Establish guidelines for the ethical, secure, and responsible use of Artificial Intelligence (AI) and automation tools within GRUPO ELG. This policy aims to protect the organization’s confidential information, prevent data leakage, and ensure compliance with applicable laws and regulations, such as the Brazilian General Data Protection Law. With the growing use of AI in companies, the lack of guidance may expose the organization to significant risks. Therefore, the purpose of this policy is to mitigate those risks by promoting information security, data privacy, and integrity in operations involving AI.
This Policy is mandatory for all individuals who act on behalf of GRUPO ELG or have access to its resources: employees, regardless of hierarchical level or work arrangement, including CLT employees, independent contractors, temporary workers, interns, and apprentices; officers and board members; outsourced workers; consultants; auditors; service providers; suppliers; partners; freelancers; and visitors. It also applies to anyone who performs work in the corporate environment, whether on-site or remote, or who, by any means, accesses information, systems, data, devices, networks, applications, repositories, brands, and other assets of GRUPO ELG, using their own equipment, third-party equipment, or equipment provided by the company.
Hallucination – An incorrect or inaccurate response produced by an AI model, presented convincingly as if it were true.
Approved AI Environment – An AI solution approved by Grupo ELG, properly contracted and subject to security requirements such as data segregation, encryption, data loss prevention (DLP), log generation, governance, and access controls. Grupo ELG has a Corporate AI Hub, an internal environment that centralizes the company’s approved prompts, contexts, and workflows, enabling the safe and standardized use of approved tools. The Hub becomes the mandatory path for corporate use of AI.
Robotic Process Automation (RPA) – Technology that automates repetitive tasks robotically by imitating human actions in digital systems. Although it is not cognitive AI, it is included in this policy because it also uses algorithms that execute activities automatically.
Personal Data/Sensitive Personal Data – Information related to an identified or identifiable natural person, as defined in the LGPD. Examples include name, identity documents, contact information, and customer or employee data. Sensitive personal data, such as racial or ethnic origin, religious belief, political opinion, trade union membership or membership in a religious, philosophical, or political organization, data concerning health or sex life, and genetic or biometric data when linked to a natural person, requires enhanced protection.
DPO (Data Protection Officer) or Person in Charge of Personal Data Processing – The person appointed by GRUPO ELG to act as a communication channel between the controller, data subjects, and the Brazilian National Data Protection Authority (ANPD), pursuant to Article 41 of Law No. 13,709/2018 (LGPD).
Third-Party AI Tools – AI platforms or services offered by external companies and generally accessed through the internet (cloud). Examples include online chatbot services, automatic translation, virtual assistants, and machine learning APIs.
Tool Approval – The internal process of evaluating and approving a technology before its corporate use. It includes an analysis to verify security, privacy, legal compliance, and alignment with company policies. Only approved tools may be used with internal information.
Public Information – Content that may be disclosed to anyone, internally or externally, without special handling. Only this type of information may eventually be used in external AI tools, provided it does not identify or compromise GRUPO ELG.
Restricted Information – Internal GRUPO ELG information whose access must be limited to employees and may not be disclosed outside the company without authorization. It is prohibited to enter this information into any external AI tool.
Confidential Information – Information whose access is limited to specific groups and whose disclosure may cause harm to the company. It requires additional protection. It is prohibited to enter this information into any external AI tool.
Secret Information – Critical information with the highest level of protection, whose disclosure may cause irreparable harm. It is prohibited to enter this information into any external AI tool.
Generative AI/LLM (Large Language Model) – A subcategory of AI capable of creating content, such as text, images, code, and other materials, based on provided instructions. Examples include chatbots such as ChatGPT and Gemini, programming copilots, and image generators.
Artificial Intelligence (AI) – An area of technology that develops systems capable of simulating aspects of human intelligence, performing tasks autonomously or assisting in decision-making. In this policy, the term also covers software tools based on machine learning or advanced algorithms that generate analyses, recommendations, or content.
Prompt – An instruction, question, or context provided to an AI model to generate a response or output.
All employees must strictly comply with this policy in their daily activities. This includes respecting the established restrictions, protecting data confidentiality, and seeking guidance when they are unsure whether a specific use of AI is appropriate. Each employee is responsible for any content they enter into AI tools and must therefore act with caution and sound judgment. Employees are expected to participate in training sessions or guidance provided by the company on the use of new technologies and to immediately report to IT any security incident, suspected data leakage, or misuse of AI that they witness.
In the event of a security incident or suspected leakage involving personal data, the Information Security area must notify the Data Protection Officer (DPO), who will assess the need to notify the ANPD and the data subjects, pursuant to Article 48 of the LGPD.
Shadow AI, such as the use of personal ChatGPT or Gemini accounts, or code generators without IT approval, and the addition of malicious software extensions, represent relevant risks. Data leakage often does not occur through a complex intrusion, but through the installation of a “useful” tool by a well-intentioned employee who attaches confidential and sensitive documents containing personal data. These attachments may be inadvertently sent to external servers, compromising information security. This is when speed compromises confidentiality.
In addition to extensions, concern about Shadow AI is growing exponentially. Employees are entering sensitive corporate data, business strategies, and customer lists into unapproved public AI tools to generate quick reports. Platforms that monitor the attack surface already classify this behavior as one of the main risks of data leakage.
With Shadow AI, exposure risks intensify quickly. All employees must pay close attention to their activities.
Team managers must ensure that the members of their teams understand and follow this policy. They are also responsible for guiding and supervising the use of AI in their areas, ensuring that projects or initiatives involving AI or RPA receive approval from IT Management before they begin. In the event of noncompliance by a subordinate, the manager must immediately take the appropriate measures and involve the responsible departments, including IT, Information Security, and, when applicable, the DPO.
Information Technology Management is responsible for approving this policy and keeping it updated according to technological and regulatory developments. IT must conduct the approval process for AI/RPA tools by assessing security, compliance, and impact risks before releasing any new technology for internal use. IT must also implement technical controls to protect the network, such as blocking unauthorized access to external AI services, in addition to providing employees with training on the safe use of these technologies. IT Management, together with Information Security, must coordinate the software approval process and keep the list of tools approved and authorized for internal use updated (Software Approved by Grupo ELG).
Information Security must support IT in the risk assessment and monitoring of AI use within the company, ensuring alignment with security policies and legal obligations, including the LGPD and applicable industry regulations. In the event of a security incident or suspected leakage involving personal data, Information Security must notify the Data Protection Officer (DPO), who is responsible for assessing the need to notify the ANPD and the data subjects within three (3) business days from awareness of the incident, pursuant to Article 48 of the LGPD and the Security Incident Communication Regulation (Resolution CD/ANPD No. 15/2024).
Human Resources is responsible for applying appropriate disciplinary measures in cases of violation of this policy. HR is also responsible for keeping the Code of Conduct and employment contracts updated, together with the Legal department, so that they reflect, whenever necessary, restrictions related to the use of Artificial Intelligence. HR must also ensure that, when violations occur, the disciplinary measures provided in the Code of Conduct are applied. Grupo ELG has planned an employee awareness program to prepare employees for the context involving Information Security.
Employees must follow the guidelines below when using AI or RPA tools in GRUPO ELG activities. These guidelines include both permitted and prohibited practices, with the purpose of clarifying what may and may not be done.
Use of Approved Tools: Use only AI tools and RPA solutions explicitly approved by GRUPO ELG for corporate purposes. Any new AI tool must undergo evaluation and approval before being used with company data. The use of any other Artificial Intelligence tools that are not among the solutions mentioned and duly approved by this policy is expressly prohibited.
AI tools currently approved for corporate use:
Read.AI:
Productivity Improvement (Non-Sensitive Data): AI may be used to improve productivity in tasks that do not involve confidential data, such as obtaining summaries of public documents, translating non-confidential texts, generating generic drafts, or automating routine tasks. Always verify that the information used is public or unrestricted before entering it into any AI tool.
Continuous Human Supervision: Maintain human oversight of any results or decisions provided by AI. Employees must review and validate AI-generated content before using it in official documents, external communications, or important decision-making. AI must be viewed as a support tool, not as the final authority.
Data Protection and Ethics: When using AI solutions, ensure data privacy is protected and ethical principles are observed. For example, anonymize personal data whenever possible and ensure that the tool complies with the LGPD when processing any personal data. Also avoid bias or discrimination: if AI is used in processes such as selection or evaluation, follow ethical guidelines to prevent unfair or discriminatory results. In addition, GRUPO ELG emphasizes that the use of Artificial Intelligence tools must always preserve transparency and process integrity, avoiding any action that may compromise the ethical principles and guidelines established by the company.
Responsible Use of RPA: RPA scripts and bots must be configured so that they do not expose sensitive information and so that they respect system access controls. The development of automations must involve the IT area to ensure that automated routines comply with security policies, such as secure storage of credentials and access limitations to only the data necessary.
Sharing Internal Information with External AI: It is strictly prohibited to share any information classified as “Restricted,” “Confidential,” or “Secret” under GRUPO ELG’s Information Security Policy with external AI tools. Only information explicitly classified as “Public” may be used in such tools, and even then with caution. This includes copying and pasting text from internal documents, proprietary source code, customer data, financial reports, or any sensitive content into public AI chats or services. Data sent to AI platforms may be stored on external servers outside the company’s control and potentially disclosed to other users, exposing the company to leaks and loss of confidentiality.
Unapproved Tools/Free Versions: Do not use AI or automation software without prior approval. Tools downloaded on one’s own initiative or unapproved free online services, such as an employee’s personal account in AI services, must not be used to process company data. If there is a need to use a specific AI/RPA tool at work, the employee must request an IT evaluation. Use may only occur after formal approval.
Use on Corporate Devices: Accessing or using generative AI platforms on corporate equipment or on GRUPO ELG’s internal network without authorization is prohibited. The company may implement technical blocks for unauthorized services. Even on personal devices, employees must not send any company information or personal data related to the business to these platforms. In other words, do not bypass this policy by using personal devices to enter corporate data into AI. The duty of confidentiality applies through any means.
Automated Decisions without Review: Do not fully delegate decisions that impact the business or third parties, such as customers or employees, to AI systems without human review. For example, transactions should not be approved, external content should not be published, and hiring or termination decisions should not be made based exclusively on the result of algorithms or AI without validation. Final responsibility is always human. AI must not be used as a justification for actions taken without evaluation.
Violation of Intellectual Property or Compliance: It is expressly prohibited to use AI tools in a way that violates laws, third-party rights, or internal rules. Employees must not enter materials protected by copyright, trademarks, trade secrets, or any other third-party intellectual assets into AI tools, unless there is authorization or a valid license allowing such use. Similarly, the use of improperly reproduced excerpts is prohibited. AI must also not be used for any unlawful, immoral, or noncompliant purpose or in a manner contrary to GRUPO ELG’s Code of Conduct. If the AI tool provides content that violates internal policies, compliance rules, or laws, such as personal data of third parties without consent, discriminatory content, or confidential information from another company, the employee must not use it and must immediately report the matter to the IT department.
Exposure of Credentials and Secrets: Never provide corporate credentials, such as company usernames or passwords, API keys, or access tokens, in AI prompts or insecure RPA flows. Likewise, do not share trade secrets or confidential strategies expecting to obtain advice from AI. In addition to the risk of leakage, AI responses in these areas may be incorrect or biased.
Misleading Manipulation or Generation of Content: It is expressly prohibited to use Artificial Intelligence systems to generate, alter, or manipulate any type of content, including text, images, audio, video, documents, or data, in a way that may mislead third parties, distort facts, simulate official communications, or affect the reputation of the company, customers, partners, or employees.
Noncompliance with this policy will be treated with the highest level of seriousness. Any violation of the guidelines established herein constitutes a disciplinary offense. With respect to employees, subject to gradation and proportionality, it may result in a warning, suspension, or dismissal for cause, pursuant to Article 482 of the Brazilian Consolidation of Labor Laws (CLT) and the Code of Conduct. With respect to service providers, contracted legal entities, independent contractors, and other third parties, the consequences will be contractual in nature, including termination and liability for losses and damages, as provided in the respective instrument.
In addition, GRUPO ELG reserves the right to adopt additional judicial or administrative measures in cases where the improper use of Artificial Intelligence tools compromises the company’s information security, ensuring the party involved the right to adversarial proceedings and a full defense.
All employees must know and fully comply with this Artificial Intelligence Use Policy. The company may conduct periodic audits and checks to ensure compliance with its guidelines. Protecting GRUPO ELG’s information is a shared responsibility. The ethical and secure use of Artificial Intelligence is an essential part of this collective commitment to organizational security and integrity.
Any and all content, material, data, document, report, or creation produced with the support of AI tools in the context of professional activities or in the corporate environment will be considered the exclusive property of GRUPO ELG, regardless of whether it was created entirely or partially by employees. The employee assigns to GRUPO ELG, irrevocably and without additional cost, all economic rights over creations eligible for protection, preserving the moral rights that the law deems inalienable. The parties acknowledge that content generated exclusively by AI, without relevant creative human intervention, may not be protected by copyright under Article 11 of Law No. 9,610/1998. In such cases, GRUPO ELG holds custody and economic exploitation rights over the material as a business asset.
This policy extends to all third parties, including service providers, consultants, auditors, suppliers, and business partners, who access GRUPO ELG information, systems, or data, or who process corporate information. Such entities must strictly adhere to the principles established herein, including, but not limited to:
The binding of third parties to this policy depends on an express provision in a contract or specific adhesion term, with confidentiality and data protection clauses. The mere existence of this internal rule is not sufficient for that purpose.
GRUPO ELG reserves the right to monitor and audit the use of Artificial Intelligence tools, including access records, types of queries, and shared information, always in compliance with applicable legislation and with respect for employee privacy. Monitoring is limited to the corporate environment and corporate assets, is based on the employer’s management authority and the controller’s legitimate interest (Article 7, IX, of the LGPD), and must observe data minimization and prior awareness by employees. It does not extend to personal communications.
This Artificial Intelligence Use Policy will be periodically reviewed and updated to ensure alignment with best practices in governance, information security, and legal compliance, taking into account the rapid evolution of technology and the constant changes in rules and guidelines applicable to the use of AI.
GRUPO ELG will maintain an AI Committee, composed of leaders and key users from the areas, with the purpose of receiving and screening suggestions for new AI tools from employees; periodically assessing tools already in use regarding security, cost, results, and compatibility among contracted solutions; and recommending approvals or discontinuations. Because this is a rapidly evolving technology, the Committee meets periodically to keep this policy and the list of approved tools up to date.
The Information Technology Management area must promote the periodic assessment of the content of this policy, or whenever there is a relevant legislative, regulatory, or technological change, and may propose adjustments, additions, or revisions to ensure its effectiveness and continuous updating.
Requesting ideas for generic text – Allowed to enter into AI: Yes. Note: Provided that it does not contain sensitive or internal data.
Researching best practices or market trends – Allowed to enter into AI: Yes. Note: Use only public information.
Generating or reviewing generic texts without names of people or companies – Allowed to enter into AI: Yes. Note: Review and edit the content before using it.
Translating excerpts of generic text – Allowed to enter into AI: Yes. Note: Only if the text does not contain corporate information.
Creating drafts or summarizing public content, such as articles, news, or manuals – Allowed to enter into AI: Yes. Note: Only publicly available content.
Reviewing texts with names of customers, suppliers, or employees – Allowed to enter into AI: No. Note: Risk of personal data leakage.
Sending internal documents, spreadsheets, reports, or policies – Allowed to enter into AI: No. Note: Corporate and confidential data.
Sharing excerpts of proprietary code or scripts – Allowed to enter into AI: No. Note: Potential exposure of intellectual property.
Entering names, emails, domains, or information from internal systems – Allowed to enter into AI: No. Note: Violation of confidentiality.
Requesting analyses of data, screenshots, or information from internal systems – Allowed to enter into AI: No. Note: Risk of exposing restricted information.
Revision: 00
Revision Date: 06/12/2026
Reason for Revision: Initial issue
Prepared by: Marcel Mesquita – IT Manager
Reviewed by: Marcel Mesquita – IT Manager
Approved by: Edgar Gazzolla – Operations Director