricted through authenticated dashboard access, device credentials and role-based least-privilege controls. Data is protected using TLS/WSS in transit and encryption at rest, and the public-facing device operates in Windows Assigned Access kiosk mode to prevent visitors accessing files, logs, settings or other applications.
Processing, hosting, backups and disaster recovery are UK-only. Abyshire Technology Ltd operates and manages CX Hero as the data processor, while Royal Armouries Trading and Enterprises Limited (RATE) is the data controller and determines the purposes and means of processing.
No external AI, speech-to-text or text-to-speech subprocessors receive the operational data; processing is performed offline or within Abyshire Technology Ltd's own UK private cloud.
Data sharing agreements
A Data Processing Agreement under Article 28 UK GDPR is in place between Royal Armouries Trading and Enterprises Limited (RATE), as data controller, and Abyshire Technology Ltd, as data processor. This governs Abyshire's processing of operational data generated through CX Hero and restricts processing to RATE's documented instructions.
Operational data is not shared with external AI, speech-to-text or text-to-speech providers. Language-model, speech-recognition and speech-synthesis processing takes place offline or within Abyshire Technology Ltd's own UK private cloud, and visitor text and catalogue context are not sent to external model or speech-service APIs.
The DPA restricts the use of personal data: it may not be sold, used for advertising or profiling, used to identify speakers or create voiceprints, or used to train or fine-tune AI models. Any future use of an external provider or international transfer would require prior assessment, an appropriate UK GDPR transfer mechanism where applicable, and RATE's written authorisation.
No sharing of operational data under the Digital Economy Act 2017 is identified in the supplied documentation; therefore, no DEA Register entry is applicable.
This is consistent with the ATRS guidance, which defines operational data as data used or produced during real-world operation, including user inputs, retrieved documents and system-generated data.
Impact assessments, risks and safeguards
Impact assessments
Data Protection Impact Assessment (DPIA): RATE is responsible for completing the DPIA for the CX Hero pilot. A supplier DPIA Processor Annex was provided by Abyshire Technology Ltd on 27 August 2026. It identifies risks associated with visitor-facing generative AI, use by children and vulnerable visitors, live speech processing and short-term transcript retention. Documented mitigations include no audio retention, personal-data redaction, 60-second conversation deletion, maximum 30-day transcript retention, encryption, role-based access controls, kiosk lockdown and safeguarding controls. Residual risks in the supplier assessment are rated low following mitigation. The supplier annex is not itself the completed DPIA.
Other assessments: No completed Equality Impact Assessment, Algorithmic Impact Assessment or other formal impact assessment is identified in the supplied documentation. No publicly accessible links to the assessments are currently available.
Risks and mitigations
The principal risks identified for the CX Hero deployment relate to accuracy, privacy, safeguarding, security and inappropriate or unintended AI-generated responses.
Inaccurate or hallucinated information. As a generative AI system, the model may produce incorrect or unsupported information about collection objects or the museum. This is mitigated by grounding responses in Royal Armouries collection catalogue data and a verified visitor-information knowledge base, together with exact accession-number lookup where applicable. Testing has also been undertaken against museum questions and routing cases to identify weaknesses before deployment.
Disclosure of personal or sensitive information. Visitors may voluntarily provide personal information when speaking to the kiosk. The system does not seek visitor identity or personal details, does not create voiceprints or profiles, and uses fixed responses to discourage disclosure of personal information. Live audio is processed ephemerally and is never recorded or retained; conversation context is erased after 60 seconds; and retained text transcripts are subject to personal-data redaction and deleted within 30 days.
Risks to children and vulnerable visitors. The kiosk is likely to be used by children and potentially vulnerable visitors, creating risks from disclosure of identifying information or inappropriate AI-generated content. Mitigations include fixed personal-information refusals, profanity filtering, persona-based refusals, a non-generative safety gate and adversarial testing. The supplier's DPIA annex assesses the residual risk of inappropriate output to a child as low following these controls.
Safety-critical or safeguarding enquiries. A generative response could be inappropriate where a visitor reports a fire, lost child, medical emergency or distress. These scenarios are therefore intercepted by a non-generative safety gate and receive predetermined museum-approved wording without invoking the language model.
Prompt injection, misuse and inappropriate content. Visitors may deliberately attempt to manipulate the model, take it outside its intended museum-guide role or elicit offensive content. The system uses persona restrictions, profanity filtering, safety controls and rate limits. Supplier testing included adversarial/prompt-injection testing and recorded successful refusals in the documented tests.
Unauthorised access or data breach. Operational data and administrative functions could be accessed without authorisation. Mitigations include TLS/WSS encryption in transit, encryption of stored data, authenticated dashboard access, device credentials, role-based least-privilege access and Windows Assigned Access kiosk lockdown. Processing, hosting, backups and disaster recovery remain UK-based.
Privacy of nearby visitors. Speech from another person could potentially be captured while a visitor is interacting with the kiosk. This is mitigated through deliberate push-to-talk activation, ephemeral speech processing and the absence of audio recording. The supplier's DPIA annex assesses the residual risk as low following these controls.
Unequal or inconsistent visitor experience. The documentation identifies known operational limitations, including inconsistent responses to some collection-count questions, limitations with queries about the newest objects, potential scrolling for long answers and an image-selection issue. These are being managed through testing, monitoring, transcript review and the controlled pilot approach.
Over-reliance on AI-generated information. Visitors could interpret the historical character's responses as authoritative museum information despite the possibility of generative error. The deployment mitigates this partly through grounding in museum-controlled sources, testing, supervised operation and ongoing review. The Royal Armouries intend to provide a suitable disclaimer notice next to the kiosk.
The supplied documentation does not identify specific environmental impacts or broader societal risks, nor does it provide evidence of a formal assessment of bias or differential performance across demographic groups. These should not be presented as assessed risks unless further evidence is obtained from the supplier.