Prima — Export Compliance Policy · PC-ECP-001 · A4
PRIMA
Operating as
PetroCompute AI
Corporate Compliance Manual — Document 1 of 10

Export Compliance Policy

Prima Artificial Intelligence LLC, operating as PetroCompute AI. The foundational document of the Company’s Corporate Compliance Manual, governing the procurement, deployment and operation of advanced computing infrastructure.
Document IDPC-ECP-001
Version1.0 (Draft for Board approval)
Effective Date[●] 2026
Document OwnerChief Compliance Officer (Head of Corporate Governance)
Approved ByChairman & Chief Executive Officer
ClassificationInternal — Confidential
Next Scheduled ReviewAnnually from Effective Date
Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 1 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001
Contents

Table of Contents

Policy
  1. 1Purpose03
  2. 2Scope03
  3. 3Policy Statement04
  4. 4Regulatory Framework05
  5. 5Application to the Company’s Business06
  6. 6Governance and Responsibilities07
  7. 7Restricted Party Screening08
  8. 8End Use and End User Controls08
  9. 9Customer Due Diligence09
  10. 10Investor and Ownership Due Diligence09
  11. 11Red Flags10
  12. 12Licenses, Authorizations, and Government Interaction10
  13. 13Recordkeeping10
  14. 14Training and Awareness11
  15. 15Reporting of Concerns; No Retaliation11
  16. 16Monitoring, Audit, and Review11
  17. 17Violations and Disciplinary Action11
  18. 18Policy Administration11
Annexes
  1. ADefinitions12
  2. BCorporate Compliance Manual: Related Documents13
  3. CEmployee Compliance Acknowledgement14
  4. DRegister of Covered Entities15
Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 2 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

1Purpose

This Export Compliance Policy (the “Policy”) establishes the principles, governance structure, and mandatory controls through which Prima Artificial Intelligence LLC and its Covered Entities (together, the “Company”) comply with applicable export control and trade sanctions laws in connection with the procurement, deployment, and operation of advanced computing infrastructure, including graphics processing units (“GPUs”) and associated high-performance computing (“HPC”) and artificial intelligence (“AI”) systems.

The Company procures advanced computing hardware of United States origin through its suppliers and integration partners and operates that hardware as data center infrastructure in the Sultanate of Oman. As a participant in a U.S.-origin supply chain, the Company is subject to obligations arising under the U.S. Export Administration Regulations and related sanctions regimes, and undertakes contractual compliance commitments toward its suppliers. This Policy is the foundational document of the Company’s Corporate Compliance Manual and is supplemented by the related policies, procedures, and forms listed in Annex B.

2Scope

2.1Entities Covered

This Policy applies to Prima Artificial Intelligence LLC, a limited liability company incorporated in the Sultanate of Oman (Commercial Registration No. 1575008), with its registered establishment in the Special Economic Zone at Duqm, Al Wusta Governorate, and to each entity that Prima Artificial Intelligence LLC directly or indirectly controls, including entities operating under the PetroCompute AI name (each a “Covered Entity”). The Chief Compliance Officer shall maintain a current register of Covered Entities as Annex D to this Policy.

Where an affiliate, shareholder entity, or joint venture is not controlled by the Company but acts on the Company’s behalf in connection with the procurement, financing, deployment, or operation of controlled items, the Company shall use reasonable contractual and practical measures to require conduct consistent with this Policy.

2.2Persons Covered

This Policy applies to all directors, officers, employees, secondees, and contract personnel of every Covered Entity, and, to the extent provided by contract, to agents, consultants, brokers, freight forwarders, and other third parties acting for or on behalf of the Company (together, “Personnel”). Compliance with this Policy is a condition of employment and of engagement.

2.3Activities Covered

This Policy governs, without limitation: (a) the purchase, import, receipt, custody, and installation of controlled hardware, software, and technology; (b) any transfer, resale, re-export, or in-country transfer of such items; (c) the provision of compute, hosting, cloud, or colocation services using such items; (d) the onboarding of customers, suppliers, investors, lenders, and partners; and (e) the handling of technical data related to controlled items.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 3 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

3Policy Statement

It is the policy of the Company to conduct all activities in full compliance with applicable export control and economic sanctions laws and regulations, including those of the United States, the Sultanate of Oman, and any other jurisdiction whose laws apply to the Company’s transactions. The Company will not participate in any transaction, and will not permit its infrastructure to be used in any manner, that it knows or has reason to know would violate such laws, would circumvent licensing requirements, or would result in the diversion of controlled items or controlled compute capacity to prohibited destinations, entities, individuals, or end uses.

No business objective, commercial opportunity, or instruction from any manager, customer, investor, or counterparty justifies a departure from this Policy. Any Personnel who are instructed to act contrary to this Policy must refuse and report the instruction in accordance with Section 15.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 4 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

4Regulatory Framework

The Company’s compliance obligations arise principally under the following regimes. The Chief Compliance Officer monitors regulatory developments and updates this Policy and the related procedures as requirements evolve.

4.1United States Export Controls

  • The Export Administration Regulations (15 C.F.R. Parts 730–774) (“EAR”), administered by the U.S. Department of Commerce, Bureau of Industry and Security (“BIS”), which govern exports, re-exports, and in-country transfers of U.S.-origin items and certain foreign-produced items, including advanced computing integrated circuits and computers classified under Export Control Classification Numbers in Categories 3 and 4 of the Commerce Control List (including ECCNs 3A090 and 4A090 and related software and technology entries), as amended from time to time;
  • BIS licensing policies, license conditions, and end-use and end-user controls applicable to advanced computing items destined for, or deployed in, the Sultanate of Oman and the wider Middle East region, including any conditions attached to specific licenses under which hardware operated by the Company was exported;
  • BIS restricted party lists, including the Entity List, the Denied Persons List, the Unverified List, and the Military End User List.

4.2United States Sanctions

  • Economic and trade sanctions programs administered by the U.S. Department of the Treasury, Office of Foreign Assets Control (“OFAC”), including the Specially Designated Nationals and Blocked Persons List (“SDN List”), sectoral sanctions, and comprehensive embargoes applicable to designated countries and regions.

4.3Other Applicable Regimes

  • United Nations Security Council sanctions;
  • Sanctions and export control measures of the European Union and the United Kingdom, to the extent applicable to the Company’s counterparties, financing, insurance, or logistics arrangements;
  • The laws and regulations of the Sultanate of Oman, including customs and import regulations and the regulatory framework of the Special Economic Zone at Duqm, and the laws of any other jurisdiction in which a Covered Entity operates, including the State of Kuwait and the United Arab Emirates.

Where regimes differ, the Company applies the strictest applicable standard. Apparent conflicts of law must be escalated to the Chief Compliance Officer before any action is taken.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 5 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

5Application to the Company’s Business

5.1The Company’s Position in the Export Chain

The Company is the end user and operator of the advanced computing infrastructure deployed at its Oman facilities. The Company does not act as a distributor, reseller, or re-exporter of controlled hardware. Hardware received by the Company remains under the Company’s custody and control at the licensed deployment site and may not be sold, leased out of the facility, transferred, re-exported, or relocated — including within Oman — without the prior written approval of the Chief Compliance Officer and, where required, authorization from BIS or compliance with the conditions of the applicable export license.

5.2License Conditions

Advanced computing items of the classes deployed by the Company (including NVIDIA Blackwell-generation systems) are typically exported to Oman under specific BIS licenses obtained by the exporter, which may impose conditions on the Company as consignee and end user. The Company shall: (a) obtain and retain copies of all applicable license conditions communicated by its suppliers; (b) implement each condition as an operational control; (c) certify compliance to suppliers where required; and (d) treat any breach of a license condition as a reportable incident under the Incident Reporting Policy (PC-INC-009).

5.3Controlled Compute Services

The Company recognizes that regulatory controls extend beyond physical hardware to the provision of computing capacity itself. Access to the Company’s GPU clusters — whether through bare-metal, virtualized, cloud, or colocation arrangements — may enable third parties to perform activities (such as training large AI models) that are subject to end-use and end-user restrictions. Accordingly, no customer may be granted access to the Company’s compute infrastructure until the customer has completed onboarding under the KYC / Customer Due Diligence Policy (PC-KYC-003) and the End User Verification Procedure (PC-EUV-008), and has executed an End User Declaration.

5.4Technology and Deemed Transfers

Controlled technology includes technical data required for the development, production, or use of controlled items (for example, certain vendor documentation, firmware, and configuration data). The release of controlled technology to a foreign national may itself constitute a controlled event under the EAR. Personnel must not share vendor-controlled technical documentation outside the Company, and must consult the Chief Compliance Officer before granting facility access, remote system access, or documentation access to any third party or to any new category of personnel.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 6 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

6Governance and Responsibilities

6.1Board of Directors

The Board of Directors bears ultimate responsibility for the Company’s compliance culture. The Board approves this Policy, receives compliance reports at least annually, approves the appointment of the Chief Compliance Officer, and is informed without delay of any material compliance incident.

6.2Chairman & Chief Executive Officer

The Chairman & Chief Executive Officer (currently Ammar Taiyeb Ali Laskarwala) sets the tone from the top, ensures that the compliance function is adequately resourced and independent, and ensures that commercial objectives are never pursued at the expense of compliance.

6.3Chief Compliance Officer

The Head of Corporate Governance (currently Carson Smith) is designated as the Company’s Chief Compliance Officer (“CCO”). The CCO reports functionally to the Board and administratively to the Chief Executive Officer, and has the authority to suspend or block any transaction pending compliance review. The CCO is responsible for:

  • maintaining, interpreting, and updating this Policy and the related documents listed in Annex B;
  • overseeing restricted party screening, customer and investor due diligence, and end-user verification;
  • approving or escalating transactions that present red flags;
  • managing the training program and maintaining training and acknowledgement records;
  • liaising with suppliers, legal counsel, and — where required — regulators on export compliance matters;
  • investigating reported concerns and directing remediation.

6.4Chief Commercial Officer

The Chief Commercial Officer (currently Anton Zadorozhnyi) ensures that all commercial engagements — customer contracts, capacity sales, financing, and investor discussions — are routed through the applicable due diligence procedures before commitments are made, and that no binding commitment is entered into with a counterparty that has not cleared screening.

6.5All Personnel

Every member of Personnel is responsible for understanding this Policy as it applies to their role, completing required training, executing the Employee Compliance Acknowledgement (Annex C), raising concerns promptly, and refusing to proceed with any activity they believe may violate this Policy.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 7 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

7Restricted Party Screening

Before entering into any relationship, and periodically thereafter, the Company screens counterparties — including customers, suppliers, logistics providers, banks, investors, ultimate beneficial owners, directors, and key personnel of counterparties — against applicable restricted party lists, including at minimum: the OFAC SDN List and other OFAC lists; the BIS Entity List, Denied Persons List, Unverified List, and Military End User List; the U.S. State Department proliferation-related lists; and the consolidated sanctions lists of the United Nations, the European Union, and the United Kingdom.

Screening is conducted, documented, and adjudicated in accordance with the Sanctions Screening Procedure (PC-SSP-004). A confirmed match, or an unresolved potential match, results in an immediate hold on the relationship or transaction pending the CCO’s determination. No Personnel may override a screening hold.

8End Use and End User Controls

The Company must know, for every deployment of its compute capacity, who the end user is and what the end use will be. The End User Verification Procedure (PC-EUV-008) sets out how end users are identified, verified, and monitored, including in multi-tenant and intermediated arrangements where the contracting customer is not the ultimate consumer of compute.

The Company prohibits, and will not knowingly support, any end use involving:

  • nuclear, chemical, or biological weapons, or missile delivery systems, or any other weapons of mass destruction application;
  • military end uses or military end users of countries subject to relevant EAR restrictions, and military-intelligence end uses and end users;
  • any use by or for the benefit of a person or entity on a restricted party list, or located in, organized under the laws of, or ordinarily resident in a comprehensively sanctioned jurisdiction;
  • circumvention of export controls, including remote access schemes designed to provide controlled compute capacity to restricted persons or destinations;
  • any end use prohibited by a condition of the export license under which the relevant hardware was supplied.

Customers must execute an End User Declaration before service commencement and must contractually commit to notify the Company of any change in end use or end user. Material changes trigger re-verification.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 8 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

9Customer Due Diligence

No customer is onboarded, and no capacity contract becomes effective, until the customer has completed due diligence under the KYC / Customer Due Diligence Policy (PC-KYC-003). Due diligence covers, at minimum: corporate identity and registration; ownership and control, including identification of ultimate beneficial owners under the Beneficial Ownership Procedure (PC-UBO-006); jurisdictional risk; sanctions and restricted party screening; the intended use of compute capacity; and an overall risk rating that determines the level of ongoing monitoring. Enhanced due diligence applies to higher-risk profiles, including intermediaries, resellers of compute capacity, customers in higher-risk jurisdictions, and customers whose ownership is opaque.

10Investor and Ownership Due Diligence

Because the identity of the Company’s owners and controllers is material to its suppliers’ export licensing and to its own regulatory standing, the Company applies due diligence to its own capital structure, not only to its customers. In accordance with the Investor Due Diligence Policy (PC-IDD-005) and the Beneficial Ownership Procedure (PC-UBO-006), the Company shall:

  • identify and screen every direct and indirect shareholder meeting the Significant Investor threshold, every ultimate beneficial owner, and every director and authorized signatory of each Covered Entity;
  • maintain a complete and current record of its ownership chain, through all intermediate holding entities and jurisdictions, sufficient to demonstrate ownership and control to suppliers, banks, and regulators upon request;
  • screen prospective investors and lenders before accepting funds or issuing equity, and decline participation by restricted persons;
  • notify affected suppliers and, where required, regulators of material changes in ownership or control, and treat any undisclosed or unverifiable beneficial owner as a condition blocking the relevant transaction until resolved.
Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 9 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

11Red Flags

Personnel must be alert to indicators that a transaction may involve diversion, evasion, or a prohibited end use. Red flags include, without limitation:

  • a counterparty reluctant to provide end-user, end-use, or ownership information, or providing information that is inconsistent, incomplete, or unverifiable;
  • requests to structure access to compute capacity through intermediaries, nominees, or remote arrangements that obscure the actual user;
  • payment from, or routing through, third parties or jurisdictions unrelated to the counterparty’s business;
  • a customer’s stated business profile inconsistent with the scale or nature of compute capacity requested;
  • shipping, installation, or relocation requests inconsistent with the licensed deployment site;
  • pressure to close a transaction quickly in order to bypass due diligence, or offers of unusual compensation for doing so;
  • any suggestion that hardware or capacity is destined, directly or indirectly, for a sanctioned jurisdiction or restricted party.

A red flag does not automatically prohibit a transaction, but it prohibits proceeding without resolution. Personnel must escalate red flags to the CCO, who must document the inquiry and its resolution before the transaction may continue.

12Licenses, Authorizations, and Government Interaction

The Company procures controlled items only from suppliers authorized to export them to Oman, and only pursuant to valid licenses or applicable license exceptions determined by the exporter. The Company does not self-classify or self-license U.S.-origin items; where the Company’s own activities may require authorization (for example, a proposed transfer, relocation, or change of end use), the CCO shall engage qualified export controls counsel and, through the appropriate channel, BIS, before proceeding. All representations made by the Company in support of a supplier’s license application — including end-user statements and facility descriptions — must be accurate, complete, and approved by the CCO.

13Recordkeeping

The Company retains all records relevant to export compliance — including screening results and adjudications, due diligence files, end-user declarations, license conditions and related correspondence, shipping and customs documentation, contracts, invoices, training records, and acknowledgements — for a minimum of five (5) years from the later of the date of the record or the completion of the related transaction, or such longer period as required by the Record Retention Policy (PC-RRP-010) or applicable law. Records must be retrievable and producible in the event of a supplier audit or regulatory inquiry.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 10 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001

14Training and Awareness

All Personnel receive export compliance training upon onboarding and at least annually thereafter, with role-specific modules for commercial, technical operations, procurement, and finance functions, as set out in the Employee Compliance Training Program (PC-TRN-007). Completion is recorded in the training log, and each member of Personnel executes the Employee Compliance Acknowledgement (Annex C) upon onboarding and upon each material revision of this Policy.

15Reporting of Concerns; No Retaliation

Any member of Personnel who becomes aware of an actual, suspected, or attempted violation of this Policy — including a screening match, a red flag, a request to circumvent controls, false documentation, an undisclosed change in ownership, or a breach of a license condition — must report it promptly to the CCO or through the channels described in the Incident Reporting Policy (PC-INC-009). Reports may be made confidentially. The Company strictly prohibits retaliation against any person who reports a concern in good faith or participates in an investigation. The CCO shall assess every report, direct any necessary interim holds, investigate, document findings, and determine remediation, including — where warranted and on advice of counsel — disclosure to suppliers or regulators.

16Monitoring, Audit, and Review

The CCO performs periodic monitoring of screening operations, onboarding files, and access controls, and commissions an independent review of the export compliance program at least every two years or following any material incident. Audit findings and remediation plans are reported to the Board. This Policy is reviewed at least annually and upon any material change in law, in the Company’s ownership, or in the Company’s business model.

17Violations and Disciplinary Action

Violations of export control and sanctions laws can result in severe civil and criminal penalties for the Company and for individuals, loss of supplier relationships, denial of export privileges, and reputational harm. Violations of this Policy by Personnel will result in disciplinary action up to and including termination of employment or engagement, and may be referred to authorities where required. Third parties who violate compliance commitments face suspension or termination of their contracts.

18Policy Administration

This Policy is owned by the Chief Compliance Officer and approved by the Board of Directors. Deviations may be granted only by the CCO, in writing, with documented justification, and only where consistent with applicable law. Questions regarding this Policy should be directed to the CCO.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 11 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001
Annex A

Definitions

TermMeaning
BISThe Bureau of Industry and Security of the U.S. Department of Commerce.
Controlled ItemAny hardware, software, or technology subject to the EAR or other applicable export control regime, including advanced computing items classified under ECCNs 3A090 and 4A090 and related entries.
Covered EntityPrima Artificial Intelligence LLC and each entity it directly or indirectly controls, as listed in the register maintained under Section 2.1.
EARThe U.S. Export Administration Regulations, 15 C.F.R. Parts 730–774.
End UserThe person or entity that ultimately receives, uses, or benefits from a controlled item or from compute capacity provided using controlled items.
In-Country TransferA change in end use or end user of an item within the same foreign country.
OFACThe Office of Foreign Assets Control of the U.S. Department of the Treasury.
PersonnelDirectors, officers, employees, secondees, contract personnel, and covered third parties as described in Section 2.2.
Re-exportThe shipment or transmission of a controlled item from one foreign country to another.
Restricted PartyA person or entity appearing on any applicable sanctions or export control list identified in Section 7.
Significant InvestorAn investor meeting the thresholds defined in the Investor Due Diligence Policy (PC-IDD-005).
UBOUltimate beneficial owner, determined in accordance with the Beneficial Ownership Procedure (PC-UBO-006).
Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 12 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001
Annex B

Corporate Compliance Manual: Related Documents

This Policy is Document 1 of the Company’s Corporate Compliance Manual. The following related documents form an integrated system and are cross-referenced throughout this Policy.

Document IDTitleOwner
PC-ECP-001Export Compliance Policy (this document)CCO
PC-ISP-002Information Security PolicyCTO / CCO
PC-KYC-003KYC / Customer Due Diligence PolicyCCO
PC-SSP-004Sanctions Screening ProcedureCCO
PC-IDD-005Investor Due Diligence PolicyCCO
PC-UBO-006Beneficial Ownership ProcedureCCO
PC-TRN-007Employee Compliance Training ProgramCCO
PC-EUV-008End User Verification ProcedureCCO
PC-INC-009Incident Reporting PolicyCCO
PC-RRP-010Record Retention PolicyCCO

Associated forms: Employee Compliance Acknowledgement (Annex C to this Policy); KYC Checklist; Investor Screening Checklist; End User Declaration; Export Compliance Review Form; Training Log; Screening Adjudication Log.

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 13 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001
Annex C

Employee Compliance Acknowledgement

I acknowledge that I have received, read, and understood the Export Compliance Policy (PC-ECP-001) of Prima Artificial Intelligence LLC and its Covered Entities. I understand that:

  • the Company’s business involves items and services subject to export control and sanctions laws, including the U.S. Export Administration Regulations;
  • I must not participate in, facilitate, or ignore any transaction or activity that violates the Policy, and I must escalate red flags and refuse instructions that conflict with the Policy;
  • I must complete assigned compliance training and cooperate with compliance reviews and investigations;
  • I must promptly report actual or suspected violations through the channels described in the Policy, and that the Company prohibits retaliation for good-faith reporting;
  • violations of the Policy may result in disciplinary action up to and including termination, and may expose me and the Company to civil and criminal liability.
Full Name
Position / Department
Covered Entity
Date
Signature

Completed acknowledgements are retained by the Chief Compliance Officer in accordance with the Record Retention Policy (PC-RRP-010).

Prima Artificial Intelligence LLC · CR 1575008 Confidential Page 14 of 15
PRIMA
Export Compliance Policy  ·  PC-ECP-001
Annex D

Register of Covered Entities

Maintained by the Chief Compliance Officer pursuant to Section 2.1. Status as of the Effective Date:

EntityJurisdictionRelationship
Prima Artificial Intelligence LLC (CR No. 1575008)Oman (SEZ at Duqm)Parent / operating company
PetroCompute AI [legal entity details to be confirmed][●]Operating brand / subsidiary
[Other controlled subsidiaries, if any — to be confirmed][●][●]

Related entities in the ownership chain that are not controlled by the Company (including Prima Security General Trading Co. LLC, Kuwait, and Density AI LLC-FZ, UAE) are recorded and screened under the Investor Due Diligence Policy (PC-IDD-005) and the Beneficial Ownership Procedure (PC-UBO-006), and are covered by Section 2.1 to the extent they act on the Company’s behalf.