Skip to main content
Review and revision metadata
Review Date: 2026-08-18
Reviewer: Operations Manager

previous version on gdrive

AI/Large Language Model (LLM) Use Policy

1. Strategic Alignment & Permitted Workloads

anDREa actively supports and encourages the strategic exploration, integration, and implementation of vetted AI and LLM technologies to drive operational excellence across three core dimensions:

  • Process Optimization & Efficiency: Automating repetitive administrative tasks, optimizing software development lifecycles within our Azure DevOps sprintboards, and accelerating technical workflows.
  • Augmented Decision-Making: Deriving structured, data-driven insights from aggregated telemetry to support formal governance choices.
  • Continuous Innovation: Identifying advanced architectural opportunities and engineering resilient solutions for the myDRE platform.
  • AI use in development: For all activities pertaining to software engineering, source code generation, debugging, or repository management, personnel must strictly adhere to the internal document on Guidelines for the Use of AI in Software Development which serves as the specialized technical annex to this overarching policy.

2. Ethical Pillars and Responsible Use Guidelines

All AI/LLM deployments must conform strictly to the following corporate governance pillars:

  • Transparency: Users and engineers must maintain comprehensive visibility into the specific capabilities, processing boundaries, and operational limitations of utilized models.
  • Fairness & Bias Mitigation: Algorithms, system prompts, and underlying datasets must be leveraged in an objective, non-discriminatory manner, explicitly preventing algorithmic bias or systematic disparate impacts.
  • Uncompromising Accountability: Ultimate accountability for any business output, codebase change, or strategic decision influenced by AI-generated data remains strictly with the human operator and the organization. AI outputs must never be accepted blindly without manual verification.
  • Privacy by Design: Personal Data and Personally Identifiable Information (PII) must be structurally isolated from unvetted public models, adhering rigidly to the data minimization principles of the GDPR.

3. Personal Information & Data Sovereignty Governance

3.1 Strict Processing Restrictions

The processing of Personal Data or PII by any AI/LLM system is prohibited by default. Corporate data assets must be protected against model retraining loops and unauthorized exposure.

3.2 Pre-Qualification and Authorization Process

To authorize an AI/LLM solution for handling personal data, personnel must execute the following structured process:

  1. Formal Request Submission: The requestor must document the specific business justification, the type of data to be processed, and the technical architecture of the AI tool.
  2. Management Team Evaluation: The request must be routed directly to the Management Team to verify the technical and legal qualifications of the model provider.
  3. White-Listing: An AI/LLM solution will only be cleared for Personal Data if the provider guarantees contractually that inputted data is excluded from model training, adheres to localized data residency laws, and operates under a valid Data Processing Agreement (DPA).
  4. Business of Enterprise tier licensing: All approved AI/LLM tooling must be provisioned under Business or Enterprise tier licensing. The use of personal or free tier accounts for business purposes is prohibited.

3.3 Mandatory Regulatory Mapping

Any approved AI/LLM solution handling personal data must demonstrate absolute compliance with the following statutory requirements:

  • GDPR Article 5 (Principles of Processing): Enforcement of data minimization, purpose limitation, and storage limitation.
  • GDPR Article 6 (Lawfulness of Processing): Clear identification of the legal basis permitting the data processing activity.
  • GDPR Article 24 (Responsibility of the Controller): Implementation of appropriate technical and organizational measures to demonstrate that processing complies with EU privacy frameworks.

4. Technical Security and Compliance Framework

4.1 Security Control Implementation

Security architectures designed to protect corporate and client data processed by AI/LLMs are mapped directly to ISO/IEC 27001:2023 Annex A controls. These include, but are not limited to, strict logical access controls (A.5.15–A.5.18), supplier information security management (A.5.19–A.5.23), and application security requirements (A.8.25–A.8.28). Access to AI/LLM tooling is documented and periodically reviewed in internal anDREa people asset overview ( https://docs.google.com/spreadsheets/d/1dGZ5o8jMv_2WYB5_A2zbcWVbgG5Ih97Cx5HXJMVaO10/edit?gid=0#gid=0&fvid=1931372138) to ensure the principle of least privilege.

4.2 The Security Impact Assessment (SIA) Lifecycle

Before any AI/LLM tool, plugin, or API is deployed within anDREa processes or integrated into the myDRE platform ecosystem, it must undergo a mandatory Security Impact Assessment (SIA).


[Tool Proposed] ──► [Management Team Inception] ──► [SIA Execution] ──► [Approved & Added to Registry]

Operational Steps for SIA Execution:

  1. Initiation: The internal sponsor must engage the Management Team to initiate a formal SIA.
  2. Review Metrics: The assessment will thoroughly evaluate data retention mechanics, end-to-end encryption protocols, vendor vulnerability management processes, and corporate blast radius isolation capabilities.
  3. Centralized Registry Logging: Upon successful validation, the Management Team will log the approved solution within the official Changes to ISMS Register.
  4. Continuous Auditing: Any modification to the AI provider’s terms of service, data privacy policy, or API architecture will automatically invalidate the active SIA, triggering a mandatory re-assessment.

5. Training, Competency, and Awareness

To align with the organizational competency requirements of ISO/IEC 27001:2023 Control A.06.03(Information security awareness, education, and training) and NIS 2 management training standards, anDREa will maintain continuous education programs covering:

  • Prompt Engineering & Technical Boundaries: Training on advanced prompting techniques alongside methods to identify and neutralize model hallucinations, algorithmic drift, and deepfake generation.
  • Policy Compliance: Ensuring clear enterprise alignment with the bounds of this policy document.
  • Data Exfiltration Awareness: Educating personnel on the implicit risks of inputting proprietary code, corporate intellectual property, or confidential client data into public or unvetted AI engines.

6. Statutory Compliance & Regulatory Frameworks

In accordance with A.05.31 - Legal, statutory, regulatory and contractual requirements and NIS 2 Article 20 (Governance and legal oversight), all employees, contractors, and executive leadership must strictly adhere to all applicable local, national, and international legislation governing AI deployments. This includes, but is not limited to:

  • Data Protection & Privacy: Full compliance with Dutch national privacy laws (including the Uitvoeringswet Algemene verordening gegevensbescherming - UAVG) and international frameworks applicable to anDREa's operations.
  • Cybersecurity Standards: Strict adherence to NIS 2 obligations regarding supply chain risk management, vulnerability reporting, and incident disclosure.
  • EU AI Act Regulation: Proactive compliance preparation for the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689). Personnel must ensure all AI system categorizations, risk assessments, and transparency obligations are fully operational prior to the strict enforcement date of 2027-08-02.