Holos
About Holos

Code of Conduct: Responsible Use of Artificial Intelligence

The shared framework of ethical principles and operational rules for how Holos develops, deploys and uses Artificial Intelligence, aligned with our corporate values, data privacy and the EU AI Act.

1. Purpose and scope

Holos recognises the transformative power of Artificial Intelligence (AI) to drive innovation, optimise efficiency, and deliver superior value to our clients.

This Code of Conduct establishes a shared framework of ethical principles and operational rules for the development, deployment, and daily usage of AI technologies at Holos. It ensures that our adoption of AI aligns with our corporate values, protects data privacy, minimises risks, and fully complies with relevant regulations, including the EU AI Act.

Scope

This code applies to all employees, contractors, consultants, and external partners working on behalf of Holos. It covers:

  • Internal productivity: the use of commercial, third-party generative AI tools (for example LLMs, image and code generators) for day-to-day office tasks, coding, or marketing.
  • Product development and delivery: the research, architectural design, training, and deployment of proprietary AI models or integrated AI features within Holos client deliverables.

2. Core principles for AI governance

To maintain trust with our clients, employees, and society, Holos commits to the following seven core pillars:

  • Human oversight: AI must assist, not replace, human accountability. Decisions always require human validation. No delegation allowed.
  • Privacy and security: data minimisation and rigorous information security protocols apply strictly to all AI interactions, on a need-to-know basis.
  • Transparency: we disclose when AI is used and ensure outputs are explainable, traceable, and not misleading.
  • Fairness and non-discrimination: we actively audit and refine data inputs and models to prevent historical or social biases.
  • Reliability and safety: AI tools must undergo rigorous testing to ensure resilience, accuracy, and technical safety.
  • Intellectual property respect: we respect copyrights, licensing, and proprietary terms regarding training data and outputs.
  • Environmental sustainability: we promote energy-efficient programming and mindful compute consumption during model training.

3. Practical rules for daily AI use

3.1 Data confidentiality and input safety

The security of our intellectual property and client data is paramount.

  • Strict prohibition: never input proprietary source code, internal financial reports, client-identifiable data (PII), unreleased project specifications, or trade secrets into public, free, or third-party generative AI tools (for example standard ChatGPT or public LLMs).
  • Approved ecosystems: only use AI interfaces explicitly sanctioned by the Holos IT and Security department, preferably those operating within enterprise-grade, data-isolated corporate accounts where inputs are not used for model retraining.

3.2 Fact-checking and accountability

Generative AI tools are prone to "hallucinations", plausible-sounding but entirely fabricated facts, code libraries, or citations.

  • The human sign-off: the employee using the AI tool remains 100% accountable for the accuracy and quality of the final output.
  • Mandatory verification: all text, mathematical calculations, and code generated by AI must be meticulously reviewed, tested, and verified by a qualified professional before being pushed to production or sent to a client.

3.3 Engineering and coding standards

  • Code quality: AI-generated code snippets must pass the same, or more stringent, peer reviews, linting, and automated testing pipelines as human-written code.
  • Security vulnerabilities: AI-generated code must be scanned for known security vulnerabilities and outdated dependencies before implementation.

3.4 Marketing, communication, and content generation

  • Disclosure: when creating comprehensive client deliverables, official public statements, or legal documents significantly drafted by AI, its use should be documented or disclosed where transparency is legally or ethically required.
  • Authenticity: we do not use AI to generate misleading deepfakes, altered media that misrepresents the truth, or content that infringes upon the copyrights of third-party creators.

4. Compliance with the EU AI Act

Holos operates under the jurisdiction of European regulations. We strictly adapt our AI processes to the risk-based approach outlined by the EU AI Act:

  • Prohibited practices: Holos will never develop or deploy AI systems that engage in cognitive behavioural manipulation, untargeted scraping of facial images, or social scoring systems.
  • High-risk AI systems: if an internal project or client request falls under the "high-risk" classification (for example biometrics, critical infrastructure, or HR evaluation software), it must immediately be routed to the Compliance Team for a mandatory Fundamental Rights Impact Assessment (FRIA) and technical CE-marking preparation.
  • AI literacy: in compliance with Article 95 of the EU AI Act, Holos commits to providing ongoing training to ensure all staff maintain the necessary skills to understand AI capabilities, limitations, and risks.

5. Violations and reporting

Adherence to this Code of Conduct is mandatory. Failing to comply can result in security breaches, legal liabilities, or severe damage to the reputation of Holos.

  • Violations: non-compliance with data privacy inputs or intentional deployment of unverified AI components may lead to disciplinary action, up to and including termination of employment or contract.
  • Reporting: if you spot an AI model producing heavily biased results, exposing private data, or being used in a way that contradicts this code, report it immediately to the Internal AI Governance Working Group or via the corporate compliance channel.

Acknowledge and accept

By continuing to use corporate infrastructure and third-party AI assets at Holos, you acknowledge that you have read, understood, and agreed to adhere to this Code of Conduct.

Holos, S.A. · Version 1.0