Responsible AI & Emerging Technologies Policy

Introduction

The ESG Institute Limited ("the Company") uses artificial intelligence (AI) and other emerging technologies across its training, advisory, community-platform and internal operations, including AI-assisted tools such as its Terra chatbot, AI-supported research and content development, and AI features offered through third-party platforms such as Circle.so. This Policy sets out the principles that govern the Company's development, procurement and use of AI so that these technologies are deployed responsibly, transparently and in a manner consistent with human rights, data protection and the Company's Code of Conduct & Ethics.

Scope

This Policy applies to all employees, contractors, consultants and third parties who develop, configure, procure or use AI or automated decision-making tools on the Company's behalf, and to AI features embedded in third-party platforms the Company uses to deliver its services (e.g. community, learning-management and productivity platforms). It covers both Company-built tools and AI features provided by third-party vendors.

Guiding Principles

  1. Human oversight – AI tools support human decision-making and do not replace it in matters materially affecting individuals (e.g. employment, learner assessment outcomes, certification decisions), which remain subject to human review.

  2. Transparency – Learners, members and other stakeholders are informed, where AI is used to generate content, respond to queries or process their data, in a manner consistent with the Company's Privacy Policy.

  3. Fairness and non-discrimination – AI tools are assessed for the risk of bias or discriminatory outcomes before deployment, consistent with the DEI Policy, and are monitored for unintended discriminatory effects.

  4. Data minimisation and privacy – Personal data used in or generated by AI tools is processed in accordance with the Privacy Policy and the Data Protection Act 2018 (Isle of Man). Personal data is not used to train external AI models without an appropriate legal basis and safeguards.

  5. Security – AI tools and the data they process are subject to the same controls set out in the Information Security & Breach Response Policy, including access control, encryption and incident reporting.

  6. Accountability – A designated owner is responsible for each AI tool used by the Company, including for monitoring performance, addressing errors and escalating concerns.

Approval and Procurement of AI Tools

Before adopting a new AI tool or enabling a new AI feature on an existing platform, the responsible manager must confirm: the tool's data-processing practices are compatible with the Privacy Policy; the vendor provides adequate security assurances consistent with the Information Security & Breach Response Policy; and the tool has been assessed for foreseeable risks of bias, error or misuse relevant to its intended use. Cloud-based or third-party AI tools are subject to the same approval process as other cloud services under the Code of Conduct & Ethics.

Use of AI in Content, Advisory and Assessment

Where AI tools are used to assist in producing training content, advisory outputs, marketing materials or research, personnel remain responsible for reviewing outputs for accuracy, fairness and alignment with the Company's mission before publication or delivery to clients or learners. AI-generated content must not be presented as independent human expert opinion where it has not been substantively reviewed by a qualified person. AI tools must not be used to determine final learner assessment results or certification decisions without human review.

Employee and Contractor Responsibilities

Personnel using AI tools on the Company's behalf must: use only Company-approved AI tools for business purposes; avoid inputting confidential, personal or client data into unapproved public AI tools; disclose to their manager where an AI tool has materially shaped a deliverable; and report suspected AI-related errors, bias, or misuse to their manager or the Compliance Officer.

Monitoring and Review

The Executive Leadership Team maintains oversight of the Company's use of AI and emerging technologies, supported by the CISO and DPO for security and data-protection matters respectively. Concerns about the Company's use of AI, including suspected bias, error or misuse, may be raised through the Whistleblowing (Disclosure) Policy or directly with the Compliance Officer.

Review

This policy is to be reviewed every two years, or earlier if there are significant changes in law, technology or our operations.

Latest update: July 2026.

This Policy is non‑contractual and may be amended at the Company's discretion.