Information Security Policy - Artificial Intelligence

Introduction

Gauss Control approves the adoption of an Information Security Management System (ISMS), comprising a set of measures designed to preserve the confidentiality, integrity, and availability of information. Today, information technologies, and particularly the adoption of Artificial Intelligence (AI) and machine learning tools, face an increasing number of threats and ethical challenges. This requires an ongoing effort not only to manage technical risks, but also to ensure that the use of these technologies respects human dignity, fairness, and the ethical values of our organization.

This Information Security Policy (hereinafter, the “Policy”) is the cornerstone governing Gauss Control’s Information Security Framework, which consists of a set of documents at different levels establishing the requirements, guidelines, and protocols to be followed in matters of security. The Security Document (hereinafter, the “SD”) shall be developed through a set of supporting documents, including usage rules, regulatory standards, procedures, manuals, guidelines, best practices, and other relevant materials, so as to cover all aspects addressed by the Policy down to the operational process level. Today, information technologies face an increasing number of threats, requiring continuous efforts to adapt and manage the risks arising from them.

1.1. Objective

The primary objective of this high-level Policy is to define the principles and basic rules governing information security management. Its ultimate purpose is to ensure that Gauss Control safeguards the security, integrity, confidentiality, and availability of information while minimizing non-financial risks arising from impacts caused by ineffective information security management.

1.2. Scope

This Policy shall comply with these minimum requirements, without prejudice to the adoption of more restrictive policies and the implementation of enhanced security measures wherever possible. Gauss Control shall adapt and further develop this Policy and shall report on its implementation and compliance. The scope of this Policy covers all information relating to Gauss Control’s processes, services, and products, regardless of how such information is processed, who accesses it, the medium in which it is contained, or where it is located, whether in printed form or stored electronically. This Policy shall apply to:

  • Gauss Control employees, suppliers of goods or services, and, in general, all persons or entities with whom Gauss Control establishes, directly or indirectly, any contractual or cooperative relationship.
  • Information assets that store, manage, and/or transmit data.

The Policy shall be made available on the corporate website, www.gausscontrol.com, and in a shared SD repository so that it is accessible to all personnel within the company.

1.3. Adaptation and Development of the Information Security Policy

The Policy shall be continuously adapted and developed within the company. The manner in which the Policy is adapted to operational activities shall be defined through specific SD documentation, which must at all times remain aligned with the guidelines set forth in this document.

This Policy is based on the Information Security best practices set forth in the International Standard ISO/IEC 27001, as well as on compliance with applicable personal data protection legislation and any regulations relating to Information Security that may affect Gauss Control. In addition, the following basic principles are established as fundamental Information Security guidelines that must always be taken into account in any activity involving the processing of information:

  • Strategic Scope: Information Security shall have the commitment and support of all levels of Gauss Control’s management, enabling it to be coordinated and integrated with the organization’s other strategic initiatives in order to establish a fully consistent and effective framework. As Information Security is the responsibility of all Gauss Control personnel, this Policy must be known, understood, and followed by all employees.
  • Comprehensive Security: Information Security shall be understood as a comprehensive process comprising technical, human, physical, and organizational elements, avoiding isolated or temporary measures except in cases of urgency or necessity. Information Security shall be considered an integral part of day-to-day operations and shall be incorporated and applied throughout the entire design, development, and maintenance lifecycle of information systems.
  • Risk Management: Gauss Control defines a risk identification and assessment process in order to implement mitigation controls and establish regular procedures for reassessment. Risk analysis and management shall be an essential component of the Information Security process. Risk management shall support the maintenance of a controlled environment by reducing risks to acceptable levels. Such risk reduction shall be achieved through the implementation of security measures that balance the nature of the data and processing activities, the impact and likelihood of the risks to which they are exposed, and the effectiveness and cost of the security measures.
  • Proportionality: The implementation of protection, detection, and recovery measures shall be proportionate to the potential risks and to the criticality and value of the information and services affected.
  • Continuous Improvement: Security measures shall be periodically evaluated and updated to ensure their effectiveness in response to the ongoing evolution of risks and protection systems. Information Security shall be managed, reviewed, and audited by qualified personnel. As part of this continuous improvement cycle, Gauss Control shall maintain defined levels for both acceptable residual risk (risk appetite) and its corresponding risk tolerance thresholds.
  • Ethics and Moral Responsibility in the Use of AI: Security at Gauss Control incorporates an ethical dimension. We are committed to ensuring that the use of algorithms and Artificial Intelligence systems does not perpetuate discriminatory biases, whether racial, gender-based, or social, nor infringe upon individuals’ privacy. Technology must always remain under human supervision (“Human in the Loop”), ensuring that critical decisions are validated by a responsible and competent individual and preventing automation from diminishing moral accountability for our actions.

Gauss Control’s Management is committed to:

  • Promoting Information Security roles and responsibilities throughout the organization.
  • Providing adequate resources to achieve Information Security objectives.
  • Promoting awareness and understanding of the Information Security Policy among Gauss Control employees, including the responsible use of emerging technologies.

  • Promoting a culture of secure innovation, ensuring that Artificial Intelligence is used in accordance with ethical and data protection standards.
  • Require compliance with this Policy, applicable legislation, and regulatory requirements relating to Information Security.
  • Consider Information Security risks in decision-making processes.

Gauss Control, through its senior management and Information Security Committee, is committed to safeguarding all assets under its responsibility while ensuring compliance with all applicable regulations and laws. Gauss Control shall appoint a person responsible for defining, implementing, and monitoring cybersecurity and Information Security measures, as well as for the management, maintenance, and implementation of the ISMS.

The specific responsibilities for each role are described below:

Role

Responsibilities

General Manager

● Review and approve the General Information Security Policy based on a cybersecurity risk assessment, at least once a year.

● Authorize the allocation of resources required for the proper implementation of the Information Security Policy.

Information Security and Data Governance Officer

● Conduct an annual risk assessment, including the risks of algorithmic bias and data poisoning in AI systems, and update the Information Security Policy document based on the results of the assessment.

● Ensure ethical compliance in the use of generative and predictive AI tools.

● Take corrective actions as part of a continuous improvement process.

● Implement a mitigation plan for such risks.

Cybersecurity and Data Governance Committee

Data Owners /Data Stewards

● Manage responses to crisis situations and incidents.

● Act as an ethical advisory body responsible for authorizing the use of new AI tools, assessing their ethical impact before deployment in production environments.

● Conduct response exercises for major contingency scenarios.

● Establish an incident communication policy.

● Oversee the implementation of the Information Security Management System.

● Ensure appropriate training and awareness among personnel.

● Establish an action plan based on the results of internal audits.

5.1 Safe and Ethical Use of Artificial Intelligence

To ensure ethical and technical integrity in the use of AI, Gauss Control establishes the following mandatory guidelines:

5.1.2 Privacy and Training Data

The use of real personal, sensitive, or confidential client data for training public or external AI models is strictly prohibited. Any data used for testing or training must first be processed in accordance with the Data Anonymization Protocol, applying pseudonymization or masking techniques to protect the identity of data subjects.

5.1.3 Generative AI and Confidentiality

Entering information classified as “Confidential Information” (CI) into publicly accessible generative AI tools (e.g., free versions of ChatGPT, Gemini, or Claude) is prohibited, as doing so may result in such data being transferred to or retained by the service provider, potentially constituting an information leakage.

5.1.4 Human Oversight and Non-Discrimination

AI-generated outputs that affect individuals or critical business processes must be reviewed by a human. Automated decisions that lack explainability or exhibit biases inconsistent with the company’s ethical standards shall not be accepted.

5.1.5 Secure AI Development

When developing proprietary solutions, secure development lifecycle controls (Control 8.25) must be applied to ensure that models are protected against manipulation and are designed without inherent security vulnerabilities.

Any exception to this Information Security Policy, or to any other policy arising from the ISMS governed by this Policy, must be documented and reported to Gauss Control’s Information Security Officer. Such exceptions shall be analyzed to assess the risks they may introduce to the organization, including ethical impacts arising from the misuse of AI. Based on the classification of such risks, responsibility for accepting them shall rest with the requesting party.

Cualquier violación de la presente Política de Seguridad de la Información, o a otra que emane desde el SGSI regido por la presente Política, puede resultar en la toma de las acciones disciplinarias correspondientes de acuerdo con el proceso interno de Gauss Control. Es responsabilidad de todos los empleados de Gauss Control notificar al responsable de Seguridad de la Información de la sociedad afectada ante cualquier evento o situación que pudiera suponer el incumplimiento de alguna de las directrices definidas por la presente Política.

Approval of this Policy implies that its implementation shall receive the support of Management in order to achieve all objectives established herein and to comply with all applicable requirements. This Information Security Policy shall be reviewed and approved annually by the Board of Directors. However, if significant changes occur within the organization or material changes are identified in the threat and risk environment, whether operational, legal, regulatory, or contractual in nature, the Policy shall be reviewed whenever deemed necessary to ensure that it remains aligned at all times with Gauss Control’s operational reality.

This Policy shall remain in effect for one year from the date of its most recent approval and shall be periodically reviewed and updated to ensure its continued suitability for the organization’s needs and any changes in applicable laws and regulations.