AI Legal Disclaimer

1. Purpose and Scope

This document defines the AI governance framework at Baumit to ensure the secure, responsible, and compliant use of generative AI. The focus lies on data quality, data protection, and risk mitigation when using AI assistants and tools across the organization.

All measures align with applicable internal policies, EU GDPR, and enterprise-grade security standards.



2. General Guidelines for the Use of AI Tools


  • Only approved AI tools may be used within Baumit.
  • Use is permitted only for non-sensitive data, unless explicitly authorized.
  • Human validation – Human-in-the-loop (HITL) – is required before publishing or acting on AI-generated content.
  • Employees must be trained to ensure awareness of risks, limitations, and correct usage of AI.
  • AI use must be documented and transparent within relevant workflows.


3. Extended Guidelines for Assistive AI Tools


  • No entry of sensitive information such as contracts, business terms, or customer data into any AI system, unless explicitly authorized.
  • Only synthetic, anonymized, or predefined data sets are used.
  • AI may assist with text creation, translations, ideation, etc., provided that the output is reviewed and refined by a human.
  • When used in content creation, the AI contribution must be clearly traceable.


4. Integrated Governance for AI Co-Pilots

AI tools embedded in productivity systems (e.g., Microsoft Copilot) are subject to:

 
  • Access control via RBAC (Role-Based Access Control).
  • Audit logging of all interactions.
  • Restricted environments that do not interface with live or sensitive systems (e.g., ERP).
  • AI assistants do not interact with the pricing logic or internal product databases.
  • Rollouts are centrally coordinated and aligned with both local and group-level governance.


5. Security and Compliance Measures

As part of the AI assistant prototype development, a secure instance of ChatGPT was deployed, hosted on Microsoft Azure. This instance is managed by OpenAI. The following security standards apply:

  • Data Isolation: No inputs are used to train public models. Data remains contained within the instance.
  • Data Encryption: TLS 1.2+ and AES-256 protect all data in transit and at rest.
  • Role-Based Access Control (RBAC): Only authorized users may access the AI tools.
  • Certified Infrastructure: Hosted on Microsoft Azure, compliant with ISO/IEC 27001, SOC 2 Type II, GDPR, and other major standards.
  • No sensitive content – such as contracts, individual pricing, or internal calculations – has been or will be shared with any AI tool. 


6. Data Protection and Information Integrity


  • Full compliance with GDPR and internal security policies is mandatory.
  • Information shared with AI tools must be classified and reviewed beforehand.
  • Baumit ensures that data quality remains high by limiting AI training data to approved, clean datasets.


7. Summary & Commitment

Through clear restrictions, certified environments, and human oversight, Baumit ensures a robust, auditable, and future-proof AI governance framework. This framework:


  • Enables the secure use of generative AI
  • Protects data integrity and confidentiality
  • Ensures compliance with all applicable regulations
  • Creates a trusted foundation for scaling AI responsibly across markets

All employees are responsible for complying with these principles and reporting any deviation or risk.