Unique AI Policy — Unique AI Documentation

Unique AI Policy

15 min read

Purpose

At Unique, we believe that artificial intelligence (AI) can be a force for positive change in the world, and we are committed to realizing this potential in a responsible and ethical manner. By adhering to the principles and values established in this policy, we build and maintain trust and confidence in our AI solutions and contribute to a better future for all.

Legal Disclaimer

This AI policy is based on the information and data provided by Unique and the recommendations of trail GmbH, which are largely based on the regulatory frameworks applicable in the EU, the international standard for IT / AI management systems (ISO/IEC 42001:2023) and other industry best practices.

We aim to review this policy regularly (at least once a year) and update it as necessary to adapt it to current regulatory requirements (this includes changes in legislation, but also developments in case law and official, regulatory practice), new standardizations and evolving best practices as well as changing business processes.

General Provisions

Purpose and Goal of the AI Policy

This AI policy defines how AI systems are procured, used, adapted, offered, and sold within Unique. The term AI includes traditional machine learning models, as well as generative AI technologies. The policy provides developers, users, and third parties, such as vendors, consultants, permanent external employees, or other relevant third parties, with guidance on the correct use and sale of AI systems. It also outlines the acceptable use cases of AI within Unique, aligns AI usage and principles with the organizational values and reputation, ensures compliance with applicable laws for AI usage and development, protects confidential data and IP, governs responsible development of AI, fosters responsible and safe AI usage, and promotes AI literacy in the organization. Further, since Unique is operating in the Financial Services Industry (FSI), the goals of developing responsible AI and deploying safe, reliable, and compliant use cases are of utmost importance for the technology to scale and to drive adoption.

The use of AI is governed by the applicable legislation, in particular, the EU AI Act, the EU General Data Protection Regulation (GDPR) and relevant sector and location-specific regulations.

Scope of the AI Policy

This policy is binding for employees, management executives (called performance board at Unique), board of directors (Verwaltungsrat), permanent external consultants or employees, vendors, and other relevant third parties of Unique. It also applies to companies affiliated with Unique.

Coming Into Force

This policy came into force after the resolution was approved by the Executive Board (Performance Board) on 25 November 2024 and is valid upon publication.

Contact

The Chief Data Officer (CDO) of Unique (aigovernance@unique.ai) is the central point of contact for all questions and concerns regarding this AI policy.

Definition of AI

AI refers to the capability of machines or computer systems to perform tasks that typically require human intelligence. Generative AI (GenAI) enables the creation of new content, while descriptive AI is used to analyze and interpret existing data. Agentic AI refers to systems and models that can autonomously pursue objectives without continuous human oversight.

This policy generally adheres to the EU AI Act's definition of AI, as outlined in Article 3: An 'AI system' is a machine-based system designed to operate with varying levels of autonomy and may exhibit adaptiveness after deployment. It infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments, for explicit or implicit objectives. AI systems can function based on explicit goals (clearly defined) or implicit goals (derived from data). The underlying technology may involve machine learning or logic- and knowledge-based approaches, extending beyond simple data processing to enable learning, reasoning, and modeling. AI systems are characterized by varying degrees of autonomy, allowing them to operate independently of human involvement to some extent. Systems that rely solely on rules set by humans for automatic action execution do not meet the criteria for an AI system.

Organization

Unique uses and offers AI systems in line with its AI strategy: the AI strategy centers on leveraging advanced AI technologies, notably GPT language models, to boost productivity, streamline operations, and enhance client interactions by automating data management and generating insights in various languages. It emphasizes skilling and building of an AI-enabled workforce to transition from traditional financial service providers towards AI-assisted operations. This is encapsulated by our Unique AI platform solution, which underscores innovation, responsibility, and security. It is important to note that Unique is not hosting or training any GenAI models at the moment. Unique works with 3rd party suppliers like Microsoft which are providing GenAI models or clients bring their own GenAI models. Additionally, Unique's robust AI governance framework ensures responsible AI deployment in line with established ethics and regulatory standards, supporting the highest level of compliance and IT security.

In summary: it is part of the core business of Unique to deliver AI use cases to the financial service industry.

The use, procurement, and sale of AI systems follow the values of diversity, equity and inclusion, customer-centricity, integrity, human-centricity, and sustainability, and are aligned with the core values of Unique:

This AI policy and any internal AI governance processes are intended to support the development of compliant and secure use cases as well as control risks that may be associated with the use and scale of AI systems in accordance with legal requirements. Unique focuses primarily on AI use cases that have low and limited-risk use cases, but some experimental medium-risk use cases. Should AI systems with a higher risk profile be relevant in the future, they will be reviewed and tested and will undergo a detailed analysis by the relevant departments.

Roles and Responsibilities

Unique is a GenAI-first company and hence everybody is responsible and accountable for identifying and introducing new, innovative AI applications throughout the company, supervising the AI systems during the period of use and making relevant adjustments to AI systems, as well as developing new AI products.

At Unique, the responsibilities for identifying, introducing, supervising, and developing AI applications are distributed across several departments:

These departments collectively ensure that AI applications at Unique are innovative, secure, and compliant with relevant regulations.

In their respective area of expertise, Dr. Sina Wulfmeyer (CDO), Michael Dreher (CISO) and Dr. Pascal Hauri (Head of AI) are responsible and accountable for developing the AI Governance Framework for Unique and its clients, including the development of technical controls for AI Governance (e.g. Unique benchmarking feature, hallucination check, compliance check, etc.).

Michael Dreher (CISO), Andi Vögeli (CFO), Dr. Andreas Hauri (CTO) and Dr. Pascal Hauri (Head of AI) are responsible for approving AI systems and Manuel Grenacher (CEO) and Dr. Andreas Hauri (CTO) are responsible for procuring AI systems.

Guiding Principles

Our AI Policy is anchored by five foundational pillars: Trust, Safety & Security, Accountability, Liability & Responsibility, Reliability & Robustness, and Explainability & Transparency. These pillars serve as the core principles that guide the development, deployment, and governance of AI systems. Supporting principles include Privacy, Economical Deployment, Sustainability, Fairness & Non-Discrimination, Beneficence & Non-maleficence, Diversity, Inclusion & Accessibility, and Truthfulness. While the pillars provide the structural foundation, the supporting principles enrich the framework by addressing broader ethical and societal dimensions.

Supporting Principles

AI Systems

Permitted, used, and bought AI systems shall be tracked and updated in Unique’s internal AI registry. This registry provides relevant information, including intended use and purpose, risk class, and the responsible internal person of or for the AI system.

The use of AI systems with unacceptable risk (e.g., emotion recognition at the workplace) is prohibited. A legal opinion on the risk level and appropriate mitigation actions for Unique use cases deployed towards clients is provided by leading Swiss lawyer WalderWyss.

AI Governance System

The implementation of an AI governance system ensures the appropriate management and control of AI systems and the effective enforcement of this AI policy. It supports employees in overseeing the procurement, use, adaptation, offer, and sale of AI systems at Unique.

Other Policies and Regulation

Other Organizational Policies

The user or vendor of an AI system is responsible for ensuring compliance with this AI policy and all other existing policies of Unique. Applicable regulations should be taken into account, such as the EU AI Act, GDPR, and relevant local laws.

Obligations and Requirements

AI Management System

Unique has built an AI Management System during the ISO 42001 preparation, which includes:

  1. AI Governance Framework: Ensures responsible management, testing, and validation of AI systems.
  2. Risk Management: Maintains an AI Risk Register to identify, document, and mitigate risks systematically.
  3. Legal Compliance: Aligns with the EU AI Act, GDPR, and bans high-risk AI use cases.
  4. High-Risk Use Cases: Unique AI follows Responsible AI principles.
  5. Operational Integration: Ensures integration into existing workflows.
  6. AI Registry: Tracks all AI systems, including purpose and risk classification.
  7. Employee Training: Mandatory training ensures awareness of ISO 42001 and responsible AI practices.
  8. Continuous Improvement: Regular updates of governance frameworks to adapt to new challenges.

Incident Reporting

Cases in which an AI system is not used correctly must be reported. Reporting follows an established Incident Process.

Trainings

The CISO, Compliance, and People & Culture Departments provide training and information for all employees on the content and practical implementation of this AI policy. Mandatory annual training is usually held each November or December.

Other Provisions

Non-Compliance with this Policy

Through various channels, employees are to familiarize themselves with this policy, and it is each person's responsibility to comply with it. The CDO is responsible for handling violations of this AI Policy.

Handling Deviations and Exceptions to this Policy

Deviations or exceptions from this policy need to be documented and approved by management.

Relation to other Unique Policies

The AI policy of Unique is related to several other policies within the organization. These policies collectively ensure that AI systems are developed, deployed, and managed responsibly.