Journeying together,

with Transparency

## Risk Disclosure

Last Updated March 30 2024

## Definitions

**GenAI Systems/ Tools/Generators, GenAI** any sophisticated artificial intelligence models that can understand and generate human-like text by leveraging vast amounts of training data and deep learning techniques. They excel in tasks such as natural language processing, content generation, and question answering, but their understanding is based on statistical patterns rather than true comprehension.

**API** means Application Programming Interface.

**BYOD** means Bring Your Own Device.

**CISO** means Chief Information Security Officer.

**Company Data** should be interpreted broadly for purposes of this Policy, and includes, but is not limited to, at least the following: all Company business information and all Personal Data (whether of employees, executives, contractors, consultants, Customers, consumers, users, or other persons) that is accessed, collected, used, processed, stored, shared, distributed, transferred, disclosed, destroyed, or disposed of by any of the Company systems; all proprietary information and intellectual property (including, but not limited to, source code, designs, schematics, product roadmaps, product plans, product specifications, market analyses, white papers, strategy documents, financial information, internal communications, Customer lists, Customer files, Customer contact information, Customer contracts, Customer's proprietary data, and any non-public Company information. Company Data includes information in written, electronic, audio, video, or any other form or medium. Company Data can include any level of information covered by the Company’s policies.)

**Customer Data** any and all data that the third parties who contract as Customers with the Company provide to the Company to use, store, transmit, or process.

**Customer(s)** any unique contracting entity listed within an active order form with the Company, including all individuals acting on the entity's behalf.

**DPO** means Data Protection Officer.

**IP (Intellectual Property)** any asset that is or may in future become the subject of intellectual property rights under the laws of any jurisdiction, including computer code and its protected elements, texts, graphics, logos, drawings, button icons, images, audio, video, audio-visual works, photographic works, fonts, musical works and sounds, data compilations (databases), any other works, performances, phonograms, videograms, inventions, utility models, industrial designs, designs, improvements, developments, scientific discoveries, trademarks, innovations, know-how and trade secrets and any other objects protected by the IP Rights.

**IP Rights (Intellectual Property rights)** any and all patent rights, rights to inventions, trademark, trade names and domain names rights, know-how and trade secret rights, rights in get-up, rights in goodwill or to sue for passing off, rights in designs, copyright and related rights and any other intellectual property rights, including any moral rights and proprietary rights, rights of publicity or privacy and all similar or equivalent rights or forms of protection, in each case, whether registered or unregistered, granted, applied for or otherwise existing now or in the future under the laws of any jurisdiction (including all applications (or rights to apply) for, and renewals or extensions of, such rights and forms of protection).

**Personal Data** within the meaning given in GDPR, any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. PII (Personally Identifiable Information) in the understanding of U.S. laws is also encompassed by the term “Personal Data” used in the Policy.

**SSO** means Single Sign-On.

**Team Member(s)** all employees permanent, contract and temporary and those under a contract for services with the Company or an affiliate of the Company as an outsourced services supplier.

## Introduction

### About GenAI

Generative AI (the “GenAI”) is a form of artificial intelligence that creates new content like text, images, or music by learning from existing data. Models like ChatGPT and Google's Bard exemplify GenAI.

### Our Approach to GenAI

At nyx.today (the “Company”), we value responsible and ethical use of GenAI as an assistant, not a replacement. We address legal and ethical concerns and establish decision-making principles for its workplace use. This Generative AI Company Use Policy (the “Policy”) provides guidance and rules for responsible GenAI use by Team Members, aiming to leverage technology for good without causing harm.

### Purpose

As GenAI tools like ChatGPT and Google’s Bard gain popularity, it is essential to outline their proper use at the Company. We adopt new technologies while ensuring responsible application and risk awareness.

The Policy establishes ethical guidelines and best practices for GenAI use within the Company. It complies with laws and regulations and safeguards Team Members, suppliers, Customers, and the Company.

### Eligibility

This Policy applies to all Team Members using or interacting with GenAI, including language models, plugins, and data-enabled tools. It covers on/off-premises work using BYOD devices for work activities.

## Principles for GenAI Use

### Responsible Use

Team Members must employ GenAI responsibly, avoiding harm, privacy violations, and malicious activities. It should promote fairness, avoid bias and discrimination, and align with the Company's values. GenAI can be used for work-related tasks like generating content for reports, emails, presentations, images, and Customer service, subject to Policy adherence.

### Ethical Use

GenAI must be used ethically, complying with laws and organisational policies. Team Members should not create discriminatory, offensive, or inappropriate content. If there are any uncertainties about the appropriateness of using GenAI in a particular situation, Team Members should consult with their supervisor or Information Governance Team.

### Compliance with Laws and Regulations

GenAI must comply with all applicable laws, including data protection, privacy, and IP laws.

### Transparency and Accountability

Team Members must be transparent about GenAI use in their work and utilise the Company's system for governance and compliance. Team Members are accountable for outcomes generated by GenAI and should be prepared to explain and justify those outcomes.

### Data Privacy and Security

Adhere to the Company's data privacy and security policies when using GenAI. Anonymise and securely store any Personal Data or sensitive data used.

### Bias and Fairness

Mitigate biases in GenAI to ensure fairness and inclusivity, avoiding discrimination.

### Human-GenAI Collaboration

Use judgement when interpreting and acting on GenAI-generated recommendations. GenAI is a tool to augment human decision-making, not replace it.

### Training and Education

Team Members must receive appropriate training for responsible GenAI use and stay informed about advancements and ethical concerns.
