
Policy
AI Use Policy
FORFIRM governs AI through clear responsibilities, authorized use, Human-in-the-Loop principles, Data Protection and ethical safeguards.
Purpose
The purpose of this policy is to establish clear guidelines, responsibilities, and ethical standards for how AI technologies are implemented, managed, and governed. This AI Usage Policy guides the responsible and innovative application of FORFIRM’s AI technologies, ensuring alignment with our values, legal obligations, and strategic business objectives.
Applicability
This policy applies to all staff, partners, and external stakeholders working on behalf of FORFIRM. It extends to include all employees, secondees, contractors, agency staff, temporary workers, consultants, and any other individuals engaged by the organization.
Definitions
For the purposes of this policy, the following terms are defined as follows: • Artificial Intelligence (AI): A set of technologies and techniques that enable computers and machines to perform tasks that typically require human intelligence, such as pattern recognition, decision-making, natural language processing, and problem-solving • Generative AI (GenAI): A subset of AI focused on creating new content, including text, images, code, audio, video, based on the patterns and data it was trained on • Machine Learning (ML): A branch of AI that uses algorithms and statistical models to enable systems to learn from data and improve their performance on a specific task over time without being explicitly programmed • Foundation Models: Large-scale AI models trained on vast amounts of data that can be adapted (fine-tuned) to a wide range of downstream tasks • High-Risk AI Systems: AI applications that have the potential to significantly impact the health, safety, or fundamental rights of individuals, or those used in critical infrastructure, education, employment, or law enforcement • AI Lifecycle: The entire span of an AI system’s existence, including data collection, design, development, testing, deployment, monitoring, and eventual decommissioning • Data Controller: The entity (in this case, FORFIRM or its designated unit) that determines the purposes and means of processing personal or proprietary data used by the AI system • Human-in-the-Loop (HITL): A governance requirement ensuring that a human remains involved in the decision-making process of an AI system to review, override, or validate its outputs.
Responsibilities
Effective AI governance is a shared responsibility. The following roles are established to ensure compliance with this policy:
AI Governance Committee (or Executive Leadership)
• Strategic Oversight: Responsible for the final approval of AI strategies and ensuring they align with corporate values and legal frameworks. • Risk Mitigation: Reviewing high-risk AI use cases and providing the "Go/No-Go" decision for deployment. • Policy Maintenance: Reviewing and updating this policy annually to reflect emerging technologies and shifting global regulations.
Management and Department Heads
• Implementation: Ensuring that all teams under their supervision are aware of and adhere to this policy. • Resource Allocation: Providing the necessary training and tools for staff to use AI safely and effectively. • Incident Reporting: Acting as the first point of contact for reporting any AI malfunctions, biases, or security breaches within their department.
AI Developers and Data Scientists
• Ethical Design: Implementing "Ethics by Design" principles, ensuring models are tested for bias, transparency, and technical robustness. • Documentation: Maintaining detailed technical documentation of AI models, including data sources, training methodologies, and validation results. • Security: Ensuring that AI systems are protected against adversarial attacks and that data privacy is maintained throughout the lifecycle.
All Staff and Authorized Users (The "End-User")
• Compliant Usage: Using only organization-approved AI tools for business purposes and following specific prompts/guidelines provided for those tools. • Verification: Taking ultimate responsibility for the output of any AI system used in their work (the "Human-in-the-Loop" principle). All AI-generated content must be reviewed for accuracy before being shared internally or externally. • Data Protection: Refraining from inputting sensitive personal data (PII), proprietary source code, or confidential client information into unapproved or public AI platforms.
Prohibited Use
To mitigate risks related to data privacy, security, and legal liability, the following actions are strictly prohibited:
Use of Unauthorized Systems
• Shadow AI: Staff must not use personal AI accounts, public "freemium" tools, or any AI platform not explicitly vetted and approved by the IT and Security departments for business use. • Personal Devices: Accessing FORFIRM-approved AI tools or processing corporate data on personal, non-managed devices is prohibited unless specifically authorized by the remote work policy.
Input of Sensitive and Proprietary Information
Users are strictly forbidden from inputting the following into any AI system (including approved tools, unless specifically designed for that purpose): • Confidential Corporate Data: This includes trade secrets, unreleased financial results, strategic business plans, or proprietary source code. • Client and Partner Data: Any data belonging to FORFIRM customers, vendors, or partners must never be uploaded to an AI system without explicit contractual permission. • Pseudonymized Data: Information that has been partially masked but could still be re-identified or "reconducted" to FORFIRM or a specific individual (e.g., project codenames, specific transaction IDs, or masked email formats) is prohibited.
Personal Data and PII
Personally Identifiable Information (PII): The input of names, home addresses, government IDs, health information, or any other data that identifies a natural person is strictly prohibited. Recruitment and HR Data: Using AI to process or summarize employee files, performance reviews, or resumes outside of HR-approved, secure platforms is not allowed.
Deceptive and Unethical Practices
Plagiarism and Attribution: Using AI-generated content and presenting it as original human work without disclosure where required. Harmful Content: Generating or disseminating content that is discriminatory, defamatory, or promotes illegal activities. Bypassing Controls: Attempting to "jailbreak" or prompt-engineer an AI system to bypass its safety filters or security protocols.
Access and Authorization Process
Access to AI technologies at FORFIRM is strictly controlled and categorized based on the hosting environment to manage data privacy and infrastructure stability.
Public and Third-Party AI Services
Access to any public or third-party hosted AI service is not permitted by default. • Service Request Requirement: Any employee or stakeholder requiring the use of an external AI service for business purposes must submit a formal request via the internal IT/Security Ticketing System. Access will only be granted if the service is deemed necessary for a specific business objective • Approval Workflow: Every request must undergo a formal approval process including Managerial Review (for necessity), Security & Compliance Assessment (for data protection), and Legal Review (for IP and contractual alignment)
Internal (On-Premise) AI Services
AI services and models hosted locally within FORFIRM’s own data centers are generally approved for internal use and do not require individual project-based tickets for standard, interactive usage. However, to ensure system availability, the following applies: • Resource Coordination: Any usage intended for high-impact activities—including batch processing, heavy API integrations, or compute-intensive ("crunchy") jobs—must be coordinated with and approved by the IT Infrastructure team prior to execution • Performance Protection: IT reserves the right to schedule such jobs during off-peak hours to prevent performance degradation for other users
Defined Scope and Duration
For all authorized AI access (particularly for external services): • Project Specificity: Access is granted only for the specific project or task outlined in the approved ticket. Using the AI service for unrelated tasks is strictly prohibited • Time-Bound Access: Authorization is temporary. Access will be granted for a specific timeframe (e.g., the duration of a project). Upon expiration, access will be automatically revoked unless a formal extension is requested and approved.
Audit Trail
Every ticket and coordination request serves as a permanent record of who accessed the AI service, for what purpose, and who authorized it, ensuring full accountability across both cloud and on-premise environments.
Reporting and Compliance Monitoring
Mandatory Reporting
All individuals covered by this policy have an affirmative duty to report any suspected or actual violations. This includes, but is not limited to: • Unauthorized AI Use: Observing the use of AI tools for business purposes without an approved ticket. • Data Spillage: Accidental input of FORFIRM confidential or customer data into an AI system. • Anomalous Output: Discovering that an approved AI system is producing biased, discriminatory, or dangerously inaccurate information (hallucinations). • Security Concerns: Suspecting that an AI tool's account or "API key" has been compromised.
Reporting Channels
Reports should be made immediately through one of the following channels: • The Corporate Ethics Hotline: For anonymous reporting of policy bypasses. • Cybersecurity Incident Response: If the report involves a potential data breach or loss of intellectual property. • Direct Management: For technical issues or minor procedural clarifications.
Compliance Audits
FORFIRM reserves the right to perform regular audits of AI usage. This includes: • Ticket Re-validation: Periodic reviews to ensure that "time-bound" access has been properly revoked or extended. • Network Monitoring: Scanning for traffic to unauthorized AI domains from corporate devices or networks. • Prompt Logging: Reviewing prompts used within approved internal AI systems to ensure compliance with the "Prohibited Use" section of this policy.
Non-Retaliation
FORFIRM maintains a strict non-retaliation policy. No employee will suffer adverse consequences for reporting a suspected AI policy violation in good faith, even if the report later proves to be unfounded.
