Ambi Robotics, Inc.
| Field | Value |
| Document Owner | CTO |
| Approver | CTO and acting CISO |
| Version | 2.1 |
1. Purpose
Ambi Robotics, Inc. (“Ambi”) permits the use of artificial intelligence (“AI”) tools by Personnel where such use advances Ambi business interests and is conducted in compliance with this policy. AI tools provide productivity benefits but introduce material risks, including potential disclosure of confidential information, ambiguity in intellectual property ownership, consequential decisions made without competent human judgment, the introduction of insecure or non-compliant AI-generated code, and the propagation of these risks through Service Providers.
This policy governs the use of AI tools by Personnel and establishes the requirements that must be met to manage those risks. It addresses approved tools, permitted data, automated decisions, intellectual property, AI-generated code, customer-facing AI, Service Providers, security controls, incident reporting, training, records, and sanctions. (Please note that most capitalized terms are defined in Section 3 (Definitions) below; other capitalized terms are defined as set out in the Data Classification Policy, in the General Information Security Policy, or as the context requires.)
This document entirely replaces all earlier-dated versions of this policy.
2. Scope
2.1 Persons in Scope
This policy applies to all Personnel. “Personnel” means employees (full-time and part-time, regardless of role or location), contractors, consultants, temporary staff, interns, Service Providers, vendors, and any agent of the foregoing who, in the course of services for Ambi, access Ambi Confidential Data or Restricted Data; create intellectual property on behalf of Ambi; or otherwise use AI in connection with services provided to Ambi.
2.2 Equipment and Settings in Scope
This policy applies to Personnel use of AI on Ambi-issued equipment, on personally owned equipment used for Ambi business, on third-party equipment, and via cloud services. It applies during and outside working hours where the use relates to Ambi business.
2.3 Out of Scope
This policy does not regulate personal use of AI on personally owned equipment for matters unrelated to Ambi business, except where such use involves Ambi Confidential Data, Restricted Data, or existing or newly created Ambi intellectual property.
2.4 Relationship to Other Policies
This policy must be read together with the General Information Security Policy, Data Classification Policy, Acceptable Use Policy, Software Development Lifecycle Policy, Procurement and Vendor Management Policy, Incident Response Policy, and the confidentiality and IP provisions of standard Ambi employment and contractor agreements. The applicable documents are available upon request.
Where this policy and a related policy address the same subject, the stricter provision applies unless the related policy expressly states otherwise.
Operational implementation detail is set out in companion guidance documents maintained by Information Security. Companion guidance supports but does not supersede this policy.
3. Definitions
AI (Artificial Intelligence). Any third-party system, software, or service (i.e., excluding Ambi systems, software and services) that uses machine learning, large language models, or comparable techniques to generate or transform content, make predictions, automate decisions, or assist in tasks. Includes general-purpose assistants (e.g., Claude, ChatGPT, Gemini, Microsoft Copilot), coding assistants (e.g., Claude Code, Cursor, GitHub Copilot, Windsurf), agentic browser tools, Office-integrated assistants, task-automation agents, MCP servers and other AI agent tooling, AI features embedded in third-party software, and successor systems.
AI-Generated Code. Code in which AI provided more than trivial assistance, as further defined in Section 4.7.
Authorized AI Tool. An AI tool that appears on the Authorized AI Tool List for the data classification at issue and the use case at issue.
Authorized AI Tool List. The list, maintained by Information Security and published on the internal portal, of AI tools approved for Ambi use, classified by the highest data classification each tool may process and the specific approved procurement (vendor, plan, contract, account).
Automated Decision. Any output, recommendation, ranking, or determination produced by an AI tool that contributes to a decision affecting a natural person or binding Ambi.
Confidential Data. Ambi information classified as Confidential under the Data Classification Policy, intended for internal use. Includes, without limitation: strategic plans, internal communications, non-public financial information, product roadmaps, Ambi source code, Ambi employee information not otherwise classified as Restricted Data, and customer data that is not subject to a contractual restriction on third-party processing and is not otherwise Restricted under Section 3.
Personnel. As defined in Section 2.1.
Prompt Injection. An attack in which adversarial instructions embedded in content the AI processes (including web pages, documents, files, emails, calendar entries, or repositories) cause the AI to take actions or produce outputs not requested by the user.
Public Data. Information that has been or may be disclosed publicly without harm to Ambi and without breach of Ambi’s legal or contractual obligations.
Restricted Data. This is the most sensitive category of Ambi information. Customer data that is not classified as Restricted Data may still be Confidential Data. Where Personnel cannot determine with confidence which category applies to a given customer data set, Personnel must treat the data as Restricted and seek clarification under Section 4.2.5 before processing it with any AI tool. Restricted Data includes:
- Customer and other third-party data (e.g., from partners, vendors, prospective customers, prospective employees, and prospective acquisition or investment targets) subject to NDAs or other contracts that restrict third-party processing. This includes data belonging to, originating from, generated about, or processed on behalf of customers, users, and end-users; customer-supplied content; and data collected by deployed Ambi systems in customer environments — where the applicable customer agreement, data processing agreement, NDA, master service agreement, or other binding instrument restricts processing by, or transfer to, third parties.
- High-sensitivity PII, including Social Security numbers, driver’s license numbers, passport numbers, and payment card numbers;
- Protected health information (PHI);
- Payment card data subject to PCI DSS, including PAN and CVV;
- Credentials, API keys, tokens, and cryptographic keys; and
- Any other category designated as Restricted under the Data Classification Policy.
Service Provider. Any third party that accesses Ambi Confidential Data, Restricted Data, or Ambi systems, creates intellectual property on Ambi’s behalf, or otherwise uses AI in connection with services provided to Ambi.
4. Policy
4.1 Approved AI Tools
Personnel must use only Authorized AI Tools and only for the data classifications and use cases for which the tool has been approved.
4.1.1 Approval Required. Free-tier consumer products and free trials are not approved. Approval is specific to each listed procurement. A different tier of the same product, or use from a personal account on any tier, is not approved unless that specific tier and procurement appears on the Authorized AI Tool List in its own right.
4.1.2 Approval Process. A request to add a tool to the Authorized AI Tool List must include a business case identifying the intended use, the data classifications involved, and the integration scope. Information Security shall review data residency and retention, model-training opt-outs, transport and at-rest encryption, access control, audit logging, and contractual data-processing protections. Legal Counsel shall review intellectual property and contract terms, including the provider’s terms of service.
4.1.3 Tools That Connect to Ambi Systems. AI tools that connect to Ambi systems — including MCP servers, connectors, browser extensions, IDE plugins, and Office add-ins — are subject to a separate inventory and approval for the specific connections enabled. Personnel must not install or enable such connections except as approved.
4.1.4 Tools Used to Produce AI-Generated Code. Tools used to produce or review AI-Generated Code must have, as part of their approval record, an explicit statement of the reviewer seniority required for outputs of that tool, consistent with Section 4.7.
4.1.5 Time-Limited Approvals. All approvals are time-limited and shall be re-reviewed at least annually, or sooner where the tool’s terms or capabilities change materially.
4.1.6 Current State of the Authorized AI Tool List. As of the Effective Date, no AI tool has been approved for processing Restricted Data. Personnel must not input Restricted Data into any AI tool unless and until a tool is added to the Authorized AI Tool List for that data classification and the specific use case is approved under Section 4.4.
4.2 Permitted Data by Classification
Personnel must not input Ambi data into an AI tool except as permitted by this section.
4.2.1 Public Data. Any Authorized AI Tool may process Public Data consistent with the tool’s terms.
4.2.2 Confidential Data. Confidential Data may be processed only by AI tools approved for Confidential Data on the Authorized AI Tool List. Personnel must not paste, upload, or otherwise transmit Confidential Data to any AI tool outside that list.
4.2.3 Restricted Data. Restricted Data may be processed only by AI tools approved for Restricted Data on the Authorized AI Tool List, and only pursuant to an approved use case under Section 4.4. The approval bar for Restricted Data is materially higher than for Confidential Data, and few consumer AI products will meet it. Personnel must refer to Section 4.1.6 for the current state of the Authorized AI Tool List.
4.2.4 Classification Uncertainty. Where the classification of data is unclear, Personnel must treat the data based on the higher classification until the correct classification is established by reference to the Data Classification Policy or by consultation with Information Security.
4.2.5 Duty to Seek Clarification. If Personnel are not certain whether information is Restricted Data, Confidential Data, or Public Data, Personnel must seek clarification before inputting the information into any AI tool. Clarification may be sought from Information Security, Legal Counsel, or — for customer data specifically — from the account owner or the Customer Success function with knowledge of the relevant contractual terms. Personnel must not resolve classification uncertainty on their own judgment, and must not proceed on the assumption that ambiguous data is non-Restricted. Where the question is whether customer data is subject to a contractual restriction on third-party processing, only the contract custodian or Legal Counsel can make that determination authoritatively.
4.3 Data Minimization
Personnel must not input data into an AI tool beyond what the task requires. Where the analysis does not require specific identifying details, Personnel must remove names, account numbers, specific dates, project codenames, internal URLs, internal tool names, and other identifying particulars before input. Where Personnel cannot determine with confidence that an input has been adequately minimized, Personnel must not input the material.
4.4 Restricted Data and Special-Category Data — Named Approval Required
Notwithstanding any general approval of an AI tool, the following categories of data must not be input into any AI tool without explicit, named, written approval from Information Security and Legal Counsel:
- Protected health information (PHI);
- Payment card data (PAN, CVV);
- Social Security numbers and government-issued identifiers (including driver’s license and passport numbers);
- Private cryptographic keys;
- Customer secrets and credentials;
- Customer data subject to NDAs or other contracts that restrict third-party processing (other customer data is Confidential under Section 3 and is governed by Section 4.2.2);
- Any other category of Restricted Data identified by Information Security as requiring named approval.
A request for written approval must specify the data category, the AI tool proposed, the business need, the duration of the approval, and the controls applied. Approvals are recorded under Section 6 and expire on the stated date.
4.5 Automated Decisions
4.5.1 General Rule. AI tools must not be the basis of any final decision affecting a natural person or binding Ambi without competent human review. This requirement applies regardless of the apparent quality or confidence of the AI’s output. AI tools may inform, recommend, summarize, and rank; a qualified human Personnel must decide, and the same Personnel owns the outcome.
4.5.2 Decisions in Scope. The decisions to which Section 4.5.1 applies include, without limitation:
- Hiring: offers, rejections, advancement between interview stages, and compensation determinations.
- Performance management: ratings, raises, promotions, performance improvement plans, and terminations.
- Customer-facing decisions of consequence: account suspension or termination, eligibility determinations, refund denials, credit decisions, and complaint resolutions.
- Commitments binding Ambi: contract interpretations, exception approvals, and escalations.
- Legal, regulatory, or compliance determinations: licensing decisions, regulatory filings, breach notifications, and dispute outcomes.
- Security-relevant decisions: access provisioning or revocation, incident severity classification, and escalation determinations.
- Safety-critical decisions: any decision affecting the operation of Ambi robotic systems in customer environments, motion control, or human-robot interaction.
- Any other decision the consequences of which, if wrong, would be material to a natural person, Ambi, or its customers.
4.5.3 Competent Human Review. Review under this section must be substantive, not procedural. The reviewer shall read the inputs the AI tool considered; have authority to override the AI tool’s output; be qualified to apply professional, ethical, and business judgment at the level of consequence the decision carries; record the decision and reasoning to the extent reasonably required to support audit, dispute resolution, and regulatory inquiry; and where the AI’s recommendation depends on data the reviewer cannot inspect, either obtain access to that data or treat the recommendation as non-binding.
4.5.4 Evaluation of Personnel by AI. AI tools must not be used to evaluate Personnel performance directly without prior written approval from the People team and Legal Counsel, a published methodology, and a process by which Personnel may challenge AI-derived inputs.
4.5.5 Applicable Law. Certain U.S. and foreign laws and regulations impose additional requirements on automated decision-making in certain circumstances. These include, without limitation, the EU AI Act, GDPR Article 22, the California Consumer Privacy Act and CPRA, NYC Local Law 144, the Illinois AI Video Interview Act, and sector-specific regulations. When in doubt, consult Legal Counsel as to the applicability of these requirements in specific circumstances.
4.5.6 Product-Embedded AI. AI and machine-learning components built into Ambi products and services (for example, perception, planning, or control systems shipped in Ambi robots) are governed by separate engineering and product governance maintained by the engineering organization, which must remain consistent with this policy. Section 4.5 governs Personnel use of AI in the conduct of Ambi work; product-level AI governance is administered separately.
4.6 Intellectual Property
The intellectual property landscape for AI-generated content is evolving in courts, regulation, and contract practice. Ambi’s positions in this section are subject to update by Legal Counsel as the law develops.
4.6.1 Ownership of Outputs. Subject to the terms of the AI tool used, content Personnel produce with AI for Ambi business is Ambi intellectual property to the extent Personnel can convey those rights to Ambi. Personnel must not use AI tools whose terms grant the provider ownership, exclusive license, or other rights that conflict with Ambi’s intellectual property position. The Authorized AI Tool approval process addresses this requirement.
4.6.2 Inputs. Ambi source code, designs, and proprietary content input to an Authorized AI Tool remains Ambi intellectual property. Personnel must not input third-party content where the AI’s processing would violate the terms under which the content was provided, including, without limitation: internal-use-only licensed content; code under copyleft licenses where AI processing may implicate flow-down provisions; and customer-provided material covered by an NDA that limits third-party processing (which is in any case Restricted Data under Section 3).
4.6.3 Fine-Tuned Models and Derivative AI Artifacts. Personnel must not create fine-tuned models, custom embeddings, vector indices, or other derivative AI artifacts using Ambi data without prior written approval from Information Security and Legal Counsel. The retention and intellectual property implications of derivative artifacts differ materially from one-time prompts and require independent analysis.
4.6.4 Attribution and External Disclosure. Where Personnel produce content for external distribution and AI played a non-trivial role, Personnel shall consult Marketing or Legal Counsel regarding disclosure. Ambi may require disclosure for specified categories of external content.
4.6.5 Patents and Copyright. Inventions and creative works developed with substantial AI assistance have complex patentability and copyrightability status under current law. Personnel involved in invention disclosures, patent applications, or copyright registrations shall disclose material AI assistance to Legal Counsel so that filings may be made correctly. In the United States as of the Effective Date, purely AI-generated material is not eligible for copyright registration, and AI cannot be named as an inventor on a patent.
4.6.6 Verification. AI systems are known to produce inaccurate or fabricated content, including citations, statistics, code, and factual claims. Personnel remain responsible for verifying the accuracy of any AI output incorporated into Ambi work product. Unverified AI output that proves incorrect, where verification was reasonable, is the responsibility of the Personnel who incorporated it.
4.7 AI-Generated Code
4.7.1 Definition. AI-Generated Code means code in which AI provided more than trivial assistance. AI-Generated Code includes code produced by a coding assistant (including Claude Code, Cursor, GitHub Copilot, Windsurf, or comparable tools) and accepted with minor or no modification; code where AI proposed the architecture or approach the engineer adopted; and code where AI was the primary author and Personnel acted as reviewer and editor. However, small autocompletes and small syntactic suggestions do not constitute AI-Generated Code.
4.7.2 Review Required. AI-Generated Code shipped to Ambi systems or to customers shall be reviewed by an appropriately senior engineer prior to merge or release. Reviewer seniority shall be determined by the impact and risk profile of the code, as set out in Section 4.7.3.
4.7.3 Required Reviewer Seniority.
| Code Category | Minimum Reviewer Seniority |
| Internal tooling, sandboxes, prototypes, throwaway scripts | Any engineer other than the original author |
| Internal-facing production code; non-customer-facing utilities | Senior engineer (L4/L5 or equivalent) |
| Customer-facing application code; backend services; APIs | Senior engineer with at least six (6) months’ Ambi tenure |
| Security-relevant code (authentication, authorization, input validation, output encoding, cryptography, secrets handling, network egress, file handling) | Senior engineer and a Security team member or designated security champion |
| Code Category | Minimum Reviewer Seniority |
| Code that manages regulated data (PHI, PCI) | Senior engineer, Security team member, and
Compliance |
| Infrastructure-as-code and CI/CD configuration with production reach | Senior engineer and a Platform or Infrastructure team member |
| MCP servers, agent skills, and code that runs in autonomous-agent contexts | Senior engineer and a Security team member |
| Safety-critical code (code affecting Ambi robot operation, motion control, or human-robot interaction) | Staff-level engineer with domain expertise, a second human reviewer with relevant expertise, and adherence to Ambi safety review process |
Engineering managers shall map these tiers to their team’s title structure and shall codify them in CODEOWNERS, branch-protection rules, or equivalent enforcement mechanisms where practical.
4.7.4 Self-Approval Prohibited. The reviewer must be a different person from the engineer who produced the code, irrespective of whether AI was involved. Self-approval is not permitted.
4.7.5 Review Standards. At minimum, the reviewer shall verify that the code performs as the author claims, verified by a passing test, manual trace, or both; does not perform actions the author did not claim, including unexpected file reads, network calls, package installations, or other side effects; any dependencies introduced went through Ambi’s dependency-adoption process; no secrets, credentials, or PII are embedded in code, comments, or test fixtures; and the code conforms to Ambi’s secure coding standards as set out in the Software Development Lifecycle Policy. Security-relevant code shall receive a security review separate from and in addition to the functional review.
4.7.6 Reviewer Accountability. The reviewer carries the same accountability for security and correctness as the original author. The fact that AI generated the code is not a defense against responsibility for a vulnerability, a license-incompatible dependency, a confabulated package, or other defect in code the reviewer approved.
4.7.7 AI Does Not Approve AI. Where approvals are required under this policy, another AI may not approve AI-Generated Code. Automated test results, static analysis, and AI-generated review summaries are inputs to the reviewer’s decision, not substitutes for it.
4.7.8 Reviewer Identification of Record. The pull request, signed-off review document, or equivalent shall identify the reviewer by name and shall record the reviewer’s approval. Where the engineering organization uses pull requests on a code-hosting platform, the platform’s review record is sufficient.
4.8 Customer-Facing AI
Where Ambi deploys AI that interacts with customers — including chatbots, automated support tools, AI-generated marketing content, and AI-assisted product features — the following requirements apply.
4.8.1 Disclosure. AI use shall be disclosed to customers where applicable law requires disclosure or where a reasonable customer would expect to be informed.
4.8.2 Commitments and Representations. AI outputs that constitute commitments, legal claims, or representations on behalf of Ambi shall be subject to competent human review before reaching the customer, consistent with Section 4.5.
4.8.3 Voice and Likeness Imitation. AI shall not be used to imitate a specific individual’s voice or likeness (whether of an employee, customer, or third party) without that individual’s documented consent.
4.8.4 Customer Data. Customer data input to AI-powered Ambi features remains subject to Ambi privacy notice, applicable data-processing agreements, customer contracts, and the Data Classification Policy. Customer data subject to a contractual restriction on third-party processing is Restricted Data under Section 3; other customer data is Confidential Data. The classification, and the controls that apply, must be confirmed for each AI feature on a per-customer basis where customer terms differ.
4.8.5 Pre-Launch Review. Product teams shall obtain Information Security and Legal Counsel review of any customer-facing AI feature prior to launch.
4.9 Service Providers and Contractors
4.9.1 Flow-Down Required. Every Ambi agreement with a Service Provider within the scope of this policy shall be subject to this policy. Without limitation, contractors and vendors are required:
- To represent that the Service Provider uses only AI tools approved under the Service Provider’s own AI policy, or, where the Service Provider has no such policy, tools that meet equivalent standards to those required by this policy;
- To prohibit inputting Ambi Confidential Data or Restricted Data into AI tools on terms materially consistent with the restrictions on Personnel under this policy;
- To ensure that AI-Generated Code and other AI-assisted deliverables meet the review and seniority requirements of Section 4.7;
- To disclose, on Ambi request, the AI tools the Service Provider used in performing the services and the categories of Ambi data processed by those tools; a flow-down obligation requiring the Service Provider to impose equivalent requirements on its sub-contractors;
- To implement an incident-notification obligation for AI-related security events affecting Ambi data, on the timeline required by Section 4.11; and
- To permit Ambi to conduct, and to cooperate with, such audits as Ambi reasonably deems necessary to verify compliance from time to time.
4.9.2 Existing Agreements. Existing agreements without these provisions shall be remediated at the next renewal or amendment. Where Procurement and Legal Counsel determine that remediation is impractical for short-term engagements, a written acknowledgment from the Service Provider of the substance of these requirements may substitute.
4.9.3 Training of Service Provider Personnel. Service Provider personnel with access to Ambi systems shall complete the AI training Personnel are required to take under Section 6, or the Service Provider’s equivalent training as approved in writing by Ambi.
4.9.4 Non-Compliance. Service Provider non-compliance with the AI provisions of its engagement contract is grounds for suspending Service Provider access to Ambi systems and data and, depending on severity, terminating the engagement. Procurement and Legal Counsel shall maintain the triage and sanctions process for AI-related Service Provider compliance concerns.
4.10 Security Controls
4.10.1 Personnel Compliance with Controls. Personnel shall comply with the security controls Ambi implements to manage AI-related risk, including without limitation:
- endpoint controls governing AI tool installation and configuration (managed-settings files, browser extension allowlists, Office add-in deployments, MCP server allowlists, IDE plugin controls);
- data-loss-prevention controls that may inspect or block transmission of sensitive data to AI tools;
- logging and monitoring of AI tool usage where implemented; and
- network controls restricting egress to approved AI endpoints.
4.10.2 No Bypass. Personnel shall not attempt to bypass, disable, circumvent, or work around the controls in Section 4.10.1.
4.10.3 Account and Credential Hygiene. Personnel shall:
- Not share AI tool accounts; each user shall receive their own seat through the standard provisioning process;
- Use SSO and multi-factor authentication wherever supported, and shall use SSO where SSO is available on an Authorized AI Tool;
- Not paste credentials, API keys, tokens, customer secrets, or other secret material into prompts;
- Treat any inadvertently pasted secret as compromised, rotated immediately, and reported under Section 4.11; and
- Treat any input submitted to an AI tool as potentially persistent.
4.11 Incident Reporting
4.11.1 Reportable Events. Personnel shall report the following to Information Security promptly, and in any event no later than twenty-four (24) hours after discovery:
- input of Confidential Data or Restricted Data into an AI tool not approved for that data classification;
- input of credentials, secrets, keys, or tokens into any AI tool;
- suspected Prompt Injection — an AI tool appearing to follow instructions from content it processed (a web page, file, email, calendar entry, repository, or similar) rather than from the user;
- suspected compromise of an AI tool account or AI tool credentials;
- suspected supply-chain compromise of an AI tool, AI agent, MCP server, IDE extension, or AI-related dependency;
- AI output that has caused, or that on reflection may have contributed to, a harmful decision under Section 4.5; and
- any other AI-related event that a reasonable person would suspect involves security risk to Ambi.
4.11.2 Good-Faith Reporting. Personnel are required to report in good faith. Ambi shall not sanction accurate, timely reports of inadvertent incidents. The sanctions provided in Section 5 apply to non-compliance with this policy and not to honest reports of mistakes.
4.11.3 Incident Response Procedure. Ambi Incident Response Policy governs subsequent investigation, containment, notification, and remediation, including any required customer or regulatory notifications.
5. Sanctions
5.1 General. Non-compliance with this policy is grounds for disciplinary action up to and including termination of employment or engagement, and may give rise to civil or criminal liability where applicable. Severity shall reflect the nature, intent, and impact of the violation.
5.2 Inadvertent Violations. Inadvertent first-time violations of this policy without significant impact shall be addressed primarily through coaching and additional training.
5.3 Intentional, Repeated, or Impactful Violations. Intentional violations, repeated violations, and violations causing significant impact (including data exposure, regulatory consequence, customer harm, or reputational damage) shall be addressed through formal disciplinary processes. Violations that constitute breaches of contract or applicable law shall be subject to all available legal remedies.
5.4 Service Providers and Contractors. Sanctions applicable to Service Providers and contractors are governed by the applicable contract and may include suspension of access, contract termination, and indemnification claims.
6. Training
6.1 Required Training. Personnel shall complete AI training: on hire or engagement, before using AI tools for Ambi business; annually thereafter; and whenever this policy or its operational guidance is materially revised.
6.2 Training Content. Training shall cover the data classification rules (Sections 3 and 4.2), the data minimization and named-approval requirements (Sections 4.3 and 4.4), the automated-decisions rules (Section 4.5), the intellectual property rules (Section 4.6), and the incident-reporting expectations (Section 4.11).
6.3 Role-Specific Training.
- Engineers and others producing AI-Generated Code shall additionally complete training on Section 4.7.
- Personnel engaged in customer-facing work using AI shall additionally complete training on Section 4.8.
- Personnel making decisions covered by Section 4.5 shall additionally complete role-specific training on automated decisions.
6.4 Tracked Completion. Training completion is tracked in Ambi learning management or HR system, tied to the version of this policy and the operational guidance at issue, and is a condition of continued use of AI tools for Ambi business.
7. Records
Ambi intends to maintain records sufficient to demonstrate compliance with this policy, including: the Authorized AI Tool List and the approval evidence for each entry; AI training completion records; AI-related security incidents reported and their disposition; pre-launch reviews and post-launch monitoring of customer-facing AI features; documentation of decisions to which Section 4.5 applies; code review records for AI-Generated Code; named approvals issued under Section 4.4; contractual AI provisions and compliance correspondence for Service Provider engagements; and acknowledgment records under Section 8.
Retention shall follow Ambi Records Retention Policy where it addresses AI records, and shall be no less than three (3) years when the Records Retention Policy does not specify a longer period. Information Security, Legal Counsel, and Internal Audit (where applicable) may inspect these records.
8. Compliance and Acknowledgment
8.1 Compliance Measurement. Information Security, in coordination with Legal Counsel, Procurement, and Internal Audit as applicable, shall verify compliance with this policy through methods including: review of the Authorized AI Tool List against active usage; review of SSO, DLP, and audit-log evidence; periodic walk-throughs and spot checks; review of Service Provider contracts for compliance with Section 4.9; review of named approvals issued under Section 4.4; and review of acknowledgment and training records.
8.2 Acknowledgment. Each person within scope of this policy shall acknowledge receipt and acceptance of this policy in writing or through Ambi’s designated electronic system at onboarding, before being granted access to any AI tool for Ambi business; on material revision of this policy; and annually thereafter. Acknowledgments shall be recorded in Ambi learning management or HR system, tied to the specific version acknowledged, and retained for audit and diligence purposes.
8.3 Exceptions. Exceptions to this policy must be requested in writing, justified by business need, approved in advance by Information Security, and recorded with an expiration date. Exceptions involving Restricted Data, customer data, or Service Providers additionally require Legal Counsel approval. Section 4.4 named approvals are exceptions for the purpose of this section.
9. Responsibilities
9.1 All Personnel shall comply with this policy, complete required training and acknowledgment, report AI-related security incidents, and use only Authorized AI Tools for approved data classifications and use cases.
9.2 Engineering Managers and Tech Leads shall enforce the AI-Generated Code review requirements of Section 4.7, including reviewer seniority and self-approval restrictions; shall ensure their teams complete role-specific training; and shall sanction engineers who route around the review process.
9.3 Information Security shall maintain this policy, the Authorized AI Tool List, and the approval process; shall operate the security controls described in Section 4.10; shall investigate and triage AI-related incidents; and shall deliver and track training.
9.4 Legal Counsel shall advise on intellectual property, contractual, and regulatory questions arising under this policy; shall review AI tools for IP and contract considerations; shall maintain the contractual AI provisions required of Service Providers; shall review customer-facing AI deployments under Section 4.8; and shall advise on automated decision-making obligations under Section 4.5.
9.5 People / HR shall apply Section 4.5 to hiring and performance decisions; shall coordinate with Legal Counsel on automated-decision questions affecting Personnel; and shall administer disciplinary processes under Section 5.
9.6 Procurement and Vendor Management shall ensure the contractual AI provisions required by Section 4.9 are in place in Service Provider engagements, both at initial engagement and at renewal; shall coordinate with Legal Counsel on contract remediation; and shall maintain the Service Provider AI-compliance process.
9.7 Internal Audit (where applicable) shall test compliance with this policy periodically and shall report findings to management.
10. Review, Revision, and Approval
10.1 Review. This policy shall be reviewed by the Document Owner, in consultation with Legal Counsel, no less frequently than every twelve (12) months. Out-of-cycle review shall be triggered by significant changes in the AI market, in applicable law, or by material incidents under Section 4.11.
10.2 Major and Minor Revisions. Major revisions alter the strategic intent of this policy or impose additional controls. Major revisions require the approval set out in Section 10.3 and carry a major version number (e.g., 3.0, 4.0). Minor revisions are clarifications or limited additions that do not alter strategic intent; the Document Owner may enter minor revisions directly under a minor version number (e.g., 2.1, 2.2).
10.3 Approval. Major revisions require approval from the CTO and the acting CISO.
10.4 Re-Acknowledgment. Material revisions trigger a fresh acknowledgment requirement under Section 8.2.
11. Contacts
| Topic | Contact |
| Whether a tool is approved; tool addition requests | Information Security |
| Named approvals under Section 4.4 | Information Security and Legal Counsel |
| Suspected incident under Section 4.11 | Information Security (standard incident channel) |
| Topic | Contact |
| Intellectual property, contract, or regulatory questions | Legal Counsel |
| Customer-data handling questions | Legal Counsel and Customer Success leadership |
| Hiring and performance-decision use cases | People team and Legal Counsel |
| Service Provider flow-down and remediation | People team and Legal Counsel |
| Customer-facing AI features (pre-launch) | Information Security and Legal Counsel |
| External disclosure of AI use (customer, marketing, IR) | Legal Counsel and the relevant communications owner |