Sustainable Corporate Operation
Responsible Artificial Intelligence Policy
Purpose
In response to the rapid advancement of Artificial Intelligence (AI) technology, the Company continuously monitors opportunities for AI application in manufacturing, engineering, quality, operations management, and other business areas, while remaining mindful of the information security, data privacy, intellectual property, operational, and social responsibility issues that AI may give rise to.
The Company upholds the principle of responsible and prudent use of AI. While advancing digital transformation and technological innovation, the Company balances the interests of the Company, employees, customers, suppliers, and other stakeholders, and progressively establishes appropriate AI governance and risk management mechanisms.
Scope of Application
This Policy applies to AI-related technologies and services developed, introduced, procured, integrated, or used by the Company in the course of its business activities, including AI systems, models, algorithms, and generative AI tools.
AI functions provided by third parties or integrated into existing software, information systems, and equipment shall also follow the relevant principles of this Policy, according to their use context and level of risk.
Fundamental Principles of Responsible AI
- Legal and Regulatory Compliance
The Company's AI applications shall comply with applicable laws, contractual requirements, and internal management regulations of the jurisdictions in which it operates, and shall continuously monitor developments in AI-related regulations (such as the EU AI Act) and international standards (such as the OECD AI Principles and ISO 42001).
AI applications involving personal data, trade secrets, intellectual property, and other protected information shall be properly managed in accordance with relevant laws and Company regulations. - Human Oversight and Accountability
AI shall serve as a tool to assist personnel in performing their duties and improving the quality of decision-making. For matters involving significant operational, quality, information security, employee, or customer interests, appropriate human judgment and oversight mechanisms (human-in-the-loop) shall be maintained according to the use context, enabling personnel to intervene, override, or escalate as necessary. Outputs generated by AI shall not be presumed correct; users shall exercise professional judgment to confirm the reasonableness and applicability of such outputs and remain accountable for final decisions and actions taken. - Data Privacy and Data Governance
The Company places importance on data protection and privacy throughout AI applications. The acquisition, processing, use, and retention of data by AI systems shall comply with applicable personal data protection and data governance requirements. Without appropriate authorization or approval, Company confidential information, trade secrets, customer data, personal data, or other protected information shall not be input into AI services that have not been evaluated by the Company. - Information Security and Reliability
The Company shall pay attention to the information security, data integrity, and system reliability of AI systems according to the use context and level of risk, and shall adopt specific safeguards for high-risk AI applications, including but not limited to data and model encryption, access control, regular vulnerability scanning and penetration testing, prompt injection protection, and output content filtering mechanisms. Appropriate preventive and management measures shall be taken, commensurate with risk, to address unauthorized access, data leakage, malicious input, anomalous output, and other information security risks that AI systems may generate. - Fairness and Avoidance of Improper Bias
The Company values fairness in AI applications and shall, according to the purpose and degree of impact, appropriately address data quality, algorithmic bias, and potential unfair impacts arising from AI outputs, including conducting regular fairness and bias assessments for high-impact AI applications. AI shall not be used as a tool for improper discrimination or infringement of the lawful rights of individuals or specific groups. - Transparency and Appropriate Disclosure
The Company shall provide an appropriate level of information, according to the use context and potential impact of AI, to enable relevant users to understand the purpose, key functions, and limitations of AI applications. For significant or high-impact AI applications, appropriate records and traceability mechanisms shall be established as needed, and generative AI content provided externally shall be appropriately labeled so that recipients are aware it is AI-generated. - Intellectual Property Rights
The Company respects and protects the intellectual property rights of the Company and third parties. When using AI-related services, attention shall be paid to data sources, licensing terms, and usage restrictions on generated content, to avoid infringement of copyrights, patents, trade secrets, or other intellectual property rights arising from AI applications. - Third-Party AI Services
For AI services procured from external vendors, outsourced for development, or otherwise used, the Company shall conduct appropriate evaluation and management according to their purpose, data nature, and risk level. Third-party AI services involving important Company information or sensitive data shall comply with the Company's relevant information security, data protection, and vendor management requirements, and preference shall be given to AI service providers and data centers with demonstrated energy efficiency and low ecological footprint practices. - Low Ecological Footprint and Green AI
When evaluating, procuring, or building AI computing infrastructure (including servers and data centers), the Company shall, as circumstances warrant, take into account energy efficiency, water consumption, and carbon emission intensity, and shall encourage the use of model optimization techniques (such as quantization and distillation) to reduce computational resource waste, while progressively measuring and disclosing the impact of AI applications on the Company's sustainability performance. - Prohibited AI System Types
The Company shall not develop, procure, or deploy AI systems that exhibit any of the following characteristics: use of subliminal, manipulative, or deceptive techniques that materially distort user behavior and cause or are likely to cause harm; exploitation of vulnerabilities related to age, disability, or socio-economic status to materially distort behavior; social scoring of individuals based on social behavior or personal characteristics that results in detrimental treatment in unrelated contexts; and real-time remote biometric identification and surveillance systems not authorized by law. - Risk Management and Continuous Improvement
The Company shall progressively establish corresponding risk identification, assessment, and management mechanisms in line with the development of AI technology and actual application circumstances. Where significant changes occur in the purpose, data, model, vendor, or use context of an AI application, the related risks and management measures shall be reviewed according to the degree of impact.
Governance and Accountability
The Company shall progressively establish an AI governance mechanism based on organizational authority, with relevant management units jointly promoting the reasonable and responsible use of AI according to their respective functions. Each business unit shall bear corresponding management responsibility for the AI applications it uses and shall designate a Business Owner and a Technical Owner for significant AI systems introduced, to ensure clear and traceable accountability. Information security, legal, human resources, sustainability, and other relevant units shall provide necessary professional assistance and risk management according to their responsibilities. AI applications involving significant risk or potential significant impact on the Company and its stakeholders shall undergo appropriate evaluation and approval in accordance with the Company's relevant management procedures.
Employee Responsibilities in AI Use
The Company shall progressively establish relevant regulations and educational mechanisms for employees' use of AI, in line with the development of AI applications, and shall provide necessary training on AI ethics, information security risks, and the content of this Policy. When employees use AI tools to perform business tasks, they shall comply with the Company's information security, data protection, intellectual property, and other relevant regulations, and shall verify AI-generated outputs as necessary. The use of AI shall not exempt employees from their existing professional and management responsibilities.
Responsible AI Implementation Program
To ensure this Policy is implemented in day-to-day operations, the Company shall, as circumstances develop, progressively advance the following implementation measures:
- Establish a company-wide AI system inventory to track the purpose, data sources, and risk level of existing AI systems.
- Set usage and access restrictions for high-impact or sensitive AI applications (such as biometric identification or surveillance-related functions).
- Establish appropriate labeling mechanisms for generative AI content used in external communications or customer-facing contexts.
- Establish performance and model drift monitoring mechanisms for significant AI systems, and set procedures for handling anomalies.
- Establish a channel for stakeholders affected by AI decisions to file appeals or objections.
- Conduct fairness and bias assessments for high-impact AI applications on a regular basis (at least annually).
- Evaluate the feasibility of adopting the ISO 42001 AI management system standard or an equivalent external verification mechanism.
Continuous Improvement
The Company shall continuously monitor developments in AI technology, industry practices, relevant regulations, and international standards, and shall refer to applicable international AI governance principles and management frameworks (such as the OECD AI Principles, the EU AI Act, and ISO 42001) to progressively enhance its AI governance and risk management capabilities.
The actual management measures under this Policy shall be progressively refined according to the Company's level of AI application, business needs, and risk characteristics.
Policy Approval and Public Disclosure
This Policy shall be implemented upon approval by the Company's management and shall be publicly disclosed on the Company's official website.
The Company shall review the applicability and content of this Policy at least annually, in light of the operating environment, AI technology developments, applicable regulations, and actual implementation experience, and shall revise it as necessary.
Policy Approval: Company Management
Applicable To: The Company
Disclosure Method: Company Official Website
Effective Date: As officially announced by the Company
Version: 1.0