AI ADDENDUM

This AI Addendum (“Addendum”) forms part of the Software and Services Agreement, order form, or statement of work (the “Agreement”) between Cority Software Inc. or its Affiliate (“Cority”) and the Client collectively identified in the Agreement (“Client”). All capitalized terms not otherwise defined herein will have the meaning given to them in the Agreement.

Last Update: March 11, 2026

1. Context, Purpose, and Scope

Cority has embedded enterprise-grade AI Systems developed by third-party licensors including, without limitation, Google and OpenAI for specific use cases within the software licensed under the Agreement. Cority therefore relies on the controls and governance mechanisms developed by such third-parties to satisfy regulatory requirements.

For a detailed list of third-party licensors that process Client data, please refer to our list of sub-processors at https://www.cority.com/legal-center/cority-sub-processors/.

This Addendum establishes mutual obligations, controls, and governance mechanisms for the use, development, deployment, or integration of artificial intelligence systems in connection with the Agreement. The Parties acknowledge that AI governance operates under a shared responsibility model.

2. Definitions

3. AI Credits and Consumption

In order to access AI functionality, Client must purchase AI System licenses and/or AI Credits through the Agreement. Once AI Credits are fully consumed, AI functionality will be automatically deactivated in order to prevent the Client from incurring unexpected overages. Client may purchase additional AI Credits to resume usage at any time and purchased AI Credits reset at the beginning of each twelve (12) month subscription period.

4. Professional Oversight & Non-Reliance

5. EU AI Act Compliance

Where either party is subject to the EU AI Act, the following obligations apply:

6. Standard of Input & Prohibited Content

Client agrees that all Input Data will meet the following standards:

7. Third-Party Terms (OpenAI & Google)

8. Warranties and IP Indemnity

9. Limitation of Liability

10. Shared Responsibility Matrix

Responsibility Area

Cority Obligations (Vendor / Integrator)

Client Obligations (Customer / Deployer)

Data Governance

Configuration & Privacy: Secure the API pipeline; ensure “Opt-Out” settings are active so Input is not used to train third-party global models without the Client’s prior consent.

Input Hygiene: Sanitize Input Data (PII/PHI) per internal policy; ensure legal right and consent to process data via third-party sub-processors.

Model Governance

Vetting & Integration: Select reputable sub-processors; provide documentation on intended use; implement moderation “wrappers” to filter out harmful content.

Validation & Suitability: Verify that the AI System is appropriate for the specific business use case; perform mandatory human review of all Output.

Security

Platform Security: Protect the Cority application environment; encrypt data in transit; monitor for system-level Prompt Injection and “jailbreak” attempts.

Endpoint & User Security: Secure user credentials and API keys; monitor for unauthorized user behavior or “malicious prompting” by internal staff.

Compliance

Systemic Compliance: Ensure the platform features meet statutory requirements (e.g., EU AI Act Provider rules); provide technical documentation for Client audits.

Operational Compliance: Ensure final use of Output complies with industry regulations (HIPAA, OSHA, etc.) and professional standards.

Transparency

Technical Disclosure: Disclose the identity of the underlying third-party models (e.g., GPT-4o, Gemini 1.5 Pro) and known probabilistic limitations.

User Notification: Notify end-users/natural persons when they are interacting with AI; label synthetic content as required by the EU AI Act (Art. 50).

Human Oversight

Control Mechanisms: Provide the technical interface allowing users to edit, override, or reject AI recommendations before they are finalized.

Independent Judgment: Maintain a “Human-in-the-Loop” for high-impact decisions; ensure no autonomous action is taken on probabilistic Output.

Accountability

Service Monitoring: Maintain records of system performance, sub-processor uptime, and security incidents at the platform level.

Audit Trails: Maintain records of how AI-assisted Outputs were used, reviewed, and approved to demonstrate responsible organizational use.

11. Data Privacy

(a) The Parties will comply with applicable data protection and privacy laws, including requirements governing automated decision-making.

(b) Client acknowledges that processing done by the AI System may occur in a different geographic region than the hosting location of the Software, subject to the security controls identified in the Agreement. For more information about where AI Systems are processing data, please refer to the list of sub-processors at https://www.cority.com/legal-center/cority-sub-processors/

13. Training

(a) No Client data will be used to train Foundational LLMs unless permitted by Client.

13. Prohibited Activities

Client will not use AI Systems, whether directly or indirectly, in connection with the Agreement for any unlawful, unethical, or prohibited purpose under applicable laws (“Prohibited Practices”). Prohibited Practices include, without limitation: (a) the generation or dissemination of misleading, deceptive, or fraudulent content; (b) infringement or misappropriation of intellectual property, trade secrets, or privacy rights; (c) discrimination, harassment, or other violations of applicable law; (d) manipulation of data or outcomes in a manner inconsistent with the purpose of this Agreement; and (e) any activity that may cause reputational, legal, or regulatory harm to either Party. Each Party will implement reasonable safeguards to ensure compliance with this provision and will promptly notify the other Party of any known or suspected breach.

14. Suspension and Termination

Cority reserves the right to immediately suspend or terminate access to the AI System, without liability, if Cority (or its third-party providers) identifies a pattern of safety violations, conduct violations (e.g., racist or derogatory content), or third-party policy breaches.

15. Usage Data and Service Improvements

Notwithstanding anything to the contrary in the Agreement, Cority may collect and analyze “Usage Data” (defined as technical logs, metadata, performance metrics, and patterns of use) derived from Client’s interaction with the AI Systems. Usage Data does not include Input Data or Output. Client agrees that Cority owns all right, title, and interest in such Usage Data and may use it to: (a) maintain, protect, and improve the AI System and the Software; (b) monitor for security threats or Prompt Injection; (c) develop aggregated, de-identified insights; (d) monitor consumption of AI Tokens. Cority will not use Usage Data in a manner that identifies Client or any natural person.

16. Change of Model Providers

Subject to Client’s right of objection under the data processing addendum where applicable, Cority reserves the right to modify or replace the underlying Foundational LLM and any third-party AI licensors, provided that such change does not materially diminish the security or functionality of the AI System.

17. Order of Precedence

In the event of a conflict between this Addendum and the Agreement, this Addendum will prevail.