top of page

AI Transparency Notice

PATRIMIUM ASSET MANAGEMENT LIMITED

AI Transparency and Responsible Use Notice

Effective date: August 2026

Regulatory Basis: This Notice is issued in compliance with the DIFC Data Protection Law No. 5 of 2020 ("DPL") and Regulation This Notice explains how Patrimium uses AI systems where they process personal data and the safeguards we apply. It is intended to support transparency under applicable DIFC data-protection requirements.

1. Introduction and Purpose of This Notice

Patrimium Asset Management Limited ("Patrimium", "we", "us", "our") is authorised and regulated by the Dubai Financial Services Authority (DFSA), Firm Reference Number F011669, and incorporated in the Dubai International Financial Centre (DIFC), Unit OT 26-42, Level 26, Central Park Offices, DIFC, Dubai, UAE.

 

We are committed to the transparent, responsible, and accountable use of artificial intelligence (AI) tools in the delivery of our investment management and related services. This Notice is provided in accordance with Regulation 10.2.2 of the DIFC Data Protection Regulations and explains what we mean by AI Systems; how we use AI Systems and for what human-defined purposes; how AI Systems may process your personal data; the principles and safeguards governing our use of AI; what we do not permit AI to do; and your rights as a data subject in connection with AI-assisted processing.

 

2. What We Mean by AI Systems

2.1 Definition

An "AI System" means any machine-based system operating in an autonomous or semi-autonomous manner that can process personal data for human-defined purposes, or purposes the system itself defines, and generate output as a result of such processing. This includes machine learning, natural language processing, and generative AI tools, consistent with the definition of "System" in Regulation 10.1.1(a) of the DIFC Data Protection Regulations.

 

2.2 Patrimium's Role: Deployer

Patrimium acts as the Deployer of AI Systems within the meaning of Regulation 10.1.1(b), assuming the general responsibilities of a Controller under the DPL with respect to AI-assisted processing. Third-party service providers who operate AI Systems on Patrimium's behalf act as Operators under Regulation 10.1.1(c).

 

2.3 The AI Tools We Use

Regulation 10.2.2 requires a description of human-defined purposes, outputs, design principles, safeguards, and applicable codes or certifications. Patrimium uses the following categories of AI tools:

  • Approved enterprise or business AI-enabled tools used for drafting, summarising, analysing, translating and other authorised purposes, subject to appropriate controls

  • Approved automated or AI-assisted compliance tools may be used to support sanctions, PEP, adverse-media and other screening processes.

Patrimium maintains records of approved AI systems, their intended purposes and applicable governance controls..

 

3. How We Use AI Systems: Human-Defined Purposes

All purposes below are human-defined and pre-set. No AI System may define its own processing purposes beyond those stated here, in compliance with Regulation 10.2.2(b)(i).

Search and information retrieval; summarisation and classification of documents and data; analysis and insight to support investment, risk, and compliance functions; drafting and content generation; translation; and transcription of spoken communications. AI-generated outputs are subject to human review appropriate to their purpose, risk and potential impact before they are relied upon externally or used to make a decision affecting an individual

Compliance and regulatory screening: AI Systems, including automated screening tools where deployed, are used to assist with AML/KYC screening, sanctions and PEP screening, adverse media monitoring, and regulatory change monitoring. Where screening tools generate automated flags or alerts, human intervention is applied before any alert is finalised or any determination or action is taken. No automated flag produces a final outcome without human review and authorisation.

Cybersecurity and anomaly detection: AI Systems are used to detect anomalies, unusual patterns, and potential security threats in order to protect the firm's systems and client data.

4. Human-Defined Limits and Principles

In compliance with Regulation 10.2.2(b)(ii), every AI System is subject to the following limits imposed by Patrimium as Deployer:

  • Purpose limitation: AI Systems may only process personal data for the specific human-defined purposes in Section 3.

  • Human oversight: all AI-generated outputs that may affect any individual are subject to human review before any action is taken.

  • Patrimium does not make decisions based solely on automated processing where those decisions produce legal or similarly significant effects on an individual, except where permitted by applicable law and subject to the safeguards required by that law.

  • Data minimisation: AI Systems process only the personal data strictly necessary for the specific task.

  • Authorised use cases only, as listed in Section 3 and in the internal AI Governance framework.

  • No sensitive profiling of individuals on the basis of sensitive characteristics.

 

5. AI System Outputs and How They Are Used

In compliance with Regulation 10.2.2(b)(iii), no AI output is used as the final basis for any decision affecting any individual without human review. The following summarises how outputs are used:

Output Type

How It Is Used

Search results and extracted data

To inform research, analysis, and decision-making by human professionals

Document summaries

To assist staff in reviewing documents efficiently; reviewed before reliance

Drafted content

Reviewed, edited, and approved by humans before any communication is finalised or sent

Translated content

Reviewed by qualified humans before reliance or distribution

Meeting transcriptions

Reviewed for accuracy by humans; used as internal records only

Compliance screening flags/alerts

Reviewed by compliance professionals; human intervention required before any determination is finalised

Anomaly and security alerts

Reviewed by IT and compliance professionals before any response is initiated

 

6. Design Principles and Safeguards

6.1 Human Agency and Oversight

AI Systems support human professionals; they do not replace them. Human oversight is maintained over all AI-assisted processes. Staff take reasonable steps to identify and mitigate bias in AI outputs.

6.2 Fairness and Non-Discrimination

Patrimium assesses proposed AI use cases prior to deployment to evaluate fairness and bias risks. AI Systems are not used in ways that could produce unfair or discriminatory outcomes for any individual.

6.3 Transparency and Explainability

Patrimium is transparent about its use of AI, as evidenced by this Notice. AI Systems are selected and reviewed with reference to their explainability.

6.4 Data Protection and Privacy by Design

We apply appropriate contractual, confidentiality, security and data-protection safeguards when engaging AI service providers. Only business-tier AI tools with appropriate data isolation and access controls are used for processing that involves client personal data.

6.5 Safety and Security

AI tools are subject to review prior to deployment. Access is restricted to authorised staff for authorised use cases only. Patrimium maintains an incident response procedure for AI-related data incidents.

6.6 Accountability

Accountability for AI governance rests with the Head of Compliance & MLRO, with oversight from the Senior Executive Officer and, Where required by applicable law for high-risk processing, Patrimium will establish the relevant accountability arrangements. AI governance is a standing item on the firm's risk management agenda. Patrimium maintains an AI Register recording approved AI systems, their purposes and relevant governance information.

7. Codes, Certifications, and Frameworks

Our AI governance approach is informed by applicable DIFC data-protection requirements and recognised responsible-AI and risk-management principles.

 

8. What Patrimium Will Never Use AI To Do

  • Make final automated decisions on investment, credit, compliance, or other matters affecting any individual without prior human review.

  • Impersonate or misrepresent any person or entity.

  • Process personal data for purposes not described in this Notice or authorised in the AI Register.

  • Profile individuals on the basis of sensitive characteristics (political opinions, religious beliefs, health information, biometric characteristics, or ethnic origin).

  • Assign social scores or trustworthiness ratings to individuals.

  • Exploit individual vulnerabilities, including those arising from age, financial position, or personal circumstances.

  • Use subliminal, deceptive, or manipulative techniques.

  • Enter client personal data or confidential information into non-approved or non-business-tier AI tools.

  • Use AI in a manner that is reasonably likely to cause unjustified physical, psychological, financial or legal harm to an individual.

 

9. Your Rights as a Data Subject

In compliance with Regulation 10.2.2(a), your rights in connection with AI-assisted processing are as follows:

Right

How It Applies in the Context of AI

Right to be informed

Satisfied by this Notice and Patrimium's Privacy Policy

Right of access

Request details of personal data processed about you through AI Systems

Right to rectification

Request correction of personal data used in AI-assisted processes

Right to erasure

Request deletion where no lawful basis for continued AI-assisted processing exists

Right to restriction

Request that AI-assisted processing is restricted in certain circumstances

Right to object

Object to AI-assisted processing where the lawful basis is legitimate interests

Right to human review

Right to request human intervention: You may request human intervention in relation to an AI-assisted process where required by applicable law or where an AI-assisted output materially affects you

Right to withdraw consent

Withdraw consent at any time where consent is the lawful basis

Right to complain

Lodge a complaint with the DIFC Commissioner of Data Protection

To exercise any of these rights, please contact the Head of Compliance, Patrimium Asset Management Limited, Unit OT 26-42, Level 26, Central Park Offices, DIFC, Dubai, UAE; patrimium.compliance@patrimiummfo.com; +971 50 633 6186.

 

10. Complaints

DIFC Commissioner of Data Protection, Level 14, The Gate, DIFC, P.O. Box 74777, Dubai, UAE; commissioner@dp.difc.ae; www.difc.com/commissioners/data-protection.

11. Updates to This Notice

We may update this Notice when our use of AI systems, legal requirements or governance arrangements change. The current version and its effective date will be available on this page.

 

Patrimium MFO Logo

Patrimium Asset Management Limited is a firm regulated by the Dubai Financial Services Authority (DFSA) and is only authorised to provide financial services to Professional Clients or Market Counterparties (all terms are defined in the DFSA Conduct Of Business (COB) Rules).

© 2026 Patrimium Multi Family Office. All Rights Reserved.

  • LinkedIn
bottom of page