Corporate Governance Back to list

7 14

Artificial intelligence management



Responsible Artificial Intelligence Policy

1. Policy Objectives and Background

SITC is committed to the responsible development, deployment, and use of Artificial Intelligence (AI) systems in its business operations. This policy aims to proactively establish an AI governance framework to ensure that the application of AI technologies aligns with ethical standards, legal and regulatory requirements, and the expectations of stakeholders. While driving innovation and efficiency, the Company seeks to effectively manage AI-related risks and establish corresponding internal management systems.

At the current stage, the AI systems applied by the Company are used only for general office scenarios such as document organization, document content generation, and internal information queries. They are not yet used for personnel evaluations and do not involve judgments based on sensitive information such as gender, age, or geographic location. The Company will continue to advance the development, deployment, and application of AI systems prudently, adhering to the principles of data security, ethics, transparency, and sustainability.

2. Scope of Application
This policy applies to the development, procurement, deployment, or use of AI systems by the Company, its subsidiaries, and affiliates in all business activities, covering all business areas including container liner shipping, freight forwarding, ship agency, ship management, and logistics services.

3. Policy Content
The Company commits to adhering to the following principles in the development, deployment, and use of AI systems:

3.1 Data Privacy Protection
When using and/or developing AI systems, the Company shall strictly comply with the data protection laws and regulations of the locations where it operates, protecting personal data throughout the entire lifecycle of AI system design, development, and operation. The Company has already committed to protecting the personal information of customers and employees and complying with relevant privacy regulations in its Code of Business Ethics and Personal Information Protection Policy. AI-related data privacy protection measures will be further detailed and implemented based on these commitments.

3.2 Network Security Assurance
Based on the IT Security Management and Emergency Procedures and the User Terminal Computer and Information Security Management Regulations, the Company shall take strong cybersecurity measures to protect AI systems from cyberattacks, including but not limited to penetration testing, incident response mechanisms, data encryption, and secure coding practices. AI systems must undergo a cybersecurity assessment and meet the Company's information security standards before deployment.

3.3 Avoiding Potential Bias
Ensure that the design and operation of AI systems follow principles of fairness and non-discrimination. Establish mechanisms for identifying and mitigating bias in AI models, including identifying and eliminating bias during the data training phase, conducting bias audits, and ensuring the diversity and representativeness of training datasets.

3.4 Human Participation in Key Decisions
Ensure effective human oversight in key decisions affected by AI and establish a Human-in-the-Loop (HITL) mechanism. For irreversible or high-risk decisions, there must be explicit human review, intervention, or veto authority to ensure that AI systems cannot make significant decisions without human supervision.

3.5 Transparency and Explainability
Ensure the transparency of AI systems by clearly disclosing the use cases, capabilities, limitations, data sources, and risks of AI. AI-generated results and decisions should provide understandable reasons and explanations. In customer interaction scenarios, customers must be clearly informed that they are interacting with an AI system.

3.6 Clear Accountability Mechanism
Establish a clear accountability mechanism for the outcomes of AI systems. Designate responsible personnel for the output, risk decisions, and compliance of AI. Establish processes for the investigation and handling of AI-related errors or damages.

3.7 Defining AI Application Boundaries
Clearly define the authorized scope, capabilities, and limitations of AI systems. Establish permissible use policies and guardrails for AI applications to prevent AI systems from operating beyond their intended scope or producing unintended applications.

3.8 Low Ecological Footprint Requirements
When self-building or using third-party AI data centers/models, pay attention to and strive to reduce energy consumption, water usage, and carbon intensity. Promote optimization technologies to reduce computational load and energy waste, prioritize energy-saving infrastructure, and encourage the use of renewable energy.

3.9 Prohibition of Banned AI Systems
The Company commits to not using or deploying AI systems that engage in manipulative behavior, exploit vulnerabilities, conduct social scoring, or perform unauthorized biometric surveillance (such as the types of systems prohibited by the EU Artificial Intelligence Act or similar acts in other regions).

3.10 Data Input and Information Protection
Employees must not input any confidential company information, trade secrets, customer personal information, source code, business or financial data, internal meeting minutes, strategic plans, or other sensitive information, data, or screenshots into any unreliable external AI platforms lacking data confidentiality. It is prohibited to download any of the aforementioned content onto private computers, mobile phones, or other devices and then upload it to AI tools.
Employees must properly safeguard the login credentials for AI tool accounts, must not share accounts with others, and ensure that AI tool accounts processing company data are not accessed by unauthorized personnel.

3.11 Review and Use of AI-Generated Content
Content generated by AI systems used by employees shall not be directly used as final work outputs. Before using AI-generated content, employees must conduct sufficient fact-checking, accuracy verification, and compliance review.

3.12 Prohibited AI Use Behaviors
When using AI systems, employees are strictly prohibited from generating false information, fraudulent content, discriminatory statements, or content that infringes upon the legal rights of others.

3.13 Training and Capacity Building
Each company and department shall, based on job requirements, provide appropriate AI literacy training for employees who need to use AI tools or could use them to improve work efficiency, ensuring that employees understand the principles of responsible AI use, data protection requirements, and ethical use norms, while also enhancing their proficiency.

4. Clear Accountability Mechanism
Establish a clear accountability mechanism for the outcomes of AI systems, identifying responsible persons for liability issues such as complaints and incidents arising from AI-related processes.

4.1 AI System Development and Management Responsibility
Personnel responsible for the development and management of AI systems shall bear responsibility for the fairness, unbiased nature, and non-discrimination of AI outputs, as well as for security boundaries, compliance, network security, and data privacy protection in AI projects.

4.2 AI User Responsibility
Employees who violate regulations in using AI tools, leading to company data breaches, leakage of trade secrets, intellectual property infringement, or legal compliance risks, shall bear corresponding liability.
Content generated by AI tools must undergo fact-checking and compliance review before use. Employees who use AI-generated content without verification, resulting in work errors, compliance risks, complaints, or incidents, shall bear responsibility.

4.3 AI Management and Supervision Responsibility
The head of each department shall ensure that departmental employees fully understand and comply with AI policies and regulations, bear management and supervision responsibility for the AI usage behavior of their department's employees, and cooperate with the complaint, investigation, and handling processes related to AI-related errors or damages.

4.4 AI-Related Complaint and Incident Handling Process
The handling processes for AI-related complaints and incidents shall refer to the corresponding complaint, whistleblowing, and incident handling procedures of SITC.

5. Policy Authorization
This policy has been formally approved and endorsed by the Board of Directors and shall take effect from the date of issuance.

6. Policy Review and Disclosure
The AI management system is planned and managed collaboratively by the Company's Information Technology Department and the ESG Governance Group.
This policy will be reviewed and updated periodically to ensure alignment with evolving laws, regulations, industry standards, and best practices, referencing international frameworks such as the OECD AI Principles, the UNESCO Recommendation on the Ethics of AI, and the EU Artificial Intelligence Act.
This policy and related implementation information will be publicly disclosed to the public through the Company's official website and sustainability reports.

 

 

 

 

 

Responsible Artificial Intelligence Project Management

1. Overview
SITC proactively establishes a responsible AI project management system aimed at ensuring that ethical and environmental considerations are taken into account during the development and implementation of any AI project, promoting an accountability and transparency culture. This project covers the full lifecycle management of AI systems, from needs assessment, development, and deployment to operational monitoring and continuous improvement.

2. Project Principles

2.1 Access Restrictions for Sensitive AI Capabilities
Implement strict access control mechanisms for sensitive AI capabilities involving facial recognition, surveillance, etc., authorizing only trained and approved personnel to use them in specific scenarios, with usage logs and audit trails established.

2.2 Clear Labeling of AI-Generated Content
All content generated by AI systems (including text, images, data analysis results, and decision recommendations) shall be clearly labeled so that customers and stakeholders can clearly distinguish AI-generated content from human-generated content.

2.3 AI Model Drift Detection and Correction
Establish an ongoing monitoring mechanism for AI model performance, regularly detecting model drift or performance degradation caused by changes in data patterns or external conditions, and promptly taking corrective measures such as retraining and parameter adjustment to ensure the continued reliability and relevance of AI systems.

2.4 Regular Assessment of AI Model Fairness/Bias
Conduct systematic fairness and bias assessments for deployed AI models, including regular audits, bias testing, and fairness evaluations, to ensure AI models treat all relevant parties fairly without perpetuating or exacerbating existing inequalities.

2.5 Initiatives to Reduce AI Ecological Footprint
When self-building or cooperating with suppliers to operate AI data centers, adopt initiatives to reduce the ecological footprint, including using energy-saving hardware, optimizing algorithms to reduce energy consumption, and utilizing renewable energy.

2.6 AI Decision Appeal Process
Establish a transparent, accessible, and responsive appeal process enabling customers, partners, or other affected parties to challenge and appeal AI-generated decisions or outcomes.

2.7 Quantification of AI’s Impact on Sustainable Development Outcomes
Establish a quantitative assessment mechanism to systematically measure the impact of AI initiatives on sustainable development goals, including indicators and Key Performance Indicators (KPIs) in areas such as carbon emission reduction, resource efficiency improvement, and operational optimization.

2.8 Employee AI Ethics and Safety Training
Provide training on the ethical use and safety of AI for all employees involved in the development, deployment, or use of AI systems, covering content such as bias awareness, data privacy, the ethical implications of AI decisions, and security protection measures.

2.9 External Validation of AI Management System
Actively promote the external validation of the AI management system, aligning with international standards, and establish, implement, maintain, and continuously improve the AI management system. The Group Headquarters’ Risk and Internal Control department conducts an audit covering information systems every three years. EY (Ernst & Young) conducts an annual external audit of the information security policy implementation records, and an external professional body verifies the information system security at least annually, with reinforcement and optimization based on the verification results.

3. Project Governance
The Responsible AI Project is planned collaboratively by the Company's Information Technology Department and the ESG Governance Group, and its implementation is authorized by the Board of Directors.