Unique AI Policy — Unique AI Documentation
Unique AI Policy
15 min read
Purpose
At Unique, we believe that artificial intelligence (AI) can be a force for positive change in the world, and we are committed to realizing this potential in a responsible and ethical manner. By adhering to the principles and values established in this policy, we build and maintain trust and confidence in our AI solutions and contribute to a better future for all.
Legal Disclaimer
This AI policy is based on the information and data provided by Unique and the recommendations of trail GmbH, which are largely based on the regulatory frameworks applicable in the EU, the international standard for IT / AI management systems (ISO/IEC 42001:2023) and other industry best practices.
We aim to review this policy regularly (at least once a year) and update it as necessary to adapt it to current regulatory requirements (this includes changes in legislation, but also developments in case law and official, regulatory practice), new standardizations and evolving best practices as well as changing business processes.
General Provisions
Purpose and Goal of the AI Policy
This AI policy defines how AI systems are procured, used, adapted, offered, and sold within Unique. The term AI includes traditional machine learning models, as well as generative AI technologies. The policy provides developers, users, and third parties, such as vendors, consultants, permanent external employees, or other relevant third parties, with guidance on the correct use and sale of AI systems. It also outlines the acceptable use cases of AI within Unique, aligns AI usage and principles with the organizational values and reputation, ensures compliance with applicable laws for AI usage and development, protects confidential data and IP, governs responsible development of AI, fosters responsible and safe AI usage, and promotes AI literacy in the organization. Further, since Unique is operating in the Financial Services Industry (FSI), the goals of developing responsible AI and deploying safe, reliable, and compliant use cases are of utmost importance for the technology to scale and to drive adoption.
The use of AI is governed by the applicable legislation, in particular, the EU AI Act, the EU General Data Protection Regulation (GDPR) and relevant sector and location-specific regulations.
Scope of the AI Policy
This policy is binding for employees, management executives (called performance board at Unique), board of directors (Verwaltungsrat), permanent external consultants or employees, vendors, and other relevant third parties of Unique. It also applies to companies affiliated with Unique.
Coming Into Force
This policy came into force after the resolution was approved by the Executive Board (Performance Board) on 25 November 2024 and is valid upon publication.
Contact
The Chief Data Officer (CDO) of Unique (aigovernance@unique.ai) is the central point of contact for all questions and concerns regarding this AI policy.
Definition of AI
AI refers to the capability of machines or computer systems to perform tasks that typically require human intelligence. Generative AI (GenAI) enables the creation of new content, while descriptive AI is used to analyze and interpret existing data. Agentic AI refers to systems and models that can autonomously pursue objectives without continuous human oversight.
This policy generally adheres to the EU AI Act's definition of AI, as outlined in Article 3: An 'AI system' is a machine-based system designed to operate with varying levels of autonomy and may exhibit adaptiveness after deployment. It infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments, for explicit or implicit objectives. AI systems can function based on explicit goals (clearly defined) or implicit goals (derived from data). The underlying technology may involve machine learning or logic- and knowledge-based approaches, extending beyond simple data processing to enable learning, reasoning, and modeling. AI systems are characterized by varying degrees of autonomy, allowing them to operate independently of human involvement to some extent. Systems that rely solely on rules set by humans for automatic action execution do not meet the criteria for an AI system.
Organization
Unique uses and offers AI systems in line with its AI strategy: the AI strategy centers on leveraging advanced AI technologies, notably GPT language models, to boost productivity, streamline operations, and enhance client interactions by automating data management and generating insights in various languages. It emphasizes skilling and building of an AI-enabled workforce to transition from traditional financial service providers towards AI-assisted operations. This is encapsulated by our Unique AI platform solution, which underscores innovation, responsibility, and security. It is important to note that Unique is not hosting or training any GenAI models at the moment. Unique works with 3rd party suppliers like Microsoft which are providing GenAI models or clients bring their own GenAI models. Additionally, Unique's robust AI governance framework ensures responsible AI deployment in line with established ethics and regulatory standards, supporting the highest level of compliance and IT security.
In summary: it is part of the core business of Unique to deliver AI use cases to the financial service industry.
The use, procurement, and sale of AI systems follow the values of diversity, equity and inclusion, customer-centricity, integrity, human-centricity, and sustainability, and are aligned with the core values of Unique:
- WE THINK BIG AND NEVER STOP CHALLENGING STATUS QUO
- WE ARE A TEAM OF ENTREPRENEURS
- WE RESPECT AND VALUE EVERYBODY’S UNIQUENESS
- WE FOSTER SUSTAINABLE BUSINESS THROUGH INTEGRITY AND LOYALTY
- WE STRIVE TO IMPROVE QUALITY OF LIFE ON OUR PLANET
This AI policy and any internal AI governance processes are intended to support the development of compliant and secure use cases as well as control risks that may be associated with the use and scale of AI systems in accordance with legal requirements. Unique focuses primarily on AI use cases that have low and limited-risk use cases, but some experimental medium-risk use cases. Should AI systems with a higher risk profile be relevant in the future, they will be reviewed and tested and will undergo a detailed analysis by the relevant departments.
Roles and Responsibilities
Unique is a GenAI-first company and hence everybody is responsible and accountable for identifying and introducing new, innovative AI applications throughout the company, supervising the AI systems during the period of use and making relevant adjustments to AI systems, as well as developing new AI products.
At Unique, the responsibilities for identifying, introducing, supervising, and developing AI applications are distributed across several departments:
- AI Governance Committee: Responsible for overseeing AI governance, ensuring ethical and responsible AI development and deployment, and promoting transparency and accountability in AI systems.
- Chief Data Officer (CDO): Plays a key role in the conformity assessment of AI systems, ensuring compliance with regulations and transparency obligations.
- Chief Information Security Officer (CISO): Involved in the conformity assessment and responsible for the security and compliance of AI systems incl. Cybersecurity, LLM security.
- Product Development Team: Responsible for the development of new AI products, integrating security into the software development lifecycle, and ensuring the AI systems are secure and reliable (in close collaboration with CISO).
- Data Science Team: Evaluates the technical feasibility of AI workflows and identifies potential for optimization and automation. Prompt engineering and identification of malicious prompting practices.
- Operational Security Manager: Supports the CISO by focusing on security architecture, product security, and compliance, ensuring the AI systems are secure during their period of use.
These departments collectively ensure that AI applications at Unique are innovative, secure, and compliant with relevant regulations.
In their respective area of expertise, Dr. Sina Wulfmeyer (CDO), Michael Dreher (CISO) and Dr. Pascal Hauri (Head of AI) are responsible and accountable for developing the AI Governance Framework for Unique and its clients, including the development of technical controls for AI Governance (e.g. Unique benchmarking feature, hallucination check, compliance check, etc.).
Michael Dreher (CISO), Andi Vögeli (CFO), Dr. Andreas Hauri (CTO) and Dr. Pascal Hauri (Head of AI) are responsible for approving AI systems and Manuel Grenacher (CEO) and Dr. Andreas Hauri (CTO) are responsible for procuring AI systems.
Guiding Principles
Our AI Policy is anchored by five foundational pillars: Trust, Safety & Security, Accountability, Liability & Responsibility, Reliability & Robustness, and Explainability & Transparency. These pillars serve as the core principles that guide the development, deployment, and governance of AI systems. Supporting principles include Privacy, Economical Deployment, Sustainability, Fairness & Non-Discrimination, Beneficence & Non-maleficence, Diversity, Inclusion & Accessibility, and Truthfulness. While the pillars provide the structural foundation, the supporting principles enrich the framework by addressing broader ethical and societal dimensions.
- Trust: Trust is critical to upholding the other principles of our AI policy. It ensures not only the adoption and responsible use of AI technology by our customers but also fosters confidence within our organization. Building trust requires transparency, accountability for outcomes, and commitment to ethical practices.
- Safety & Security: AI systems should include safety mechanisms throughout their lifecycle, capable of preventing misuse and mitigating unwanted harms.
- Accountability, Liability & Responsibility: AI systems must be subject to human oversight and monitored by individuals with relevant and sufficient expertise to ensure compliance. AI actors must be held accountable for AI systems and their functioning.
- Reliability & Robustness: AI systems must operate reliably and function appropriately even under adverse conditions.
- Explainability & Transparency: The use of AI systems must be transparent, ensuring users are aware of their interactions and proper usage.
Supporting Principles
- Privacy: AI systems must uphold privacy throughout their lifecycle, adhering to data protection laws and policies.
- Economical Deployment: AI systems should be designed and deployed economically to optimize work processes and exploit new growth opportunities.
- Sustainability: The use and development of AI systems should be both socially and environmentally sustainable.
- Fairness & Non-Discrimination: AI systems must treat all individuals equitably and avoid bias and discrimination.
- Beneficence & Non-maleficence: AI systems should always enforce human welfare and well-being.
- Diversity, Inclusion & Accessibility: AI actors should promote diversity and inclusion, ensuring accessibility of AI technologies.
- Truthfulness: AI systems should provide truthful information without deceiving users or stakeholders.
AI Systems
Permitted, used, and bought AI systems shall be tracked and updated in Unique’s internal AI registry. This registry provides relevant information, including intended use and purpose, risk class, and the responsible internal person of or for the AI system.
The use of AI systems with unacceptable risk (e.g., emotion recognition at the workplace) is prohibited. A legal opinion on the risk level and appropriate mitigation actions for Unique use cases deployed towards clients is provided by leading Swiss lawyer WalderWyss.
AI Governance System
The implementation of an AI governance system ensures the appropriate management and control of AI systems and the effective enforcement of this AI policy. It supports employees in overseeing the procurement, use, adaptation, offer, and sale of AI systems at Unique.
Other Policies and Regulation
Other Organizational Policies
The user or vendor of an AI system is responsible for ensuring compliance with this AI policy and all other existing policies of Unique. Applicable regulations should be taken into account, such as the EU AI Act, GDPR, and relevant local laws.
Obligations and Requirements
AI Management System
Unique has built an AI Management System during the ISO 42001 preparation, which includes:
- AI Governance Framework: Ensures responsible management, testing, and validation of AI systems.
- Risk Management: Maintains an AI Risk Register to identify, document, and mitigate risks systematically.
- Legal Compliance: Aligns with the EU AI Act, GDPR, and bans high-risk AI use cases.
- High-Risk Use Cases: Unique AI follows Responsible AI principles.
- Operational Integration: Ensures integration into existing workflows.
- AI Registry: Tracks all AI systems, including purpose and risk classification.
- Employee Training: Mandatory training ensures awareness of ISO 42001 and responsible AI practices.
- Continuous Improvement: Regular updates of governance frameworks to adapt to new challenges.
Incident Reporting
Cases in which an AI system is not used correctly must be reported. Reporting follows an established Incident Process.
Trainings
The CISO, Compliance, and People & Culture Departments provide training and information for all employees on the content and practical implementation of this AI policy. Mandatory annual training is usually held each November or December.
Other Provisions
Non-Compliance with this Policy
Through various channels, employees are to familiarize themselves with this policy, and it is each person's responsibility to comply with it. The CDO is responsible for handling violations of this AI Policy.
Handling Deviations and Exceptions to this Policy
Deviations or exceptions from this policy need to be documented and approved by management.
Relation to other Unique Policies
The AI policy of Unique is related to several other policies within the organization. These policies collectively ensure that AI systems are developed, deployed, and managed responsibly.