AI Transparency Notice
PATRIMIUM ASSET MANAGEMENT LIMITED
AI Transparency and Responsible Use Notice
Effective date: August 2026
Regulatory Basis: This Notice is issued in compliance with the DIFC Data Protection Law No. 5 of 2020 ("DPL") and Regulation This Notice explains how Patrimium uses AI systems where they process personal data and the safeguards we apply. It is intended to support transparency under applicable DIFC data-protection requirements.
1. Introduction and Purpose of This Notice
Patrimium Asset Management Limited ("Patrimium", "we", "us", "our") is authorised and regulated by the Dubai Financial Services Authority (DFSA), Firm Reference Number F011669, and incorporated in the Dubai International Financial Centre (DIFC), Unit OT 26-42, Level 26, Central Park Offices, DIFC, Dubai, UAE.
We are committed to the transparent, responsible, and accountable use of artificial intelligence (AI) tools in the delivery of our investment management and related services. This Notice is provided in accordance with Regulation 10.2.2 of the DIFC Data Protection Regulations and explains what we mean by AI Systems; how we use AI Systems and for what human-defined purposes; how AI Systems may process your personal data; the principles and safeguards governing our use of AI; what we do not permit AI to do; and your rights as a data subject in connection with AI-assisted processing.
2. What We Mean by AI Systems
2.1 Definition
An "AI System" means any machine-based system operating in an autonomous or semi-autonomous manner that can process personal data for human-defined purposes, or purposes the system itself defines, and generate output as a result of such processing. This includes machine learning, natural language processing, and generative AI tools, consistent with the definition of "System" in Regulation 10.1.1(a) of the DIFC Data Protection Regulations.
2.2 Patrimium's Role: Deployer
Patrimium acts as the Deployer of AI Systems within the meaning of Regulation 10.1.1(b), assuming the general responsibilities of a Controller under the DPL with respect to AI-assisted processing. Third-party service providers who operate AI Systems on Patrimium's behalf act as Operators under Regulation 10.1.1(c).
2.3 The AI Tools We Use
Regulation 10.2.2 requires a description of human-defined purposes, outputs, design principles, safeguards, and applicable codes or certifications. Patrimium uses the following categories of AI tools:
-
Approved enterprise or business AI-enabled tools used for drafting, summarising, analysing, translating and other authorised purposes, subject to appropriate controls
-
Approved automated or AI-assisted compliance tools may be used to support sanctions, PEP, adverse-media and other screening processes.
Patrimium maintains records of approved AI systems, their intended purposes and applicable governance controls..
3. How We Use AI Systems: Human-Defined Purposes
All purposes below are human-defined and pre-set. No AI System may define its own processing purposes beyond those stated here, in compliance with Regulation 10.2.2(b)(i).
Search and information retrieval; summarisation and classification of documents and data; analysis and insight to support investment, risk, and compliance functions; drafting and content generation; translation; and transcription of spoken communications. AI-generated outputs are subject to human review appropriate to their purpose, risk and potential impact before they are relied upon externally or used to make a decision affecting an individual
Compliance and regulatory screening: AI Systems, including automated screening tools where deployed, are used to assist with AML/KYC screening, sanctions and PEP screening, adverse media monitoring, and regulatory change monitoring. Where screening tools generate automated flags or alerts, human intervention is applied before any alert is finalised or any determination or action is taken. No automated flag produces a final outcome without human review and authorisation.
Cybersecurity and anomaly detection: AI Systems are used to detect anomalies, unusual patterns, and potential security threats in order to protect the firm's systems and client data.
4. Human-Defined Limits and Principles
In compliance with Regulation 10.2.2(b)(ii), every AI System is subject to the following limits imposed by Patrimium as Deployer:
-
Purpose limitation: AI Systems may only process personal data for the specific human-defined purposes in Section 3.
-
Human oversight: all AI-generated outputs that may affect any individual are subject to human review before any action is taken.
-
Patrimium does not make decisions based solely on automated processing where those decisions produce legal or similarly significant effects on an individual, except where permitted by applicable law and subject to the safeguards required by that law.
-
Data minimisation: AI Systems process only the personal data strictly necessary for the specific task.
-
Authorised use cases only, as listed in Section 3 and in the internal AI Governance framework.
-
No sensitive profiling of individuals on the basis of sensitive characteristics.
5. AI System Outputs and How They Are Used
In compliance with Regulation 10.2.2(b)(iii), no AI output is used as the final basis for any decision affecting any individual without human review. The following summarises how outputs are used:
Output Type
How It Is Used
Search results and extracted data
To inform research, analysis, and decision-making by human professionals
Document summaries
To assist staff in reviewing documents efficiently; reviewed before reliance
Drafted content
Reviewed, edited, and approved by humans before any communication is finalised or sent
Translated content
Reviewed by qualified humans before reliance or distribution
Meeting transcriptions
Reviewed for accuracy by humans; used as internal records only
Compliance screening flags/alerts
Reviewed by compliance professionals; human intervention required before any determination is finalised
Anomaly and security alerts
Reviewed by IT and compliance professionals before any response is initiated
6. Design Principles and Safeguards
6.1 Human Agency and Oversight
AI Systems support human professionals; they do not replace them. Human oversight is maintained over all AI-assisted processes. Staff take reasonable steps to identify and mitigate bias in AI outputs.
6.2 Fairness and Non-Discrimination
Patrimium assesses proposed AI use cases prior to deployment to evaluate fairness and bias risks. AI Systems are not used in ways that could produce unfair or discriminatory outcomes for any individual.
6.3 Transparency and Explainability
Patrimium is transparent about its use of AI, as evidenced by this Notice. AI Systems are selected and reviewed with reference to their explainability.
6.4 Data Protection and Privacy by Design
We apply appropriate contractual, confidentiality, security and data-protection safeguards when engaging AI service providers. Only business-tier AI tools with appropriate data isolation and access controls are used for processing that involves client personal data.
6.5 Safety and Security
AI tools are subject to review prior to deployment. Access is restricted to authorised staff for authorised use cases only. Patrimium maintains an incident response procedure for AI-related data incidents.
6.6 Accountability
Accountability for AI governance rests with the Head of Compliance & MLRO, with oversight from the Senior Executive Officer and, Where required by applicable law for high-risk processing, Patrimium will establish the relevant accountability arrangements. AI governance is a standing item on the firm's risk management agenda. Patrimium maintains an AI Register recording approved AI systems, their purposes and relevant governance information.
7. Codes, Certifications, and Frameworks
Our AI governance approach is informed by applicable DIFC data-protection requirements and recognised responsible-AI and risk-management principles.
8. What Patrimium Will Never Use AI To Do
-
Make final automated decisions on investment, credit, compliance, or other matters affecting any individual without prior human review.
-
Impersonate or misrepresent any person or entity.
-
Process personal data for purposes not described in this Notice or authorised in the AI Register.
-
Profile individuals on the basis of sensitive characteristics (political opinions, religious beliefs, health information, biometric characteristics, or ethnic origin).
-
Assign social scores or trustworthiness ratings to individuals.
-
Exploit individual vulnerabilities, including those arising from age, financial position, or personal circumstances.
-
Use subliminal, deceptive, or manipulative techniques.
-
Enter client personal data or confidential information into non-approved or non-business-tier AI tools.
-
Use AI in a manner that is reasonably likely to cause unjustified physical, psychological, financial or legal harm to an individual.
9. Your Rights as a Data Subject
In compliance with Regulation 10.2.2(a), your rights in connection with AI-assisted processing are as follows:
Right
How It Applies in the Context of AI
Right to be informed
Satisfied by this Notice and Patrimium's Privacy Policy
Right of access
Request details of personal data processed about you through AI Systems
Right to rectification
Request correction of personal data used in AI-assisted processes
Right to erasure
Request deletion where no lawful basis for continued AI-assisted processing exists
Right to restriction
Request that AI-assisted processing is restricted in certain circumstances
Right to object
Object to AI-assisted processing where the lawful basis is legitimate interests
Right to human review
Right to request human intervention: You may request human intervention in relation to an AI-assisted process where required by applicable law or where an AI-assisted output materially affects you
Right to withdraw consent
Withdraw consent at any time where consent is the lawful basis
Right to complain
Lodge a complaint with the DIFC Commissioner of Data Protection
To exercise any of these rights, please contact the Head of Compliance, Patrimium Asset Management Limited, Unit OT 26-42, Level 26, Central Park Offices, DIFC, Dubai, UAE; patrimium.compliance@patrimiummfo.com; +971 50 633 6186.
10. Complaints
DIFC Commissioner of Data Protection, Level 14, The Gate, DIFC, P.O. Box 74777, Dubai, UAE; commissioner@dp.difc.ae; www.difc.com/commissioners/data-protection.
11. Updates to This Notice
We may update this Notice when our use of AI systems, legal requirements or governance arrangements change. The current version and its effective date will be available on this page.
