Introduction
This Artificial Intelligence Addendum (“Addendum”) is incorporated by reference in the Agreement (defined in the EUSA). If there is a conflict between this Addendum and the Agreement, this Addendum shall control with respect to the subject matter herein. Any defined terms used but not defined herein shall have the meaning given in the Agreement.
1. Definitions
“AI” means machine-based systems, programs or product features in the Products that: (a) are designed to operate with varying levels of autonomy; (b) may exhibit adaptiveness after deployment; (c) for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
“AI Law” means any law or regulation specifically governing artificial intelligence technologies that are in the Products and that are applicable to Zscaler as the provider of the Products in the jurisdictions where Zscaler provides the Products, including the EU AI Act.
2. Artificial Intelligence
2.1. Customer acknowledges that Zscaler uses AI in the Products.
2.2. Zscaler shall not, without prior consent from Customer, use Customer Data or Customer's Personal Data to create, develop, fine-tune, or train any AI, except for the sole purpose of providing the Products to Customer.
2.3. Zscaler shall:
(a) ensure that prior to deployment, the AI has been:
(i) tested by Zscaler to ensure that it performs in a manner consistent with its intended purposes; and
(ii) assessed by Zscaler to ensure that it complies with AI Law.
(b) implement and maintain an appropriate security risk management system in relation to the AI in accordance with Section 10.2 of the Agreement;
(c) take reasonable steps in accordance with good industry practice to mitigate the risk that the AI will return or provide any output which is unlawful; and
(d) upon written request, provide Customer with reasonable assistance and information about the AI in response to a regulatory body’s inquiry about the AI used in the Products. Customer acknowledges and agrees that the foregoing obligation does not require Zscaler to disclose its proprietary business processes, trade secrets, source code, or other Confidential Information unless legally compelled or regulatorily required under applicable AI Law.
2.4. Zscaler shall comply with AI Law, including informing users when they are interacting directly with an AI chatbot.
2.5. Zscaler and Customer shall each:
(a) use the AI in the Software and SaaS responsibly and ethically at all times; and
(b) not use the AI in the Software or SaaS in any way that may damage the reputation of the other party.
2.6. Customer acknowledges that, due to the nature of AI:
(a) output generated by AI may not be wholly unique and the AI may generate the same or similar output for other customers; and
(b) Zscaler gives no representation or warranty that the AI-generated output will be correct, complete or appropriate. Customer is solely responsible for verifying the output before taking or refraining from taking any action.
2.7. Customer further acknowledges that Zscaler Products are intended and designed to provide cyber security and related services. Zscaler Products are not designed nor intended for use as a safety component of any product or equipment, or for any purpose requiring fail-safe performance or hazardous application for which failure could result in significant risk of death, personal injury, illnesses, or severe physical, property, or environmental damage (each a “High Risk Activity”). In addition, Zscaler Products are not designed nor intended for any purpose involving the assessment of an individual’s access to, or the terms of, education, employment, financial or legal services, insurance, healthcare, or any other public benefits or essential services.