| Version: | Current |
| Effective date: | August 25, 2026 |
| Owner: | AvePoint Privacy, Security, and Risk Team |
| Classification Level: | Public |
1. Purpose and Scope
AvePoint Inc. (“AvePoint,” the “Company,” “we,” “us,” or “our”) is committed to the responsible development, deployment, and use of artificial intelligence (“AI”). This Policy describes AvePoint’s general approach to AI governance, including responsible AI practices and expectations for acceptable use.
AvePoint aims to develop, deploy, and use AI in ways that promote trust, security, accountability, transparency, fairness, privacy, reliability, safety, and appropriate human oversight.
This public-facing Policy applies broadly to AI systems developed, deployed, procured, integrated, or used in connection with AvePoint products, services, operations, and business activities. It applies to AI systems that generate content, support decisions, automate workflows, interact with systems or data, or take actions for authorized business purposes on behalf of users or the Company.
2. Acceptable Use of AI
Privacy, Confidentiality, and Security
- AI systems and tools must be used responsibly, ethically, securely, and only for appropriate and authorized business purposes.
- Sensitive, confidential, proprietary, personal, or regulated information should not be entered into, made accessible to, or processed by an AI system unless the system, data access, and applicable use case have been appropriately reviewed and authorized.
- AI-generated content, recommendations, decisions, and actions should be subject to review and safeguards appropriate to the nature and risk of the use case, including applicable legal, privacy, security, contractual, and regulatory requirements.
- AI systems should be configured and used in a manner designed to limit access to data, applications, tools, and functionality to what is appropriate for the authorized purpose.
Responsible Use of AI
- AI must be used responsibly and ethically and in accordance with applicable Company policies, laws, contractual obligations, and ethical standards.
- Users must not use, configure, direct, or permit AI to engage in unlawful, unauthorized, deceptive, discriminatory, harmful, or otherwise prohibited activities.
- Users must not use AI in a manner reasonably likely to harm AvePoint, its customers, partners, personnel, or reputation.
- Proprietary source code must not be submitted to or made accessible by an AI system unless the system and use case have been approved through applicable privacy, security, legal, and risk review processes.
- AI-generated code and other output should be appropriately reviewed and tested before use, taking into account accuracy, security, intellectual-property, licensing, and other applicable risks.
- AI must not be represented as having authority to bind AvePoint, make commitments on behalf of AvePoint, or give final legal, financial, employment, security, compliance, or other material determinations unless expressly authorized and subject to appropriate safeguards.
- Engineers must not submit proprietary source code to AI systems unless the system and use case have been approved through applicable privacy, security, legal, and risk review processes.
- Engineers should appropriately review and test AI-generated code before use and should consider potential intellectual property, licensing, security, and confidentiality implications associated with such code.
- AI-generated content must be appropriately reviewed before external, commercial, or other material use, including for applicable intellectual-property, accuracy, confidentiality, privacy, and contractual considerations. Legal review should be obtained where appropriate.
Agentic AI
Agentic AI refers to an AI system that can pursue objectives or perform tasks by planning or executing one or more steps, including by accessing data, using tools, interacting with applications or other AI systems, making recommendations or decisions, or taking actions with varying levels of human direction or supervision. Because Agentic AI may take actions or interact with systems on behalf of users or AvePoint, its use should be subject to safeguards proportionate to the nature, autonomy, access, and potential impact of the applicable use case. Such safeguards may include:
- appropriate review and authorization before deployment or material expansion of capabilities;
- a defined business purpose and accountable owner;
- access controls and permissions appropriate to the agent’s authorized purpose;
- appropriate human oversight for consequential, sensitive, high-impact, or difficult-to reverse actions;
- testing and evaluation before deployment and following material changes;
- logging, monitoring, and review appropriate to the agent’s activities and risk;
- measures designed to prevent or limit unauthorized actions, data disclosure, misuse, or unintended delegation; and
- processes for modification, suspension, incident response, and retirement.
Agentic AI must not be used to circumvent Company approvals, access restrictions, security controls, segregation-of-duties requirements, or other safeguards applicable to the underlying activity.
Data Retention and Deletion
- Data generated, accessed, collected, or otherwise processed through AI must be retained in accordance with applicable legal, contractual, and Company retention requirements, and should not be retained longer than necessary for the authorized purpose.
- AI-generated records and records of AI or agent activity should be managed in accordance with applicable record-retention, deletion, legal-hold, security, privacy, and audit requirements.
- AI systems and agents that are no longer authorized, supported, or required should be appropriately disabled, retired, or removed, subject to applicable recordkeeping and preservation requirements.
3. Responsible AI Governance
Governance Commitments
AvePoint’s responsible AI governance approach is designed to identify, assess, and manage AI related risks throughout the AI lifecycle. This includes attention to privacy, security, fairness, transparency, reliability, accountability, and human oversight.
- Risk Management: AvePoint evaluates AI systems and use cases to identify potential risks and implement safeguards appropriate to their intended purpose, capabilities, autonomy, data access, and potential impact.
- Privacy and Security: AvePoint applies privacy and security considerations to AI systems, agents, data, integrations, tools, permissions, and related processes.
- Accountability and Ownership: AvePoint supports appropriate accountability for AI systems and agents, including ownership and governance responsibilities proportionate to the use case.
- Fairness and Transparency: AvePoint seeks to reduce inappropriate bias and support understandable and accountable AI interactions and outcomes.
- Human Oversight: AvePoint supports appropriate human review, intervention, and oversight for AI-enabled processes, especially where an AI system may make or materially influence consequential decisions or take significant actions.
- Reliability and Safety: AvePoint supports risk-based testing, evaluation, monitoring, and safeguards intended to promote reliable operation and reduce unintended or harmful outcomes.
- Access and Action Controls: AvePoint supports controls appropriate to the data, systems, tools, and actions available to AI systems and agents.
- Lifecycle Management: AvePoint supports governance throughout the AI lifecycle, including review, deployment, monitoring, modification, incident response, and retirement, as appropriate.
- Continuous Improvement: AvePoint monitors developments in AI technology, laws, practices, standards, and risks, and updates governance measures as appropriate.
4. AI System Types
AI systems may have different or overlapping capabilities and levels of autonomy. Generative AI refers to AI that can create or assist with content such as text, images, code, summaries, recommendations, or other outputs.
Agentic AI refers to AI that can pursue objectives or perform tasks through one or more steps, including by planning, accessing information, using tools, interacting with applications or other AI systems, or taking actions with varying levels of human direction or supervision.
An AI system may be both Generative AI and Agentic AI. AvePoint considers the specific use case, capabilities, data access, integrations, autonomy, and potential impact when determining appropriate review and safeguards.
5. Guiding Principles
AvePoint’s responsible AI approach is guided by the following principles:
AvePoint’s Responsible AI policy is grounded in the following principles, inspired by NIST’s RMF for AI:
- Accountability: Maintaining appropriate human and organizational responsibility for AI systems, agents, decisions, actions, and outcomes.
- Transparency: Supporting clear, understandable information about AI interactions, capabilities, limitations, and use where appropriate.
- Fairness: Working to reduce inappropriate bias and promote equitable outcomes.
- Security and Control: Protecting data and applying safeguards appropriate to the data, permissions, tools, integrations, and actions available to AI systems and agents.
- Reliability and Safety: Supporting dependable AI systems and agents and reducing the risk of unintended, unsafe, unauthorized, or harmful interactions and outputs.
- Human-Centered Design: Using AI to support people and business objectives, while preserving appropriate human judgment, intervention, and accountability.