INTEA Artificial Intelligence (AI) Policy
Version 1.1 – July 6th, 2026
1. Purpose
This policy sets out how employees of INTEA may use artificial intelligence (AI) tools in their work. Its aim is to enable employees to use AI quickly and confidently in low-risk situations, while ensuring appropriate safeguards are in place for higher-risk uses, such as when handling personal data, customer information, or making decisions that affect individuals.
2. Scope
This policy applies to all employees and contractors who use AI tools for work purposes - from writing assistants and chatbots to image/video generation tools and automation.
Out of scope: basic built-in features that don’t involve learning from data (spell-check, autofill formulas in Excel, standard filters and sorting).
3. Key Terms
- AI tool — any service or model (e.g. ChatGPT, Claude, Gemini, image/video generation tools) that produces text, images, video, code or recommendations based on training on data.
- Approved tool — an AI tool included in the List of Approved Tools (see §7).
- Personal data — any information that can directly or indirectly identify a specific person (name, email, photo, ID number, etc.).
- Confidential / sensitive data — customer data, financial information, trade secrets, employees’ personal data — anything that could harm INTEA or individuals if leaked.
4. General Principles for Using AI
The following principles shall apply to AI use in INTEA:
- Accountability — Every AI tool used at work must have a designated person responsible for its use and the outcomes it produces.
- Verification of outputs — AI can make mistakes or generate inaccurate information (“hallucinations”). All AI-generated outputs must be reviewed by a human before use, particularly if they will be shared with a client.
- Confidentiality — Customer, employee, and other confidential company information must not be entered into unapproved AI tools or personal AI accounts.
- Transparency — Where practical, employees should disclose when AI has made a significant contribution to content provided to a client.
- Human oversight — AI must not be used to make decisions about individuals, such as hiring, performance evaluation, or termination, without meaningful human involvement.
- Legal compliance — All use of AI must comply with applicable legal requirements, including the GDPR and the EU AI Act.
5. Risk Classification
INTEA classifies AI systems in accordance with the risk-based approach set out in the EU Artificial Intelligence Act (EU AI Act). The level of oversight and approval required depends on the applicable risk category. Where employees are unsure how an AI system should be classified, they must consult the AI Owner before using it. This Policy is intended to reflect the risk-based approach of the EU AI Act. Where this Policy is silent on a particular issue, the requirements of applicable law, including the EU AI Act and the GDPR, prevail.
5.1 Minimal Risk — Permitted Use
Examples: Email autocomplete, meeting summaries, drafting text, IT support chatbots, coding assistance, and similar productivity tools.
Requirement: AI systems presenting minimal risk may be used without prior approval, provided they are included in the List of Approved Tools (Section 7) and are used in accordance with this Policy.
5.2 Limited Risk — Transparency Required
Examples: AI systems that interact directly with individuals (such as chatbots) or generate AI-created content where transparency obligations apply under the EU AI Act.
Requirement: Limited-risk AI systems may be used only where the applicable transparency requirements under the EU AI Act and this Policy are met. Where required, users must clearly disclose that content has been generated or materially assisted by AI. Any uncertainty about applicable transparency obligations should be referred to the AI Owner.
5.3 High-Risk AI Systems — Approval Required
Examples: AI systems used in areas such as employment, education, access to essential services, or other applications classified as high-risk under the EU AI Act.
Requirement: High-risk AI systems must not be used unless:
- the proposed use has been reviewed and approved in writing by the INTEA’s Higher Management;
- the Compliance Officer has confirmed that all applicable legal requirements, including those under the EU AI Act and the GDPR, have been addressed;
- appropriate human oversight is maintained throughout the use of the AI system.
6. Prohibited AI Practices
INTEA does not permit the use of AI practices that are prohibited under the EU AI Act. In addition, INTEA prohibits the following uses of AI, whether or not an exception may be available under applicable law:
- Using manipulative or deceptive AI techniques that are likely to materially distort a person’s behaviour and cause or are likely to cause harm.
- Exploiting the vulnerabilities of individuals or groups, including vulnerabilities related to age, disability, or socio-economic circumstances, to influence their behaviour.
- Social scoring of individuals based on their social behaviour or personal characteristics.
- Using AI systems to recognise or infer employees’ emotions in the workplace.
- Creating or expanding facial recognition databases through the untargeted scraping of facial images from the internet, CCTV footage, or other sources.
- Using biometric data to classify individuals or infer sensitive characteristics, such as race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, or other protected characteristics.
7. AI Governance and Approval Process
7.1 AI Owner
INTEA appoints an AI Owner (currently the IT Manager) who is responsible for the governance of AI tools used within INTEA. The AI Owner is responsible for implementing and maintaining this Policy and for overseeing the INTEA’s use of AI in accordance with applicable law, including the GDPR and the EU AI Act. The Compliance Officer may assist the AI Owner in maintaining this Policy and conducting risk assessments where necessary to ensure compliance with applicable national and EU legal requirements.
The AI Owner’s responsibilities include:
- maintaining the List of Approved Tools and the purposes for which each tool may be used;
- assessing requests to introduce new AI tools or new use cases for existing tools, taking into account the level of risk, the nature of the data involved, and applicable legal and security requirements;
- determining the appropriate risk classification of proposed AI systems or use cases under this Policy;
- consulting legal or external advisers where necessary to ensure compliance with applicable legislation;
- reviewing this Policy and the List of Approved Tools at least annually, or earlier where required by changes in law, technology, or INTEA’s operations.
7.2 Approval of New AI Tools
Employees wishing to use an AI tool that is not included in the List of Approved Tools must submit a request to the AI Owner before using the tool for any INTEA-related business. The request should include a brief description of:
- the intended use of the AI tool;
- the types of information or data that will be processed;
- the expected business purpose or benefit.
The AI Owner will assess the request in accordance with this Policy and determine whether the proposed use is permitted, requires additional safeguards, or should be refused.
7.3 Employee Responsibilities
Employees remain responsible for their use of AI tools and for the quality and lawfulness of any work produced with AI assistance.
When using AI tools for INTEA-related business, employees must:
- use AI only for approved business purposes and only through approved AI tools;
- comply with this Policy and any instructions issued by the AI Owner;
- ensure that confidential information and personal data are handled in accordance with the INTEA’s data protection and information security requirements;
- review AI-generated outputs for accuracy, completeness and suitability before relying on or sharing them;
- exercise appropriate professional judgment and not rely solely on AI-generated outputs;
- ensure that decisions affecting individuals are not made solely by AI where human oversight is required;
- promptly report any suspected security incident, data breach, malfunction, or material error involving an AI tool to the AI Owner.
Approval of an AI tool or use case does not transfer responsibility for its use. Employees remain accountable for the decisions they make and the work they produce with the assistance of AI.
9. Data Protection and Confidentiality
The use of AI tools must comply with the INTEA’s data protection, confidentiality, and information security requirements, as well as applicable legislation, including the GDPR and the EU AI Act.
Personal data may be processed using AI tools only where this is necessary for a legitimate business purpose and only through AI tools approved for processing such data.
Where INTEA intends to introduce a new or recurring use of AI involving the processing of personal data, the AI Owner shall assess the associated risks before implementation. Where required by law or where the proposed use presents an elevated risk to the rights and freedoms of individuals, the AI Owner shall ensure that an appropriate data protection assessment is carried out and shall obtain legal advice where necessary.
AI functionality that is disabled by default within existing INTEA systems or cloud services shall not be enabled without the prior approval of the AI Owner, who shall assess any associated legal, security, and operational risks before implementation.
10. AI Literacy and Training
INTEA shall ensure that employees using AI tools possess an appropriate level of AI literacy, taking into account their role, responsibilities, technical knowledge, and the nature of the AI systems they use, in accordance with the EU AI Act.
All employees who use AI tools for INTEA-related business shall receive appropriate training on this Policy and the responsible use of AI. Training shall, as a minimum, cover:
- INTEA’s requirements for the use of AI tools;
- protection of personal data and confidential information;
- verification of AI-generated outputs;
- the limitations and risks of AI, including inaccurate or misleading outputs (“hallucinations”);
- the reporting of incidents, errors, or suspected misuse.
The AI Owner shall determine whether additional or role-specific training is required for employees whose duties involve higher-risk AI use, administration of AI systems, or the processing of sensitive or personal data.
Training shall be provided to new employees as part of their onboarding and refreshed periodically to reflect changes in technology, legislation, or the INTEA’s use of AI.
11. Incident Reporting and Response
Employees must promptly report any actual or suspected incident involving the use of AI tools to the AI Owner or, where appropriate, to their direct manager.
Reportable incidents include, but are not limited to:
- unauthorised disclosure of personal data or confidential information through an AI tool;
- use of an AI tool that has not been approved in accordance with this Policy;
- AI-generated outputs that are materially inaccurate, misleading, discriminatory, or otherwise inappropriate and may adversely affect INTEA or third parties;
- suspected security vulnerabilities, unauthorised access, or malfunction of an AI tool;
- any suspected breach of this Policy, the GDPR, the EU AI Act, or other applicable legal or regulatory requirements.
Upon receiving a report, the AI Owner shall assess the incident, determine the level of risk, and take appropriate action to mitigate any adverse impact. Where necessary, the AI Owner shall consult the Compliance Officer, INTEA’s higher management, external legal advisers, or other appropriate specialists.
Where an incident involves the processing of personal data, INTEA shall assess whether any obligations arise under the GDPR, including notification to the competent supervisory authority or affected individuals.
The AI Owner shall maintain a record of reported AI-related incidents and the actions taken in response. Records shall be retained for an appropriate period in accordance with the Company’s record retention practices.
Employees who report incidents or concerns in good faith shall not be subject to retaliation or adverse treatment for making such reports.
12. Non-Compliance
All employees are expected to comply with this Policy. Suspected or actual breaches should be reported promptly to the AI Owner or the employee’s direct manager.
INTEA will investigate reported breaches in a fair and proportionate manner. Deliberate or repeated violations of this Policy, including the unauthorised use of AI tools or the inappropriate disclosure of confidential or personal information through AI systems, may result in disciplinary action in accordance with INTEA’s internal procedures.
Employees who report suspected breaches or raise concerns in good faith shall not be subject to retaliation for doing so.
13. Policy Review and Contact
This policy is reviewed by the AI Owner at least once a year, or sooner if there is a significant change in the law (EU AI Act, GDPR) or in the tools used.
Questions, requests for new tools, and incident reports go to: ak@intea.lv.