| Document ID | PC-ECP-001 |
| Version | 1.0 (Draft for Board approval) |
| Effective Date | [●] 2026 |
| Document Owner | Chief Compliance Officer (Head of Corporate Governance) |
| Approved By | Chairman & Chief Executive Officer |
| Classification | Internal — Confidential |
| Next Scheduled Review | Annually from Effective Date |


This Export Compliance Policy (the “Policy”) establishes the principles, governance structure, and mandatory controls through which Prima Artificial Intelligence LLC and its Covered Entities (together, the “Company”) comply with applicable export control and trade sanctions laws in connection with the procurement, deployment, and operation of advanced computing infrastructure, including graphics processing units (“GPUs”) and associated high-performance computing (“HPC”) and artificial intelligence (“AI”) systems.
The Company procures advanced computing hardware of United States origin through its suppliers and integration partners and operates that hardware as data center infrastructure in the Sultanate of Oman. As a participant in a U.S.-origin supply chain, the Company is subject to obligations arising under the U.S. Export Administration Regulations and related sanctions regimes, and undertakes contractual compliance commitments toward its suppliers. This Policy is the foundational document of the Company’s Corporate Compliance Manual and is supplemented by the related policies, procedures, and forms listed in Annex B.
This Policy applies to Prima Artificial Intelligence LLC, a limited liability company incorporated in the Sultanate of Oman (Commercial Registration No. 1575008), with its registered establishment in the Special Economic Zone at Duqm, Al Wusta Governorate, and to each entity that Prima Artificial Intelligence LLC directly or indirectly controls, including entities operating under the PetroCompute AI name (each a “Covered Entity”). The Chief Compliance Officer shall maintain a current register of Covered Entities as Annex D to this Policy.
Where an affiliate, shareholder entity, or joint venture is not controlled by the Company but acts on the Company’s behalf in connection with the procurement, financing, deployment, or operation of controlled items, the Company shall use reasonable contractual and practical measures to require conduct consistent with this Policy.
This Policy applies to all directors, officers, employees, secondees, and contract personnel of every Covered Entity, and, to the extent provided by contract, to agents, consultants, brokers, freight forwarders, and other third parties acting for or on behalf of the Company (together, “Personnel”). Compliance with this Policy is a condition of employment and of engagement.
This Policy governs, without limitation: (a) the purchase, import, receipt, custody, and installation of controlled hardware, software, and technology; (b) any transfer, resale, re-export, or in-country transfer of such items; (c) the provision of compute, hosting, cloud, or colocation services using such items; (d) the onboarding of customers, suppliers, investors, lenders, and partners; and (e) the handling of technical data related to controlled items.

It is the policy of the Company to conduct all activities in full compliance with applicable export control and economic sanctions laws and regulations, including those of the United States, the Sultanate of Oman, and any other jurisdiction whose laws apply to the Company’s transactions. The Company will not participate in any transaction, and will not permit its infrastructure to be used in any manner, that it knows or has reason to know would violate such laws, would circumvent licensing requirements, or would result in the diversion of controlled items or controlled compute capacity to prohibited destinations, entities, individuals, or end uses.
No business objective, commercial opportunity, or instruction from any manager, customer, investor, or counterparty justifies a departure from this Policy. Any Personnel who are instructed to act contrary to this Policy must refuse and report the instruction in accordance with Section 15.

The Company’s compliance obligations arise principally under the following regimes. The Chief Compliance Officer monitors regulatory developments and updates this Policy and the related procedures as requirements evolve.
Where regimes differ, the Company applies the strictest applicable standard. Apparent conflicts of law must be escalated to the Chief Compliance Officer before any action is taken.

The Company is the end user and operator of the advanced computing infrastructure deployed at its Oman facilities. The Company does not act as a distributor, reseller, or re-exporter of controlled hardware. Hardware received by the Company remains under the Company’s custody and control at the licensed deployment site and may not be sold, leased out of the facility, transferred, re-exported, or relocated — including within Oman — without the prior written approval of the Chief Compliance Officer and, where required, authorization from BIS or compliance with the conditions of the applicable export license.
Advanced computing items of the classes deployed by the Company (including NVIDIA Blackwell-generation systems) are typically exported to Oman under specific BIS licenses obtained by the exporter, which may impose conditions on the Company as consignee and end user. The Company shall: (a) obtain and retain copies of all applicable license conditions communicated by its suppliers; (b) implement each condition as an operational control; (c) certify compliance to suppliers where required; and (d) treat any breach of a license condition as a reportable incident under the Incident Reporting Policy (PC-INC-009).
The Company recognizes that regulatory controls extend beyond physical hardware to the provision of computing capacity itself. Access to the Company’s GPU clusters — whether through bare-metal, virtualized, cloud, or colocation arrangements — may enable third parties to perform activities (such as training large AI models) that are subject to end-use and end-user restrictions. Accordingly, no customer may be granted access to the Company’s compute infrastructure until the customer has completed onboarding under the KYC / Customer Due Diligence Policy (PC-KYC-003) and the End User Verification Procedure (PC-EUV-008), and has executed an End User Declaration.
Controlled technology includes technical data required for the development, production, or use of controlled items (for example, certain vendor documentation, firmware, and configuration data). The release of controlled technology to a foreign national may itself constitute a controlled event under the EAR. Personnel must not share vendor-controlled technical documentation outside the Company, and must consult the Chief Compliance Officer before granting facility access, remote system access, or documentation access to any third party or to any new category of personnel.

The Board of Directors bears ultimate responsibility for the Company’s compliance culture. The Board approves this Policy, receives compliance reports at least annually, approves the appointment of the Chief Compliance Officer, and is informed without delay of any material compliance incident.
The Chairman & Chief Executive Officer (currently Ammar Taiyeb Ali Laskarwala) sets the tone from the top, ensures that the compliance function is adequately resourced and independent, and ensures that commercial objectives are never pursued at the expense of compliance.
The Head of Corporate Governance (currently Carson Smith) is designated as the Company’s Chief Compliance Officer (“CCO”). The CCO reports functionally to the Board and administratively to the Chief Executive Officer, and has the authority to suspend or block any transaction pending compliance review. The CCO is responsible for:
The Chief Commercial Officer (currently Anton Zadorozhnyi) ensures that all commercial engagements — customer contracts, capacity sales, financing, and investor discussions — are routed through the applicable due diligence procedures before commitments are made, and that no binding commitment is entered into with a counterparty that has not cleared screening.
Every member of Personnel is responsible for understanding this Policy as it applies to their role, completing required training, executing the Employee Compliance Acknowledgement (Annex C), raising concerns promptly, and refusing to proceed with any activity they believe may violate this Policy.

Before entering into any relationship, and periodically thereafter, the Company screens counterparties — including customers, suppliers, logistics providers, banks, investors, ultimate beneficial owners, directors, and key personnel of counterparties — against applicable restricted party lists, including at minimum: the OFAC SDN List and other OFAC lists; the BIS Entity List, Denied Persons List, Unverified List, and Military End User List; the U.S. State Department proliferation-related lists; and the consolidated sanctions lists of the United Nations, the European Union, and the United Kingdom.
Screening is conducted, documented, and adjudicated in accordance with the Sanctions Screening Procedure (PC-SSP-004). A confirmed match, or an unresolved potential match, results in an immediate hold on the relationship or transaction pending the CCO’s determination. No Personnel may override a screening hold.
The Company must know, for every deployment of its compute capacity, who the end user is and what the end use will be. The End User Verification Procedure (PC-EUV-008) sets out how end users are identified, verified, and monitored, including in multi-tenant and intermediated arrangements where the contracting customer is not the ultimate consumer of compute.
The Company prohibits, and will not knowingly support, any end use involving:
Customers must execute an End User Declaration before service commencement and must contractually commit to notify the Company of any change in end use or end user. Material changes trigger re-verification.

No customer is onboarded, and no capacity contract becomes effective, until the customer has completed due diligence under the KYC / Customer Due Diligence Policy (PC-KYC-003). Due diligence covers, at minimum: corporate identity and registration; ownership and control, including identification of ultimate beneficial owners under the Beneficial Ownership Procedure (PC-UBO-006); jurisdictional risk; sanctions and restricted party screening; the intended use of compute capacity; and an overall risk rating that determines the level of ongoing monitoring. Enhanced due diligence applies to higher-risk profiles, including intermediaries, resellers of compute capacity, customers in higher-risk jurisdictions, and customers whose ownership is opaque.
Because the identity of the Company’s owners and controllers is material to its suppliers’ export licensing and to its own regulatory standing, the Company applies due diligence to its own capital structure, not only to its customers. In accordance with the Investor Due Diligence Policy (PC-IDD-005) and the Beneficial Ownership Procedure (PC-UBO-006), the Company shall:

Personnel must be alert to indicators that a transaction may involve diversion, evasion, or a prohibited end use. Red flags include, without limitation:
A red flag does not automatically prohibit a transaction, but it prohibits proceeding without resolution. Personnel must escalate red flags to the CCO, who must document the inquiry and its resolution before the transaction may continue.
The Company procures controlled items only from suppliers authorized to export them to Oman, and only pursuant to valid licenses or applicable license exceptions determined by the exporter. The Company does not self-classify or self-license U.S.-origin items; where the Company’s own activities may require authorization (for example, a proposed transfer, relocation, or change of end use), the CCO shall engage qualified export controls counsel and, through the appropriate channel, BIS, before proceeding. All representations made by the Company in support of a supplier’s license application — including end-user statements and facility descriptions — must be accurate, complete, and approved by the CCO.
The Company retains all records relevant to export compliance — including screening results and adjudications, due diligence files, end-user declarations, license conditions and related correspondence, shipping and customs documentation, contracts, invoices, training records, and acknowledgements — for a minimum of five (5) years from the later of the date of the record or the completion of the related transaction, or such longer period as required by the Record Retention Policy (PC-RRP-010) or applicable law. Records must be retrievable and producible in the event of a supplier audit or regulatory inquiry.

All Personnel receive export compliance training upon onboarding and at least annually thereafter, with role-specific modules for commercial, technical operations, procurement, and finance functions, as set out in the Employee Compliance Training Program (PC-TRN-007). Completion is recorded in the training log, and each member of Personnel executes the Employee Compliance Acknowledgement (Annex C) upon onboarding and upon each material revision of this Policy.
Any member of Personnel who becomes aware of an actual, suspected, or attempted violation of this Policy — including a screening match, a red flag, a request to circumvent controls, false documentation, an undisclosed change in ownership, or a breach of a license condition — must report it promptly to the CCO or through the channels described in the Incident Reporting Policy (PC-INC-009). Reports may be made confidentially. The Company strictly prohibits retaliation against any person who reports a concern in good faith or participates in an investigation. The CCO shall assess every report, direct any necessary interim holds, investigate, document findings, and determine remediation, including — where warranted and on advice of counsel — disclosure to suppliers or regulators.
The CCO performs periodic monitoring of screening operations, onboarding files, and access controls, and commissions an independent review of the export compliance program at least every two years or following any material incident. Audit findings and remediation plans are reported to the Board. This Policy is reviewed at least annually and upon any material change in law, in the Company’s ownership, or in the Company’s business model.
Violations of export control and sanctions laws can result in severe civil and criminal penalties for the Company and for individuals, loss of supplier relationships, denial of export privileges, and reputational harm. Violations of this Policy by Personnel will result in disciplinary action up to and including termination of employment or engagement, and may be referred to authorities where required. Third parties who violate compliance commitments face suspension or termination of their contracts.
This Policy is owned by the Chief Compliance Officer and approved by the Board of Directors. Deviations may be granted only by the CCO, in writing, with documented justification, and only where consistent with applicable law. Questions regarding this Policy should be directed to the CCO.

| Term | Meaning |
|---|---|
| BIS | The Bureau of Industry and Security of the U.S. Department of Commerce. |
| Controlled Item | Any hardware, software, or technology subject to the EAR or other applicable export control regime, including advanced computing items classified under ECCNs 3A090 and 4A090 and related entries. |
| Covered Entity | Prima Artificial Intelligence LLC and each entity it directly or indirectly controls, as listed in the register maintained under Section 2.1. |
| EAR | The U.S. Export Administration Regulations, 15 C.F.R. Parts 730–774. |
| End User | The person or entity that ultimately receives, uses, or benefits from a controlled item or from compute capacity provided using controlled items. |
| In-Country Transfer | A change in end use or end user of an item within the same foreign country. |
| OFAC | The Office of Foreign Assets Control of the U.S. Department of the Treasury. |
| Personnel | Directors, officers, employees, secondees, contract personnel, and covered third parties as described in Section 2.2. |
| Re-export | The shipment or transmission of a controlled item from one foreign country to another. |
| Restricted Party | A person or entity appearing on any applicable sanctions or export control list identified in Section 7. |
| Significant Investor | An investor meeting the thresholds defined in the Investor Due Diligence Policy (PC-IDD-005). |
| UBO | Ultimate beneficial owner, determined in accordance with the Beneficial Ownership Procedure (PC-UBO-006). |

This Policy is Document 1 of the Company’s Corporate Compliance Manual. The following related documents form an integrated system and are cross-referenced throughout this Policy.
| Document ID | Title | Owner |
|---|---|---|
| PC-ECP-001 | Export Compliance Policy (this document) | CCO |
| PC-ISP-002 | Information Security Policy | CTO / CCO |
| PC-KYC-003 | KYC / Customer Due Diligence Policy | CCO |
| PC-SSP-004 | Sanctions Screening Procedure | CCO |
| PC-IDD-005 | Investor Due Diligence Policy | CCO |
| PC-UBO-006 | Beneficial Ownership Procedure | CCO |
| PC-TRN-007 | Employee Compliance Training Program | CCO |
| PC-EUV-008 | End User Verification Procedure | CCO |
| PC-INC-009 | Incident Reporting Policy | CCO |
| PC-RRP-010 | Record Retention Policy | CCO |
Associated forms: Employee Compliance Acknowledgement (Annex C to this Policy); KYC Checklist; Investor Screening Checklist; End User Declaration; Export Compliance Review Form; Training Log; Screening Adjudication Log.

I acknowledge that I have received, read, and understood the Export Compliance Policy (PC-ECP-001) of Prima Artificial Intelligence LLC and its Covered Entities. I understand that:
| Full Name | |
| Position / Department | |
| Covered Entity | |
| Date | |
| Signature |
Completed acknowledgements are retained by the Chief Compliance Officer in accordance with the Record Retention Policy (PC-RRP-010).

Maintained by the Chief Compliance Officer pursuant to Section 2.1. Status as of the Effective Date:
| Entity | Jurisdiction | Relationship |
|---|---|---|
| Prima Artificial Intelligence LLC (CR No. 1575008) | Oman (SEZ at Duqm) | Parent / operating company |
| PetroCompute AI [legal entity details to be confirmed] | [●] | Operating brand / subsidiary |
| [Other controlled subsidiaries, if any — to be confirmed] | [●] | [●] |
Related entities in the ownership chain that are not controlled by the Company (including Prima Security General Trading Co. LLC, Kuwait, and Density AI LLC-FZ, UAE) are recorded and screened under the Investor Due Diligence Policy (PC-IDD-005) and the Beneficial Ownership Procedure (PC-UBO-006), and are covered by Section 2.1 to the extent they act on the Company’s behalf.