Artificial Intelligence at EG

At EG, we believe AI should expand what is possible for our customers - without compromising security, privacy, or trust. As we integrate AI capabilities across our products and internal operations, we are committed to doing so responsibly: with security in mind, in compliance with applicable law, aligned with international standards, and guided by clear ethical principles.​

Our AI Governance Framework

Our approach to AI is grounded in EG’s formal AI Governance Framework, aligned with the EU AI Act. It applies to all AI use in EG - whether built in-house or sourced from third parties, used internally or delivered to customers.

Security, Privacy & Data Ethics

How EG handles personal data, intellectual property rights, and human accountability in AI-assisted decisions.

Human Oversight, AI Literacy & Regulatory Alignment

EG invests in AI literacy across the organization and aligns its governance framework with leading regulatory standards - including the EU AI Act, NIST, and GDPR.

AI Governance in Practice

Our AI Policy applies to every AI use case across EG - whether built in-house or purchased, internal or customer-facing.

Our approach

Our AI Governance Framework

Our approach to AI is grounded in EG’s formal AI Governance Framework, aligned with the EU AI Act. It applies to all AI use in EG - whether built in-house or sourced from third parties, used internally or delivered to customers.

Transparency

EG is committed to being transparent about how AI is used - both internally and in the products and services we deliver to customers. Where AI is used in a workflow, users are informed. Third-party AI providers are assessed for model transparency before integration.

Governance

EG has established a cross-functional AI Forum as the central governance body overseeing AI across the organization, with representatives from Group Legal & Compliance, Cyber & Information Security, Technology & Innovation, Corporate IT, and Business Units. All significant AI use cases must be registered in our governance, risk & compliance system and reviewed in accordance with their risk classification.

Security

EG applies a structured set of AI-specific security controls covering input and output security, access management, audit logging, data protection, model transparency, security testing, and incident response. Controls are scaled to the risk classification of each use case. All AI tools and services must be approved through our Vendor Approval Board process before deployment.

Compliance

EG’s AI Governance Framework is aligned with the EU AI Act. We apply its risk-based classification, transparency requirements, and high-risk AI provisions. Our framework incorporates elements of the NIST AI Risk Management Framework, OWASP LLM Security Guidelines, and GDPR. Our AI Policy applies to all employees, consultants, and contractors.

OUR COMMITMENTS

Security, Privacy & Data Ethics

How EG handles personal data, intellectual property rights, and human accountability in AI-assisted decisions.

Security

EG applies security controls to all AI use cases, covering areas such as input and output guardrails, access management, audit logging, data protection, security testing, model security monitoring, and incident response. Controls scale with risk: higher-risk use cases face stricter requirements. All controls are documented in EG's AI registry and reviewed regularly as part of lifecycle management.

Privacy & Data Ethics

AI at EG is designed and operated in accordance with GDPR and EG’s Data Ethics Policy. We apply data minimization: AI systems process only the personal data strictly necessary for their purpose. Employees may not upload confidential or customer data to unapproved AI tools. A Data Protection Impact Assessment (DPIA) is conducted where required under GDPR.

Intellectual Property

EG takes a careful approach to the IP implications of AI-generated content. Employees are expected to evaluate AI outputs before use, particularly where content may implicate third-party rights.​ Questions about IP ownership of AI-generated outputs are handled in consultation with Group Legal & Compliance.

Human Oversight, AI Literacy & Regulatory Alignment

EG invests in AI literacy across the organisation and aligns its governance framework with leading regulatory standards - including the EU AI Act, NIST, and GDPR.

Human Oversight

EG maintains a “human in the loop” principle for AI decisions that affect individuals. Where AI supports consequential decisions, documented approval workflows ensure a human reviews and takes responsibility for the outcome.​ AI does not make final decisions in critical processes without human validation.

AI Literacy

Consistent with the EU AI Act’s AI literacy requirements, EG is committed to providing all employees with training on the responsible, lawful, and ethical use of AI tools.​ Training is available through our learning management systems. Product-specific guidance is maintained in EG’s internal playbooks. Employees are expected to understand both the possibilities, risks and the limitations of the AI tools they use.

Regulatory Alignment

EG’s AI Governance Framework is aligned with the EU AI Act, the world’s first comprehensive AI regulation. We apply its risk-based classification, transparency requirements, and high-risk AI provisions.​ Our framework incorporates elements of the NIST AI Risk Management Framework, OWASP LLM Security Guidelines, and GDPR. EG’s AI Policy applies to all employees, consultants, and contractors and is reviewed at least annually.

Our Policy

AI Governance in Practice

Our AI Policy applies to every AI use case across EG - whether built in-house or purchased, internal or customer-facing.

Risk Based Classification

Every AI use case at EG is registered in our governance, risk & compliance system and classified by risk level, taking into account the type of data involved, whether it affects customers or end users, and the degree of AI autonomy - before it can be deployed.

AI Forum

The AI Forum brings together representatives from Group Legal & Compliance, Cyber & Information Security, Technology & Innovation, Corporate IT, and Business Units. It is responsible for maintaining our AI Governance Framework, monitors use of high-risk AI across EG and are responsible for our AI adoption ensuring we keep pace with evolving technology.

Lifecycle management

AI use cases are subject to periodic reassessment whenever they materially change - for example, when an AI model is upgraded, new data types are introduced, or the system’s level of autonomy increases.

AI Governance Process

1. Risk Assessment

EG classifies AI use cases according to the level of risk it presents. Use cases that present lower risk are subject to standard controls and approved tool requirements.

2. AI Forum Review

Use cases that present higher risk require formal review and approval by the AI Forum. Use cases that cannot be made secure and compliant are blocked entirely.

3. Lifecycle Monitoring

All approved AI use cases are periodically reassessed whenever the use case materially changes - for example, when an AI model is upgraded, new data types are introduced, or the system's level of autonomy increases.

See how EG puts AI to work

AI governance sets the foundation. Real impact happens when AI is built into the software itself.