ThaiBev’s Sustainability 2025
Home / Governance & Economic
Artificial Intelligence

Data Security
and Privacy
Generative AI is an advanced artificial intelligence technology capable of creating a wide range of new content, such as text, images, reports, designs, and software code, by learning from vast amounts of data. This technology drives innovation and enhances organizational efficiency through capabilities such as summarizing large volumes of information, drafting professional documents, supporting creative thinking, and automating repetitive processes.

However, the adoption of Generative AI also entails significant risks, including cybersecurity threats, personal data protection issues, data accuracy concerns, intellectual property risks, and uncertainties arising from evolving legal and regulatory frameworks. Therefore, organizations and users must be aware of the need for responsible use, with due consideration given to security, compliance, and ethical principles, in order to fully realize the benefits of Generative AI while maintaining organizational trust and long-term sustainability.
Management Approach
The organization recognizes the role of Generative AI in driving innovation, enhancing operational efficiency, and strengthening competitiveness, while also acknowledging the associated risks related to cybersecurity, personal data protection, ethics, and compliance with applicable laws and regulations. To ensure that the adoption and use of Generative AI are appropriate and sustainable, the organization has established an AI Policy and AI Guideline as the primary governance framework for the development, procurement, and use of AI technologies within the organization.

The organization’s AI Policy defines key principles of transparency, accountability, security, and respect for individual rights. It requires that the use of AI must not violate personal data protection, intellectual property rights, or cause adverse impacts on stakeholders. The AI Guideline serves as a practical reference for employees and relevant parties, covering permitted and prohibited uses of AI, the protection of confidential and personal data, the validation of AI-generated outputs, and the avoidance of overreliance on AI without appropriate human judgment.

AI governance is integrated into the organization’s overall risk management, information technology, and cybersecurity frameworks. This includes conducting risk assessments prior to AI deployment, ensuring oversight by relevant functions, and regularly monitoring and reviewing AI usage. In addition, the organization promotes communication, awareness, and training to educate employees on the responsible use of Generative AI, ensuring that such technologies are leveraged to support business objectives while adhering strictly to ethical standards, security requirements, and legal and regulatory obligations.

AI Policy : https://sustainability.thaibev.com/download/ai_en.pdf
Key Projects
Secure AI Access Governance Process for Enterprise Infrastructure Systems
The company has established a governance process for the use of Microsoft Copilot in Active Directory (AD) and Network operations under the Responsible AI principle and in alignment with ISO/IEC 42001 guidelines. This process is built upon the existing security controls of the AD and Network environment, which has already been certified under ISO/IEC 27001. As part of “Limiting access to sensitive AI capabilities,” the organization restricts AI usage only to authorized Infrastructure and Cyber Security personnel. Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC) integrated with Active Directory are implemented to prevent unauthorized access to sensitive information. In addition, AI usage logs are continuously monitored and retained to support transparency, auditability, and traceability. These controls help reduce risks related to unauthorized access to configurations, scripts, and critical infrastructure data. The organization also defines measurable security indicators, including 100% MFA enforcement and quarterly access reviews, to support secure and sustainable AI governance across enterprise infrastructure operations.
  • Assign Microsoft Copilot access permissions through Active Directory based on user roles and responsibilities (RBAC)
  • Enable Multi-Factor Authentication (MFA) for all AI-related user accounts
  • Separate access permissions for AD, Network, and Script information according to data sensitivity levels
  • Collect and monitor AI usage logs to support audit and traceability requirements
  • Perform quarterly access reviews by the IT Governance and Cyber Security teams to ensure appropriate system access permissions

AI Output Labeling and Verification Process for Enterprise Infrastructure Operations
The company has established an AI output labeling and verification process for Microsoft Copilot used in Active Directory (AD) and Network operations under the Responsible AI principle and aligned with ISO/IEC 42001 guidelines. This process is supported by the organization’s existing ISO/IEC 27001-certified AD and Network security environment to ensure secure and transparent AI usage. As part of “Distinct labeling of AI-generated content and outcomes of AI-driven decisions,” all AI-generated outputs are clearly identified with AI-generated labels and verification notices before being applied to operational activities. The organization requires IT personnel to review and validate AI recommendations related to scripts, configurations, troubleshooting guidance, and network operations before implementation. In addition, AI activity logs and verification records are retained to support auditability, traceability, and operational transparency. These controls help reduce risks from inaccurate AI-generated recommendations and support reliable infrastructure management. The organization also monitors key indicators such as 100% AI output labeling compliance and mandatory human verification for all critical operational changes.
  • Configure AI-generated labels and warning messages for all Microsoft Copilot outputs related to AD and Network operations
  • Require IT administrators to validate AI-generated scripts, configurations, and recommendations before implementation
  • Record AI usage activities and verification results to support audit and traceability requirements
  • Store AI output history and operational review logs for compliance monitoring
  • Conduct periodic reviews by IT Governance and Cyber Security teams to ensure transparency and proper AI usage

AI Performance Monitoring and Continuous Improvement Process for Enterprise Infrastructure Operations
The company has established an AI performance monitoring and continuous improvement process for Microsoft Copilot used in Active Directory (AD) and Network operations under the Responsible AI principle and aligned with ISO/IEC 42001 guidelines. This process is supported by the organization’s ISO/IEC 27001-certified AD and Network environment to ensure that AI services remain accurate, secure, and operationally reliable over time. As part of “Mechanisms to detect and correct drift or degradation of AI models over time,” the organization continuously monitors AI-generated recommendations, troubleshooting guidance, scripts, and configuration outputs to identify inaccurate, outdated, or inconsistent responses. AI outputs are periodically reviewed through sampling, user feedback, operational validation, and incident analysis to ensure alignment with the organization’s infrastructure standards and operational procedures. When incorrect or degraded AI responses are identified, the organization updates prompts, revises knowledge sources, and improves operational guidance to reduce future inaccuracies. In addition, AI monitoring records and improvement activities are documented to support transparency, auditability, and continuous improvement. The organization also defines measurable indicators such as monthly AI accuracy reviews, error rate monitoring, and periodic improvement cycles to strengthen sustainable AI governance.
  • Monitor AI-generated recommendations, scripts, and troubleshooting guidance related to AD and Network operations on a regular basis
  • Perform periodic sampling reviews and validate AI outputs against operational standards and infrastructure procedures
  • Collect user feedback and analyze incidents related to incorrect or outdated AI-generated responses
  • Update prompts, knowledge sources, and operational guidance when AI performance degradation is identified
  • Record monitoring activities, improvement actions, and validation results to support audit and continuous improvement processes

AI Fairness and Bias Assessment Process for Enterprise Infrastructure Operations
The company has established an AI fairness and bias assessment process for Microsoft Copilot used in Active Directory (AD) and Network operations under the Responsible AI principle and aligned with ISO/IEC 42001 guidelines. This process is supported by the organization’s ISO/IEC 27001-certified AD and Network environment to ensure that AI-generated recommendations are reliable, transparent, and operationally appropriate for all users. As part of “Regular assessments of deployed AI models for fairness/bias,” the organization conducts periodic reviews of AI-generated outputs, including troubleshooting guidance, scripts, and configuration recommendations, to identify inconsistent, biased, or inappropriate responses. Assessment activities are performed using multiple operational scenarios involving Junior and Senior IT personnel to ensure that AI recommendations remain fair and aligned with organizational standards. The organization also reviews user feedback, incident records, and operational validation results to improve AI reliability and reduce the risk of misleading recommendations. For example, at least 10 operational scenarios are tested per quarter, with a target consistency rate of 90% or higher across different user groups. In addition, all assessment results and improvement activities are documented to support auditability, transparency, and continuous improvement processes.
  • Conduct periodic reviews of AI-generated troubleshooting guidance, scripts, and configuration recommendations related to AD and Network operations
  • Test AI outputs using multiple operational scenarios involving Junior and Senior IT personnel to evaluate fairness and consistency
  • Collect user feedback and analyze incidents related to inaccurate or potentially biased AI-generated recommendations
  • Review assessment results and improve prompts, operational guidance, and knowledge sources when inconsistencies are identified
  • Record assessment activities, consistency measurements, and improvement actions to support audit and transparency requirements

Sustainable AI Resource and Infrastructure Optimization Process
The company has established a sustainable AI resource and infrastructure optimization process for Microsoft Copilot used in Active Directory (AD) and Network operations under the Responsible AI principle and aligned with ISO/IEC 42001 guidelines. This process is supported by the organization’s ISO/IEC 27001-certified AD and Network environment to ensure secure, efficient, and environmentally responsible AI operations. As part of “Initiatives (own/with suppliers) to lower the ecological footprint of AI data centers/models,” the organization works with cloud service providers and internal IT teams to optimize AI resource usage, reduce unnecessary processing workloads, and improve operational efficiency. AI-related queries, troubleshooting requests, and operational workloads are monitored regularly to reduce excessive compute utilization and unnecessary AI processing activities. The organization also applies on-demand resource usage, scheduled workload optimization, and operational review processes to minimize energy consumption and improve sustainability performance. For example, the organization targets a 20% reduction in unnecessary AI queries and monitors infrastructure utilization during peak and off-peak periods. In addition, operational metrics, optimization activities, and sustainability improvement records are documented to support transparency, auditability, and continuous environmental improvement initiatives.
  • Monitor AI-related queries and operational workloads associated with AD and Network troubleshooting activities
  • Coordinate with cloud service providers and internal IT teams to optimize AI resource utilization and reduce unnecessary processing workloads
  • Apply on-demand AI resource allocation and workload scheduling to reduce energy consumption during off-peak periods
  • Review infrastructure utilization metrics and identify opportunities to improve operational efficiency and sustainability performance
  • Record sustainability metrics, optimization activities, and improvement results to support audit and environmental governance requirements

AI Incident Review and Appeals Management Process for Enterprise Infrastructure Operations
The company has established an AI incident review and appeals management process for Microsoft Copilot used in Active Directory (AD) and Network operations under the Responsible AI principle and aligned with ISO/IEC 42001 guidelines. This process is supported by the organization’s ISO/IEC 27001-certified AD and Network environment to ensure secure, transparent, and accountable AI operations. As part of “Appeals process for users/affected third parties to contest an AI decision or outcome,” the organization provides a formal mechanism for users and affected parties to report, challenge, or request reviews of AI-generated recommendations, troubleshooting guidance, scripts, and operational decisions. All reported issues are recorded through the IT Service Desk system and reviewed by Infrastructure, Cyber Security, or IT Governance personnel using a Human-in-the-loop approach before final operational actions are approved. The organization also analyzes incident records, user feedback, and operational impacts to improve AI reliability and reduce the risk of inaccurate recommendations. For example, all AI-related appeal requests are targeted to receive an initial response within 4 hours, and 100% of tickets are recorded and tracked for audit purposes. In addition, review results, corrective actions, and operational improvements are documented to support transparency, auditability, and continuous improvement activities.
  • Provide an official IT Service Desk channel for users or affected parties to report or appeal AI-generated recommendations and operational outcomes
  • Record and classify all AI-related incidents, complaints, and appeal requests for investigation and audit purposes
  • Perform Human-in-the-loop reviews by Infrastructure, Cyber Security, or IT Governance personnel before operational implementation
  • Analyze incident trends, user feedback, and operational impacts to improve AI reliability and reduce inaccurate recommendations
  • Document review results, corrective actions, SLA performance, and operational improvements to support transparency and continuous improvement

AI Sustainability Impact Measurement and Performance Evaluation Process
The company has established an AI sustainability impact measurement and performance evaluation process for Microsoft Copilot used in Active Directory (AD) and Network operations under the Responsible AI principle and aligned with ISO/IEC 42001 guidelines. This process is supported by the organization’s ISO/IEC 27001-certified AD and Network environment to ensure secure, measurable, and sustainable AI operations. As part of “Quantification of the impact of AI initiatives/tools on sustainability outcomes,” the organization measures the operational and sustainability benefits achieved through AI-assisted troubleshooting, operational analysis, and infrastructure support activities. Key performance indicators such as Mean Time to Resolution (MTTR), incident escalation reduction, operational productivity, and reduced onsite support activities are monitored regularly to evaluate AI effectiveness and sustainability outcomes. The organization also reviews operational reports, AI usage metrics, and support performance data to identify opportunities for continuous improvement and resource optimization. For example, the organization targets a 50% reduction in MTTR, a 30% decrease in incident escalations, and a 20% reduction in onsite support visits through AI-assisted operational support. In addition, sustainability performance records, operational metrics, and improvement activities are documented to support transparency, auditability, and long-term AI governance objectives.
  • Measure operational and sustainability performance indicators related to AI-assisted AD and Network support activities
  • Monitor key metrics such as MTTR, incident escalation rates, operational productivity, and onsite support reduction
  • Analyze AI usage reports and operational performance data to identify improvement opportunities and resource optimization initiatives
  • Review sustainability outcomes and operational efficiency improvements through periodic management reporting processes
  • Record sustainability metrics, operational results, and improvement activities to support audit and long-term AI governance objectives

AI Ethics and Security Awareness Training Process for Enterprise Infrastructure Operations
The company has established an AI ethics and security awareness training process for Microsoft Copilot used in Active Directory (AD) and Network operations under the Responsible AI principle and aligned with ISO/IEC 42001 guidelines. This process is supported by the organization’s ISO/IEC 27001-certified AD and Network environment to ensure that employees use AI securely, responsibly, and in accordance with organizational governance requirements. As part of “Training of employees on the ethical use and/or security of AI,” the organization provides regular training programs covering AI security awareness, ethical AI usage, data protection practices, and operational controls related to AD and Network environments. Employees are trained on topics such as preventing sensitive data exposure, validating AI-generated outputs, handling AI-assisted troubleshooting activities, and complying with organizational security policies. The organization also conducts knowledge assessments, operational workshops, and periodic refresher training sessions to improve employee awareness and reduce operational risks associated with AI usage. For example, all Infrastructure and Cyber Security personnel are required to complete AI awareness training annually with a minimum assessment score of 85%, while refresher training sessions are conducted at least twice per year. In addition, training records, assessment results, and awareness improvement activities are documented to support transparency, auditability, and continuous AI governance improvement.
  • Conduct AI ethics and security awareness training programs for Infrastructure and Cyber Security personnel involved in AD and Network operations
  • Provide guidance on secure AI usage, sensitive data protection, AI output validation, and compliance with organizational policies
  • Perform knowledge assessments and operational workshops to evaluate employee understanding and operational readiness
  • Organize periodic refresher training sessions and awareness communication activities to reinforce responsible AI practices
  • Record training participation, assessment results, and awareness improvement activities to support audit and continuous governance requirements


Read More Information about
Artificial Intelligence
in Sustainability Report 2025