Policy on the Responsible and Ethical Use of Artificial Intelligence (AI)

Artificial Intelligence (AI) has become an integral tool in supporting organizational operations, enabling more efficient information retrieval, data analysis, content generation, language translation, and a wide range of other work-related activities. While AI offers significant opportunities to enhance productivity and innovation, its use may also pose potential risks relating to the accuracy and reliability of information, confidentiality, privacy, intellectual property rights, and organizational reputation if not used and governed appropriately.

To promote the responsible adoption of AI, Health Intervention and Technology Assessment Program Foundation (HITAP) has established this AI Policy to provide a governance framework for the ethical, transparent, secure, and accountable use of AI. This Policy aims to ensure that the use of AI is consistent with applicable laws and regulations, professional standards, research ethics, and HITAP’s internal policies. This policy will be reviewed and updated annually or whenever significant changes occur in AI technologies, to reflect developments in AI technologies, evolving best practices, and changes in applicable laws, regulations, and HITAP policies.

Purpose

This Policy describes the principles governing the use of AI by personnel of HITAP. It aims to promote the responsible, ethical, effective, and efficient use of AI in research, administration, operational activities, and other work-related functions, while ensuring appropriate governance, accountability, and compliance with applicable legal, ethical, and organizational requirements.

Scope

This Policy applies to all HITAP employees (including full-time and part-time employees) and interns. HITAP strongly encourages external parties performing work for or providing services to HITAP to follow the principles of this Policy, as appropriate.

This Policy covers the use of all AI systems and services, including those provided, approved, or developed by HITAP, as well as AI solutions provided by third-party service providers that are used for work-related activities.

For the purposes of this Policy, “AI systems” include, but are not limited to, Generative AI, Machine Learning systems, AI Assistants, AI Agents, and any other AI-enabled technologies used to generate, analyze, process, summarize, translate information, or support decision-making.

1) Principles for the Use of Artificial Intelligence (AI)

HITAP encourages the responsible use of AI to enhance productivity, improve operational efficiency, and support work-related activities. The use of AI shall be governed by the following principles:

 

1.1) AI for Work-Related Activities

  • Personnel may use AI to support information retrieval, data analysis, summarization, translation, document drafting, and other work-related activities, provided that such use serves the interests of HITAP and complies with applicable laws, regulations, and HITAP’s policies.

1.2) Ethical, Transparent, and Fair Use

  • AI shall be used in an ethical, transparent, and fair manner. Personnel should be able to explain or disclose the use of AI where appropriate and must not use AI in any manner that violates applicable laws, intellectual property rights, individual rights, or relevant ethical principles.
  • The use of AI must not compromise research integrity, research ethics, intellectual property rights, or the requirements of funding agencies, publishers, or other relevant organizations.
  • Personnel must not misrepresent AI-generated content or outputs as solely their own work. Where appropriate, or where required by applicable policies, regulations, or contractual obligations, the use of AI should be appropriately disclosed.
  • AI must not be used to create, disseminate, or facilitate false, misleading, deceptive, or harmful information, or in any manner that may cause harm to individuals, HITAP, or the public.
  • The use of AI shall take into account its potential impacts on individuals, the organization, and society. In particular, AI applications that may affect individuals’ rights, privacy, safety, or decisions affecting individuals, AI-generated outputs shall be reviewed by a human before being used to support decision-making.

1.3) Human Accountability and Ownership

  • AI is a tool to support, not replace, human judgment and decision-making. Personnel remain fully accountable for the outputs, decisions, actions, and consequences arising from the use of AI. Users are responsible for exercising professional judgment and ensuring that AI-generated outputs are accurate, complete, appropriate, and fit for their intended purpose before they are used, shared, published, or relied upon in decision-making.
  • Any work, document, report, or other material created in the course of performing duties for HITAP, whether produced solely by personnel or with the assistance of AI, shall be regarded as work created for the benefit of HITAP. Ownership and intellectual property rights in such work shall be governed by HITAP’s applicable policies and requirements.

1.4) Accuracy and Reliability

  • Personnel must critically review and verify the accuracy, completeness, appropriateness, and reliability of AI-generated outputs before using, publishing, sharing, or relying on them for decision-making.

1.5) Data Protection and Confidentiality

  • Personnel shall protect confidential information, personal data, and other sensitive information when using AI, and comply with applicable laws, including the Personal Data Protection Act (PDPA), and HITAP policies relating to data protection, confidentiality, and information security.

1.6) AI Awareness and Capability Development

  • HITAP encourages personnel to continuously develop their AI knowledge and skills to ensure that AI is used effectively, responsibly, and with an appropriate understanding of its capabilities and limitations.

2) Principles for the Use of Artificial Intelligence (AI) in Research and Academic Activities

The use of AI in research and academic activities shall be consistent with the principles of research integrity, research ethics, and other applicable professional standards. Researchers are expected to adhere to the following principles:

2.1) AI as a Research Support Tool

  • HITAP supports the responsible use of AI as a tool to enhance the efficiency and quality of research activities. AI may be used to assist with information retrieval, literature review, data analysis, knowledge synthesis, idea generation, and the preparation of academic documents. Researchers remain fully responsible for the research process, research outputs, interpretations, conclusions, and any decisions arising from the use of AI.

2.2) Transparency in the Use of AI

  • Where AI has made a significant contribution to the preparation of research outputs, reports, or academic work, researchers shall disclose the use of AI in accordance with the requirements of funding agencies, publishers, regulatory bodies, or HITAP’s policies. In the absence of specific requirements, researchers should disclose the use of AI where appropriate.

2.3) Accuracy and Reliability

  • Researchers must critically evaluate and verify the accuracy, completeness, reliability, and validity of AI-generated information, references, analyses, and outputs before incorporating them into research or academic work. Researchers are expected to exercise professional judgment when interpreting AI-generated outputs and apply appropriate scholarly methods to validate research findings.

2.4) Research Ethics

  • Researchers shall use AI in accordance with the principles of research ethics, fairness, respect for privacy, intellectual property rights, and responsible research practices. They should also consider potential risks associated with data bias, as well as the possible impacts of AI on research participants, stakeholders, and society.

3) Data Protection and Confidentiality

3.1) Data Protection and Information Security

  • The use of AI shall be conducted with due regard for data protection, personal privacy, and information security. All personnel must comply with applicable laws, regulations, and HITAP’s policies relating to data protection and information security.

3.2) Protection of Confidential and Personal Information

  • Personnel must not input confidential information, personal data, sensitive personal data, or information subject to disclosure restrictions into any AI system unless the AI system has been approved by HITAP and such use complies with applicable laws, including PDPA where applicable, and HITAP policies.

3.3) Consultation

  • Where there is any uncertainty regarding data protection, information security, or compliance with applicable laws or HITAP’s policies, personnel must consult their Head of Units or immediate supervisor before proceeding.

4) Reporting of AI Incidents and Risks

  • Personnel should promptly report any AI-related incidents, risks, or concerns to their Head of Unit or immediate supervisor to enable appropriate assessment and response. Such incidents may include, but are not limited to:
    • inappropriate input of confidential or personal data into AI systems;
    • data leakage through AI;
    • use of AI that may violate applicable laws, ethical principles, or HITAP policies; or
    • other incident that may adversely affect information security or HITAP
  • HITAP encourages personnel to report AI-related incidents, risks, or concerns in good faith. Personnel who make reports in good faith will be treated fairly and will not be subject to retaliation or any adverse consequences as a result of such reporting. This protection does not apply to reports that are knowingly false or made with malicious intent.

5) Governance and Policy Review

5.1) Communication and AI Capability Development

  • HITAP shall communicate this Policy to all personnel and promote awareness, understanding, and responsible AI practices through training, internal communications, and other appropriate capacity-building activities.

5.2) Standard Practices and Supplementary Guidance

  • HITAP may establish, revise, or issue Standard Practices, standards, or supplementary guidance relating to the use of AI to reflect changes in applicable laws, emerging technologies, and operational requirements. Such documents shall form part of HITAP’s AI governance framework and support the implementation of this Policy.

5.3) Policy Review

  • HITAP shall review and update this Policy annually or whenever significant changes occur in AI technologies, applicable laws, regulations, HITAP policies, or relevant standards, to ensure that the Policy remains appropriate, up to date, and aligned with HITAP’s operational context.

5.4) Roles and Responsibilities

  • All personnel share responsibility for supporting and complying with this AI Policy. HITAP designates the Information Technology (IT) Team under the Administration Unit, in collaboration with Management Team, to oversee the governance of AI within HITAP. Their responsibilities include reviewing and approving AI systems for organizational use, developing and periodically reviewing the AI Standard Practices, and monitoring and promoting compliance with this policy.

6) Policy Compliance

All personnel are required to comply with this Policy and any related Standard Practices. All personnel are required to complete the “Artificial Intelligence (AI) Policy Acknowledgement and Agreement” form online. Failure to comply with this Policy may result in actions in accordance with HITAP’s applicable policies, procedures, and regulations, and may also be taken into consideration in performance evaluations, as appropriate.

Effective on 20th July 2026