BACI

RESPONSIBLE AI POLICY

Version 1.0 · Effective Date: 10 September 2026 · Last Updated: 10 September 2026

This Responsible AI Policy ("Policy") establishes the principles and governance framework BACI LLC ("BACI") applies to the design, development, deployment, operation and oversight of artificial-intelligence and machine-assisted functionality.

BACI develops intelligence systems to augment human capability, improve business decision-making and, where authorised, perform bounded actions. BACI's approach is therefore not limited to model behaviour. Responsible AI must address the complete system: data, models, prompts, retrieval, orchestration, tools, permissions, outputs, human workflows, Autonomous Actions, monitoring and the consequences of deployment.

This Policy is a governance policy. Contractual rules governing Customer use of AI and Autonomous functionality are set out in the AI & Autonomous Systems Terms, Terms of Service, Acceptable Use Policy and applicable Orders.

1. SCOPE

This Policy applies to AI-enabled BACI Services, including machine learning, generative AI, predictive systems, classification, scoring, forecasting, recommendation, retrieval-augmented generation, intelligent agents, orchestration, decision support and Autonomous functionality.

It applies across the AI lifecycle, including conception, design, data selection, development, testing, deployment, monitoring, material modification and retirement.

It also informs BACI's evaluation of third-party models and AI providers incorporated into the Services.

2. RELATIONSHIP TO THE BACI LEGAL FRAMEWORK

This Policy forms part of the BACI Legal Framework and should be read with the Terms of Service, Privacy Policy, Data Processing Addendum, Security Policy / Security Addendum, Acceptable Use Policy, AI & Autonomous Systems Terms, Developer & API Terms, Government & Public Sector Schedule and applicable Orders and Supplemental Terms.

The Terms establish BACI's baseline contractual commitments. The Data Processing Addendum is authoritative for Processing Customer Personal Data on Customer's behalf. The AI & Autonomous Systems Terms are authoritative for contractual rules governing AI and Autonomous functionality where applicable.

This Policy expresses BACI's responsible-AI governance principles and does not independently weaken a higher-precedence contractual protection.

3. RESPONSIBLE AI PRINCIPLES

BACI's responsible-AI framework is organised around the following principles:

1. Human Purpose — AI should serve legitimate human and organisational objectives. 2. Accountability — responsibility must remain identifiable even when systems act autonomously. 3. Safety and Reliability — AI should be designed and operated proportionately to foreseeable consequence. 4. Security and Privacy — AI must respect applicable security, confidentiality and data-protection requirements. 5. Fairness and Non-Discrimination — systems should be assessed for unjustified discriminatory effects where relevant. 6. Transparency and Traceability — material AI activity should be understandable and auditable to a degree appropriate to the use. 7. Human Oversight — consequential uses require meaningful governance and appropriate intervention mechanisms. 8. Bounded Autonomy — Autonomous systems must operate within authorised scope. 9. Proportionality — controls should increase as potential harm, irreversibility and consequence increase. 10. Continuous Governance — responsible AI is a lifecycle obligation rather than a one-time approval.

4. HUMAN PURPOSE

BACI designs AI to augment legitimate human and organisational capability rather than to remove accountability.

Before deploying material AI functionality, BACI should consider the intended purpose, affected users, foreseeable consequences, whether AI is appropriate to the problem and whether the functionality creates risks disproportionate to its expected benefit.

Technical feasibility alone does not establish that a use should be enabled.

5. ACCOUNTABILITY

BACI seeks to maintain clear responsibility for material AI systems and governance decisions.

Appropriate accountability may include defined system owners, engineering responsibility, product responsibility, security and privacy review, risk ownership, approval authorities, Customer responsibility boundaries and escalation procedures.

An AI model, agent or automated workflow cannot itself bear legal or organisational accountability.

6. RISK-BASED GOVERNANCE

BACI applies governance proportionate to AI risk.

Risk evaluation may consider the purpose of the system; affected persons; degree of autonomy; reversibility of actions; financial or operational consequence; use of Personal Data or sensitive information; potential discrimination; safety impact; legal or regulatory context; scale; external-system access; model capability; and potential for misuse.

Higher-consequence systems may require stronger testing, permissions, human oversight, monitoring, approval or deployment restrictions.

7. AI SYSTEM INVENTORY AND CLASSIFICATION

BACI may maintain records identifying material AI-enabled systems, their purpose, responsible owner, model or provider dependencies, data categories, deployment context, autonomy level and risk classification.

The depth of documentation may vary according to consequence and complexity.

Material changes to a system may trigger reassessment.

8. DATA GOVERNANCE

AI development and operation must use data in accordance with applicable law, contracts, privacy requirements, confidentiality obligations and BACI data-governance controls.

BACI will seek to use data appropriate to the intended purpose and to address material quality, provenance, representativeness, access and retention considerations where relevant.

The existence of data does not itself establish a right to use it for AI development or training.

9. CUSTOMER DATA OWNERSHIP AND CONTROL

Customer retains its rights in Customer Data as provided by the Agreement.

BACI will not treat Customer Data as BACI-owned training material merely because it is processed through an AI-enabled Service.

Customer-controlled data remains subject to the applicable contractual, privacy, security and retention framework.

10. NO GENERAL MODEL TRAINING BY DEFAULT

Unless Customer expressly agrees in writing or affirmatively opts into a clearly identified programme, BACI will not use Customer Confidential Information, Customer Personal Data, private Inputs or private Outputs to train or fine-tune general-purpose or shared AI models for the benefit of other customers.

This principle does not prevent Processing reasonably necessary to provide, secure, support, maintain or troubleshoot the Services; follow Customer instructions; comply with law; or perform Customer-specific private training or fine-tuning expressly authorised under applicable terms.

For Customer Personal Data processed on Customer's behalf, the Data Processing Addendum controls.

11. THIRD-PARTY MODELS

BACI may use third-party models or AI infrastructure where appropriate to the Services.

BACI will evaluate material providers according to factors relevant to the intended use, which may include security, privacy, contractual data use, retention, training terms, model capability, reliability, geographic processing, Subprocessor status, legal requirements and operational resilience.

BACI will not represent that a third-party provider offers a particular training, retention, localisation, confidentiality or security commitment unless that commitment is factually and contractually applicable to BACI's use.

12. MODEL SELECTION

BACI may select different models according to task complexity, consequence, latency, cost, capability, security, privacy, availability and other operational requirements.

The most computationally powerful model is not necessarily the appropriate model for every task.

BACI may use governance mechanisms to route higher-consequence decisions to stronger review, more capable systems or additional controls where appropriate.

13. FRONTIER AND HIGH-CAPABILITY MODELS

Where BACI uses frontier or unusually capable models, deployment decisions should consider whether increased capability materially changes risk, autonomy, security, privacy, misuse potential or consequence.

Access to a more capable model does not itself authorise higher-risk activity.

BACI may apply additional thresholds, approval requirements, monitoring or restrictions to higher-capability model use.

14. ACCURACY AND EPISTEMIC LIMITS

AI Outputs may be probabilistic, incomplete, inaccurate, outdated, ambiguous or internally inconsistent.

BACI seeks to improve reliability through appropriate grounding, retrieval, evaluation, validation, monitoring, tool use, structured workflows and other techniques.

BACI will not present probabilistic AI output as guaranteed fact merely because the system generated it confidently.

15. GROUNDING AND SOURCE QUALITY

Where appropriate to the use case, BACI may ground AI systems in Customer Data, authorised external information, structured data, retrieval systems or other relevant sources.

Grounding should use sources appropriate to the intended decision and should respect access rights and confidentiality boundaries.

Grounding can reduce certain errors but does not eliminate the need for proportionate review.

16. TRACEABILITY

BACI seeks to support traceability appropriate to the nature and consequence of AI functionality.

Traceability may include system logs, model or provider identification, data lineage, retrieval records, prompt or instruction records, tool calls, approvals, action records, configuration history and output provenance where technically and legally appropriate.

Not every internal reasoning process of a model can or should be exposed. Traceability focuses on information reasonably useful for governance, verification and accountability.

17. EXPLAINABILITY

BACI seeks to provide explanations appropriate to the type of AI system and intended audience where explanation is meaningful and technically feasible.

Explanation may include relevant source information, material factors, system purpose, limitations, confidence indicators, workflow steps or reasons for an automated recommendation.

BACI will not fabricate an explanation for a model decision where the system cannot reliably provide one.

18. TRANSPARENCY

BACI aims to communicate material information concerning AI-enabled functionality sufficiently for Customers to understand its intended purpose, significant limitations and their own governance responsibilities.

Where appropriate, BACI may identify that content or recommendations are AI-generated or AI-assisted.

Transparency does not require disclosure of BACI trade secrets, security-sensitive information, model weights, proprietary prompts, algorithms or protected intellectual property.

19. FAIRNESS

BACI seeks to reduce unjustified discriminatory effects in AI systems where fairness is relevant to the use case.

Assessment may consider data representativeness, protected characteristics, proxy variables, performance across relevant groups, disparate effects, model limitations and deployment context.

Fairness is context-dependent and may involve legitimate trade-offs; BACI will not represent that a model is universally unbiased merely because it passes a particular test.

20. PROTECTED CHARACTERISTICS

BACI will not intentionally design AI to unlawfully discriminate on the basis of legally protected characteristics.

Use of protected-characteristic data may be appropriate where lawful and necessary for fairness testing, compliance, accessibility, remediation or another legitimate purpose.

Customers remain responsible for lawful deployment of BACI AI in contexts where their decisions affect individuals.

21. HIGH-CONSEQUENCE DECISIONS

BACI AI must not be used as the sole basis for a legally significant or similarly high-consequence decision where Applicable Law prohibits that use or requires meaningful human review.

Relevant contexts may include employment, lending, credit, insurance, housing, education, healthcare, public benefits, law enforcement, immigration and criminal justice.

Where BACI supports such a permitted use, oversight, testing, documentation and intervention should be proportionate to the consequence.

22. HUMAN OVERSIGHT

Human oversight should be meaningful rather than ceremonial.

For consequential uses, an appropriate human reviewer should have sufficient information, authority, competence and time to assess the AI-supported outcome and, where appropriate, override, pause, escalate or reject it.

A requirement to click “approve” does not by itself constitute meaningful oversight if the reviewer cannot realistically evaluate the decision.

23. HUMAN-AI HANDOFF

BACI may design workflows that escalate from AI to a human when the system encounters uncertainty, policy limits, high consequence, missing information, conflicting instructions, safety concerns or other conditions requiring judgment.

The appropriate handoff mechanism depends on the Service and Customer configuration.

24. AUTONOMOUS SYSTEMS

Autonomous functionality may perform authorised actions without Customer approval immediately before each action.

Such functionality must operate within defined authority boundaries supported by the Service and configured by Customer.

Authority may be bounded by spending, financial limits, approval thresholds, markets, jurisdictions, channels, categories, objectives, connected systems, authorised actions, user permissions, frequency, volume and other constraints.

Autonomy does not remove governance.

25. BOUNDED AUTHORITY

BACI does not treat technical access to a connected system as unlimited authority to act.

Autonomous systems should receive only the permissions reasonably necessary for their authorised purpose.

Where practical and proportionate, higher-consequence permissions should be separated, limited, time-bound, approval-gated or otherwise constrained.

26. IRREVERSIBLE AND HIGH-IMPACT ACTIONS

AI systems capable of irreversible or materially consequential actions should receive heightened governance.

Controls may include confirmation, dual approval, transaction limits, staged execution, simulation, rollback where technically possible, restricted tool access, human checkpoints or narrower operating boundaries.

The absence of a technically available rollback increases the importance of pre-action controls.

27. FINANCIAL AUTHORITY

Where AI or Autonomous functionality can initiate spending, purchasing, bidding, advertising expenditure, contractual steps or other financial activity, BACI may support configurable financial limits and approval boundaries.

Customer is responsible for ensuring that delegated authority is valid and appropriate.

An AI recommendation does not itself constitute financial, investment, legal or fiduciary advice.

28. PROCUREMENT, GRANTS AND OPPORTUNITY INTELLIGENCE

BACI AI may identify, analyse, prioritise or support bids, procurement opportunities, grants, funding and other commercial opportunities.

AI must not be used to fabricate eligibility, qualifications, certifications, past performance, pricing evidence, declarations or other material submission information.

Customers remain responsible for the truthfulness and legal sufficiency of submissions.

29. INVESTOR AND FUNDER INTELLIGENCE

AI-supported investor, funder or opportunity matching must respect applicable securities, solicitation, privacy, confidentiality and anti-fraud requirements.

BACI will not treat a predicted match as evidence of endorsement, investment intent, regulatory eligibility or guaranteed funding.

30. COMPETITIVE INTELLIGENCE

AI may support lawful competitive and market intelligence.

BACI does not authorise theft of trade secrets, unauthorised access to private systems, unlawful interception, breach of confidentiality or other prohibited competitive conduct.

Public availability of information does not necessarily eliminate intellectual-property, privacy or contractual restrictions.

31. SAFETY

BACI seeks to design AI systems so that foreseeable safety risks are addressed proportionately to their use.

Unless expressly authorised for a specialised environment, BACI AI is not intended to serve as sole operational control for systems where failure could directly cause death, serious bodily injury, catastrophic physical damage or comparable harm.

Business planning, intelligence and decision support concerning safety-related industries may be permitted subject to appropriate governance.

32. SECURITY

AI systems are subject to BACI's Security Policy / Security Addendum.

Relevant AI security risks may include unauthorised model or tool access, prompt injection, data exfiltration, insecure retrieval, poisoned inputs, malicious files, credential exposure, excessive permissions, model extraction, adversarial manipulation and abuse of Autonomous tools.

BACI may implement controls proportionate to the architecture and risk.

33. PROMPT INJECTION AND TOOL ABUSE

Where AI systems can retrieve external information or use tools, BACI may implement controls designed to reduce unauthorised instruction following, privilege escalation, data disclosure and malicious tool execution.

External content should not automatically be treated as trusted instruction.

High-impact tools may require additional permissions or validation.

34. PRIVACY

AI Processing involving Personal Data is subject to BACI's Privacy Policy, DPA and Applicable Data Protection Law.

BACI seeks to apply purpose limitation, minimisation, access control, retention and lawful-processing principles to AI systems.

AI capability does not create an independent legal basis to collect or use Personal Data.

35. SENSITIVE DATA

BACI will not intentionally expand collection or inference of Sensitive Personal Data merely because AI makes such inference technically possible.

Processing sensitive information must have an appropriate lawful purpose, authority and safeguards.

Specialised or regulated data must not be placed into an ordinary BACI environment where the relevant Service has not been authorised for it.

36. CHILDREN AND VULNERABLE PERSONS

BACI's general commercial Services are designed primarily for business and professional use.

AI functionality should not intentionally exploit age, disability, dependency, vulnerability or limited capacity.

Where a Service is expressly designed for or materially affects children or vulnerable persons, additional safeguards, legal review and age-appropriate or context-appropriate controls may be required.

37. MANIPULATION AND DECEPTION

BACI AI must not be designed or used for unlawful manipulation, coercion, fraud, deceptive impersonation or concealment of material facts.

AI-generated content should not be presented as authentic human-origin evidence where doing so would be materially deceptive.

Legitimate simulation, testing, creative work, research and authorised training contexts are not prohibited merely because synthetic content is used.

38. SYNTHETIC CONTENT AND PROVENANCE

Where appropriate to risk and technical feasibility, BACI may support provenance, labelling, metadata, source information or other mechanisms that help users understand AI-generated or AI-modified content.

Provenance controls are not guaranteed to survive every downstream transformation or third-party system.

39. MISUSE PREVENTION

BACI may use policy controls, access restrictions, monitoring, rate limits, content safeguards, tool permissions, account controls and other mechanisms to reduce prohibited AI use.

The Acceptable Use Policy governs prohibited Customer conduct.

BACI may restrict functionality where reasonably necessary to address material abuse, security risk or legal requirements.

40. RED TEAMING AND ADVERSARIAL TESTING

BACI may conduct adversarial testing, red teaming, abuse-case testing or other evaluations proportionate to the capability and consequence of material AI systems.

Testing may examine instruction adherence, harmful outputs, data leakage, prompt injection, tool misuse, bias, reliability, security and other relevant risks.

Testing does not establish that all possible failure modes have been eliminated.

41. EVALUATION

BACI may evaluate AI systems before and after deployment using qualitative and quantitative methods appropriate to the use case.

Evaluation may address accuracy, task success, groundedness, hallucination, safety, fairness, robustness, latency, security, tool execution, human usability and other relevant measures.

Evaluation criteria should reflect the actual deployment context rather than rely solely on generic benchmarks.

42. PRE-DEPLOYMENT REVIEW

Material AI functionality may undergo risk-based review before general deployment.

Review may consider intended use, prohibited use, data, privacy, security, model/provider selection, testing results, human oversight, autonomy, regulatory context, user disclosure, monitoring and fallback behaviour.

Higher-risk systems may require approval from designated governance functions before release.

43. POST-DEPLOYMENT MONITORING

Responsible AI continues after launch.

BACI may monitor material systems for reliability, safety, security, misuse, drift, changing performance, tool failures, unexpected outcomes, Customer reports and other relevant signals.

Material issues may trigger remediation, additional controls, restricted deployment, model replacement or suspension.

44. MODEL AND SYSTEM CHANGES

Changes to models, prompts, retrieval architecture, tools, permissions or orchestration may alter system risk even when the user interface appears unchanged.

BACI may reassess material changes according to their potential impact.

Routine updates need not undergo the same review as a fundamentally changed capability where risk is not materially increased.

45. INCIDENT MANAGEMENT

Material AI incidents may include harmful or prohibited outputs, unauthorised actions, security compromise, significant data exposure, systematic discrimination, severe reliability failure or other events with material impact.

BACI may investigate, contain, remediate, document and review such incidents according to applicable governance and security processes.

Where an incident constitutes a Security Incident or Personal Data Breach, the DPA and Security Addendum govern applicable notification obligations.

46. STOP, PAUSE AND RESTRICTION AUTHORITY

BACI may pause, disable, restrict or roll back AI functionality where reasonably necessary to address material safety, security, legal, reliability or abuse risk.

The ability to intervene is particularly important for Autonomous functionality.

Where appropriate, BACI may limit only the affected capability rather than suspend unrelated Services.

47. CUSTOMER CONTROL

BACI seeks to provide Customers with control appropriate to the AI functionality offered.

Controls may include mode selection, permissions, data sources, tool access, approval thresholds, financial limits, users, markets, channels, integrations, frequency, volume, monitoring and disablement.

Available controls vary by Service and configuration.

48. CUSTOMER RESPONSIBILITIES

Customers are responsible for selecting appropriate use cases; providing lawful data and instructions; configuring permissions and authority; maintaining qualified human oversight where required; validating material Outputs proportionate to consequence; complying with sector-specific law; and preventing prohibited use.

Customer remains responsible for decisions it makes using BACI Intelligence except to the extent responsibility is allocated otherwise by the Agreement.

49. DEVELOPERS AND INTEGRATORS

Developers and integrators using BACI AI capabilities must preserve applicable safeguards and must not intentionally circumvent safety, security, rate, permission, authority or usage controls.

An integration that materially changes the context or consequence of an AI system may require additional governance by the integrating party.

Developer & API Terms and the Acceptable Use Policy also apply.

50. THIRD-PARTY INTEGRATIONS

BACI may connect AI systems to third-party applications and data sources.

Customer is responsible for authorising Customer-controlled integrations and ensuring that connected systems permit the intended use.

BACI will not treat the existence of an integration as evidence that every technically possible action is legally or contractually authorised.

51. PUBLIC-SECTOR AI

Government and public-sector use may require heightened requirements concerning due process, human oversight, transparency, procurement, records, accessibility, civil liberties, non-discrimination and accountability.

The Government & Public Sector Schedule may impose additional restrictions.

Ordinary BACI environments must not be represented as satisfying specialised government AI requirements unless BACI has established the necessary contractual and factual basis.

52. REGULATORY COMPLIANCE

BACI seeks to design and operate AI functionality in accordance with Applicable Law governing BACI.

AI regulation varies by jurisdiction, system role, use case and risk classification.

BACI may modify, restrict, document or geographically limit functionality where reasonably necessary to comply with legal requirements.

53. AI LITERACY AND TRAINING

BACI may provide role-appropriate guidance or training to personnel involved in material AI development, deployment or governance.

Training may address responsible-AI principles, privacy, security, bias, system limitations, human oversight, incident escalation and applicable legal requirements.

The depth of training may vary by role.

54. MULTI-DISCIPLINARY GOVERNANCE

Material AI governance may involve product, engineering, security, privacy, legal, compliance, domain, user-experience and business perspectives according to the system's risk.

BACI recognises that responsible AI cannot be reduced to model engineering alone.

External expertise may be used where appropriate.

55. DOCUMENTATION

BACI may maintain documentation appropriate to the risk and maturity of material AI systems.

Documentation may include intended use, limitations, data sources, model/provider information, evaluation results, approvals, monitoring, material incidents, authority boundaries and other governance information.

BACI may protect proprietary, privileged, security-sensitive and third-party confidential information.

56. CUSTOMER TRANSPARENCY MATERIALS

BACI may publish or provide AI documentation describing material functionality, limitations, governance controls, model/provider dependencies or responsible-use guidance.

Such materials must accurately reflect the applicable Service and should not claim safeguards or certifications that do not exist.

Product-specific transparency materials may supplement this Policy.

57. ENVIRONMENTAL AND RESOURCE CONSIDERATIONS

Where reasonably practicable, BACI may consider computational efficiency, model selection, workload routing and infrastructure utilisation when they can reduce unnecessary resource consumption without materially compromising security, reliability or required capability.

Environmental considerations form part of responsible technology governance but do not override safety, privacy or legal requirements.

58. ACCESSIBILITY AND INCLUSION

BACI seeks to consider accessibility and inclusive use when designing AI-enabled interfaces and workflows.

AI should not unnecessarily exclude users because of disability, language, technical sophistication or other characteristics where reasonable design can reduce the barrier.

Accessibility requirements applicable to a specific Customer or regulated deployment may be addressed through applicable product or public-sector terms.

59. RESEARCH AND INNOVATION

BACI supports responsible AI research and innovation.

Research involving Customer Data remains subject to the Agreement and BACI's data-use restrictions.

Experimental capability may be offered as beta, preview or evaluation functionality with appropriate limitations and safeguards.

60. RESPONSIBLE RETIREMENT

BACI may retire a model, provider or AI capability when it becomes obsolete, insecure, legally unsuitable, materially unreliable or no longer appropriate for the Services.

Retirement should consider Customer continuity, data retention, migration, contractual commitments and any material effect on Autonomous workflows.

BACI may replace an underlying model without changing the commercial Service where permitted by the Agreement.

61. METRICS AND CONTINUOUS IMPROVEMENT

BACI may use governance metrics, incident trends, evaluation results, Customer feedback, security findings and operational telemetry to improve AI systems and responsible-AI processes.

Metrics should be interpreted in context and should not be used to create a misleading appearance of safety or fairness.

Responsible AI governance will evolve as technology, law and evidence evolve.

62. NO UNIVERSAL SAFETY CLAIM

BACI will not represent that an AI system is universally safe, unbiased, accurate, explainable or appropriate for every use merely because it has passed internal testing.

Suitability depends on the system, data, configuration, deployment context and consequence.

This principle does not reduce BACI's obligation to satisfy express contractual or legal requirements.

63. NO FALSE CERTIFICATION OR COMPLIANCE CLAIM

BACI will not claim compliance with, certification under or conformity to an AI standard, regulatory regime or assurance programme unless the claim is factually supportable and applicable to the relevant BACI system or organisation.

Alignment with principles or use of a framework for internal governance does not itself constitute certification.

64. REPORTING CONCERNS

Customers and users may report suspected AI safety, misuse, privacy or security concerns through the appropriate BACI contact channel.

Security concerns may be directed to security@bacihq.com and privacy concerns to privacy@bacihq.com.

BACI may investigate credible reports and take proportionate corrective action.

65. CHANGES TO THIS POLICY

BACI may update this Policy as AI technology, Services, regulation, industry practice and BACI governance evolve.

Each version will identify its effective and last-updated dates.

BACI will not use this Policy to unilaterally reduce a higher-precedence contractual protection.

66. INTERPRETATION

This Policy establishes BACI's responsible-AI governance framework.

Statements that BACI “may” implement a control recognise that controls vary by system and risk; they do not represent that every listed control exists in every Service.

Statements that BACI “will” follow a principle express BACI's policy commitment within the stated scope.

Mandatory Applicable Law and higher-precedence contractual provisions control to the extent of inconsistency.

67. CONTACT

Responsible-AI and governance enquiries may be directed through BACI's applicable customer or legal contact channel.

Privacy matters: privacy@bacihq.com

Security matters: security@bacihq.com

ANNEX I — BACI RESPONSIBLE AI RISK FRAMEWORK

BACI may assess material AI systems across the following dimensions:

1. Intended purpose and reasonably foreseeable use. 2. Degree of human involvement. 3. Degree of autonomy. 4. Reversibility of actions. 5. Financial, legal, operational or societal consequence. 6. Personal Data and sensitive-data involvement. 7. Fairness and discrimination risk. 8. Safety impact. 9. Security and misuse potential. 10. External-system and tool access. 11. Scale and affected population. 12. Model capability and provider dependency. 13. Reliability and uncertainty. 14. Transparency and traceability needs. 15. Regulatory classification. 16. Customer configuration and authority boundaries. 17. Monitoring and intervention capability. 18. Potential for cumulative or systemic effects.

Controls should become stronger as material risk and consequence increase.

ANNEX II — AI LIFECYCLE GOVERNANCE

BACI's responsible-AI lifecycle may include:

1. CONCEPT — define problem, intended benefit, affected stakeholders and whether AI is appropriate. 2. CLASSIFY — assess risk, autonomy, data, consequence and regulatory context. 3. DESIGN — establish permissions, oversight, data governance, safety and security requirements. 4. BUILD — implement models, prompts, retrieval, tools and controls. 5. EVALUATE — test reliability, safety, fairness, security, tool behaviour and intended performance. 6. APPROVE — obtain risk-appropriate review before deployment. 7. DEPLOY — release with appropriate documentation, permissions and monitoring. 8. MONITOR — observe material performance, incidents, misuse and drift. 9. RESPOND — remediate, restrict, pause or escalate when material issues arise. 10. CHANGE — reassess material model, data, tool, permission or architecture changes. 11. RETIRE — safely decommission or replace systems and address data and workflow dependencies.

Not every low-risk feature requires identical governance depth.

ANNEX III — AUTONOMY GOVERNANCE MODEL

BACI recognises three principal operating modes:

MANUAL — BACI discovers, analyses, organises, generates, prioritises or recommends. Customer decides whether to act.

HYBRID — BACI may perform Customer-authorised actions within defined parameters while designated decisions or actions remain subject to approval.

AUTONOMOUS — BACI may perform authorised actions or processes without individual Customer approval immediately before each action, within Customer-established authority and supported Service controls.

Autonomous authority may be constrained by:

spending or financial limits; • approval thresholds; • markets and jurisdictions; • channels; • categories and objectives; • connected systems; • authorised action types; • user and role permissions; • frequency and volume; • time periods; • risk thresholds; and • other supported constraints.

Technical capability does not equal authority. Customer cannot delegate authority it does not possess. Autonomous functionality must not be used to bypass legally required human review.

Autonomy does not remove governance.

ANNEX IV — HIGH-CONSEQUENCE CONTROL FRAMEWORK

Where AI materially affects rights, access, safety, finances or other significant interests, appropriate controls may include:

1. documented intended use and prohibited use; 2. qualified human oversight; 3. data-quality and relevance review; 4. fairness assessment where applicable; 5. source and provenance controls; 6. accuracy and reliability evaluation; 7. explanation or reason information where appropriate; 8. audit logging; 9. approval thresholds; 10. restricted permissions; 11. rollback or intervention mechanisms where technically possible; 12. incident escalation; 13. ongoing monitoring; 14. Customer governance guidance; 15. legal or regulatory assessment; and 16. periodic reassessment.

The exact controls depend on the system and Applicable Law.

ANNEX V — RESPONSIBLE AI RESPONSIBILITY MODEL

BACI RESPONSIBILITIES may include responsible design of BACI-controlled functionality; appropriate security and privacy controls; risk-based testing; supported authority controls; governance of BACI-selected AI providers; material system monitoring; incident response; accurate product transparency; and compliance with BACI's contractual data-use commitments.

CUSTOMER RESPONSIBILITIES include lawful use-case selection; lawful Inputs and instructions; Customer-specific legal compliance; user permissions; connected-system authority; configuration of operating mode and authority boundaries; appropriate human oversight; verification of consequential Outputs; and compliance with the Acceptable Use Policy.

SHARED RESPONSIBILITIES may include deployment risk assessment, data quality, integration security, monitoring, incident coordination, human workflow design and regulated-use governance.

The applicable Agreement controls if it expressly allocates a responsibility differently.

BACI RESPONSIBLE AI POLICY — VERSION 1.0 Effective 10 September 2026

RELATED

We're listening.