1. Purpose and Scope
This policy defines Guanta's principles, commitments and direction for the responsible use and development of artificial intelligence systems. It provides the policy framework for AI objectives and for the development, provision, acquisition, deployment, operation, monitoring and use of AI solutions within Guanta.
The objective is to ensure that AI systems are developed and used in a responsible, ethical, secure, reliable and lawful manner, consistent with Guanta's strategy, customer commitments, management systems and applicable legal, regulatory and contractual requirements.
This policy applies to all personnel, contractors, suppliers, partners and other third parties who participate in AI-related activities on Guanta's behalf. It applies both to AI systems developed or provided by Guanta and to AI tools, services or models used in Guanta operations.
Everyone working for or on behalf of Guanta is responsible for applying this policy within their area of work. Management is responsible for making the policy available, understood, implemented, maintained and reviewed.
2. Responsible AI Principles
Guanta commits that AI-related activities will follow the principles below.
2.1. Legality, Ethics and Compliance
AI systems and AI use must comply with applicable laws, regulations, standards, contractual obligations and approved internal policies. Guanta will not develop, provide or use AI systems for prohibited practices or for uses that create unacceptable risk.
When an AI use case has uncertain legal, ethical, contractual or regulatory implications, the activity must be assessed and approved before it proceeds. Relevant obligations and decisions are documented in Guanta's internal management-system records.
2.2. Transparency and Explainability
AI systems must be understandable enough for their purpose, risk and audience. Guanta will provide clear information about intended use, limitations, conditions of use, human oversight requirements and relevant AI involvement where required or where it would not otherwise be apparent.
Explanations, interpretability information and traceability are provided in proportion to the system's context and potential impact. Guanta must not make claims that overstate the accuracy, autonomy, safety, certification or legal status of an AI system.
2.3. Fairness and Non-Discrimination
AI systems must be designed, selected and used to reduce unjustified bias and discriminatory outcomes. Guanta will consider the quality, representativeness, integrity and suitability of data and evaluate outputs where AI can materially affect people, groups or customers.
AI outputs must not be treated as objective or authoritative merely because they were produced by a model. Concerns about unfair, biased or discriminatory behavior must be recorded, assessed and treated.
2.4. Security, Protection and Technical Robustness
AI systems must be protected and robust enough for their intended use. Guanta will apply proportionate controls for secure design, access control, data and model integrity, logging, monitoring, error handling, recovery and change control.
Relevant risks may include prompt injection, data poisoning, model or information extraction, unsafe tool use, hallucination, performance degradation, supplier failure, unauthorized access and misuse.
2.5. Privacy and Personal Data Protection
AI systems must follow privacy and data-protection principles by design and by default. Personal data, customer data, confidential information and restricted information may only be used with AI systems when the use, provider, legal basis and safeguards have been assessed and authorized.
Guanta will minimize data, define processing purposes and roles, apply appropriate security and retention controls, and perform data-protection or privacy impact assessments where required by law or risk.
2.6. Human Supervision
Human oversight must be proportionate to the AI system's autonomy, context and potential impact. Guanta will define who supervises AI behavior or outputs, when human validation is required, how concerns are escalated, and how an AI system can be corrected, restricted, disabled or retired.
People assigned oversight must have sufficient competence, information, authority and time to perform the role. AI output must not be the sole basis for a decision with material impact on rights, safety, employment, access to essential services or similarly significant interests unless the use has been specifically assessed and approved with all required safeguards.
2.7. Positive Social Impact and Harm Minimization
Guanta will consider the effects of AI systems on people, customers, vulnerable groups, work, accessibility, society and the environment. AI activities should support beneficial outcomes and avoid or reduce foreseeable harm.
Where relevant, assessments must consider energy and computing efficiency, supplier infrastructure, environmental impact, misuse at scale and broader social consequences. Significant adverse effects must be treated, accepted by authorized management, avoided, or result in stopping the system or use.
3. Responsible AI Commitments
This policy complements Guanta's information security, privacy, software development, supplier, quality and management-system policies. Responsible AI requirements must be integrated into the AI system life cycle and into relevant operational processes.
Guanta commits to:
- Register in-scope AI systems before production use or customer availability.
- Define each AI system's purpose, owner, intended use, foreseeable misuse, stakeholders, dependencies, data resources, suppliers, users and operating context.
- Assess AI-specific risks, opportunities and impacts, including technical, security, privacy, legal, ethical, social, contractual and supplier risks.
- Maintain current AI risk, treatment and system documentation records.
- Evaluate applicable AI management-system controls and maintain evidence of control applicability and operation.
- Include responsible AI objectives and control requirements in system requirements, design decisions, testing, release approval, monitoring and change control.
- Establish controls for data quality, data integrity, data provenance, authorized data use and protection of personal, customer and confidential information.
- Provide technical and user documentation where needed, including limitations, warnings, human oversight requirements, safe-use instructions and incident or concern reporting channels.
- Review supplier responsibilities, contractual terms, security and privacy commitments, documentation, service limitations, processing locations, subprocessors, change practices and assurance evidence.
- Train and raise awareness for personnel according to their AI responsibilities and context of use.
- Record monitoring evidence, incidents, nonconformities, corrective actions and improvement opportunities.
- Apply continual improvement so AI governance evolves with new laws, risks, technologies, stakeholder expectations and lessons learned.
4. Governance and Records
Guanta maintains internal management-system records for AI governance, including system documentation, risk assessments, responsibilities, supplier reviews, training evidence, control evidence, monitoring results, incidents and improvement actions. Detailed internal records are maintained separately from this public policy.
Organizational responsibilities, competence requirements, personnel assignments and AI-system-specific ownership are defined and maintained internally. Supplier governance follows Guanta's supplier management process.
AI systems must be monitored in proportion to their risk. Monitoring may include service health, errors, quality of outputs, security events, unsafe or misleading behavior, complaints, human overrides, supplier changes and control effectiveness.
Incidents, suspected policy breaches, harmful outputs, unlawful behavior, security concerns, privacy concerns, bias concerns and material inaccuracies must be reported. Guanta may restrict or suspend an AI system or use while the concern is assessed. Incidents and external communications are handled through Guanta's established incident and communication processes.
5. Review and Availability
This policy is reviewed at least annually and after significant legal, regulatory, contractual, organizational, supplier, technology, risk, incident or certification changes.
The approved current version is made available to personnel and may be shared with customers, auditors, authorities and other interested parties. Draft versions must not be represented as approved policy.