KORE AI Governance Addendum to POL-022

TERMS OF USE

Last Updated: August 6, 2026

Supplement to the existing AI Usage Policy

Purpose

This AI Governance Addendum supplements POL-022 AI Usage Policy and establishes additional governance requirements for Company-approved AI tools, internal AI applications, AI-enabled business platforms, and approved AI use cases.

Output Reliability

AI-generated outputs may be inaccurate, incomplete, biased, misleading, inconsistent, or outdated. Employees, contractors, and other authorized users remain responsible for reviewing and validating all AI-generated outputs before using them for Company business.

Human Oversight

AI tools may not be used as the sole basis for legal, compliance, financial, accounting, tax, HR, employment, compensation, promotion, disciplinary, safety, security, customer-impacting, or other material business decisions. Appropriate human review and approval are required before any AI-generated output is used for such purposes.

High-Risk Use Case Review

The following AI use cases require review and approval by Security, Compliance, and Legal before deployment or use:

  • Processing regulated, confidential, customer, employee, or sensitive information.
  • Use in employment, disciplinary, compensation, promotion, termination, or HR workflows.
  • Customer-facing AI tools or externally available AI features.
  • Automated decision-making or recommendations that materially affect individuals or customers.
  • Legal, compliance, financial, tax, safety, or security-related recommendations.
  • Use of prompts, uploaded data, or outputs for model training, retraining, fine-tuning, or improvement.
  • Integration of a new AI vendor, model, plug-in, connector, browser extension, or data source.

Company Ownership

Prompts, inputs, uploaded content, submitted information, AI-generated outputs, reports, analyses, drafts, summaries, and work product created through approved AI tools in connection with Company business are Company property and Company records.

No Expectation of Privacy

Users should have no expectation of personal privacy when using Company-approved AI tools or Company AI systems. Prompts, uploaded content, generated outputs, logs, usage records, acceptance records, and related activity may be monitored, reviewed, retained, audited, disclosed, or investigated by authorized Company personnel for legitimate business, security, compliance, legal, operational, and administrative purposes.

Model Training Restrictions

Company information, customer information, confidential information, personal information, prompts, uploaded files, and AI-generated outputs may not be used to train, retrain, fine-tune, or improve AI models unless expressly approved in advance by Security, Compliance, and Legal.

Data Retention

Prompts, uploaded content, AI-generated outputs, logs, usage records, acceptance records, and related activity data may be retained in accordance with Company record-retention requirements, legal-hold obligations, audit requirements, compliance needs, security investigations, operational requirements, and legitimate business purposes.

Business units and system owners should not delete AI records that are subject to litigation hold, investigation, audit, security review, compliance review, regulatory inquiry, or other preservation requirement.

Sensitive Data Restrictions

Users must not submit personal information, sensitive information, confidential information, customer data, employee data, financial information, protected health information, credentials, source code, security configurations, contracts, or other restricted information into AI tools unless the tool has been expressly approved to process that category of information.

Governance Workflow

Activity Business Unit Security Compliance Legal
New AI tool request Submit use case and business need Security review and approval Privacy/compliance review Legal review if high risk
High-risk AI use case Submit details and impact Approve controls Approve compliance approach Approve legal risk treatment
AI vendor/model change Notify stakeholders Review vendor/security impact Review privacy impact Review contractual/legal issues
Customer-facing AI Request approval Approve security posture Approve compliance posture Approve terms, disclosures, and risk allocation
Model training use Request exception Approve technical controls Approve data use and compliance Approve legal and IP treatment

 

Implementation Requirements

  • Maintain an Approved AI Tools List.
  • Require users to complete the AI Tool User Acknowledgment before accessing approved internal AI tools.
  • Maintain acceptance logs and historical versions of AI acknowledgments.
  • Conduct Privacy Impact Assessments when AI tools process personal or sensitive data.
  • Require Legal, Security, and Compliance review before customer-facing deployment, model training, automated decision-making, or high-risk uses.