Artificial Inteligence

Use AI deliberately, not indiscriminately.

AI is already part of the way digital products are designed, built and operated. The interesting question is no longer whether organisations should use it, but where it is useful, where it introduces risk, and where a human should remain firmly in control.

Good AI governance shouldn't stop people experimenting. It should make experimentation safer, more useful and easier to turn into something genuinely valuable.

Governance, not just policy

An AI policy can tell people what they are allowed to do. Governance goes further: it creates a practical framework for deciding which tools to use, what information can be shared with them, how outputs are checked, who is accountable and when AI simply isn't the right solution.

The aim isn't to wrap AI in process. It's to give teams enough structure to move quickly without creating unnecessary technical, legal, reputational or operational risk.

Principles

Human accountability
AI can assist with decisions, research and production, but responsibility stays with people. There should always be someone who owns the outcome.
Appropriate use
Not every problem needs AI. I start with the problem and choose the simplest technology capable of solving it well.
Data awareness
Teams need to understand what they are putting into AI systems, where that information may go and whether it should have been shared in the first place.
Verification
AI output is not inherently correct. The level of human review should increase with the potential impact of getting something wrong.
Transparency
AI shouldn't be hidden where its use materially changes an interaction, a decision or the provenance of something being presented as original work.
Proportionality
Governance should reflect risk. Generating placeholder copy and influencing an important decision do not need the same controls.

Think in levels of risk

I find it more useful to govern AI by consequence than by technology. Instead of maintaining a huge list of approved and prohibited use cases, ask what happens if the system is wrong.

  1. Low risk

    Brainstorming, summarising non-sensitive material, prototyping, development assistance and other work where the output is reviewed before it goes anywhere.

  2. Moderate risk

    Customer-facing content, analysis, recommendations or automation where inaccurate output could affect trust, quality or operational decisions. These need clear ownership and review.

  3. High risk

    Decisions involving people, sensitive information, significant money, legal obligations, safeguarding or other situations where an error could cause meaningful harm. AI may still have a supporting role, but it shouldn't quietly become the decision-maker.

A practical workflow

Governance works best when it becomes part of normal delivery rather than a document people read once.

  1. Define the problem

    Be clear about what AI is expected to improve and why it is preferable to a conventional solution.

  2. Understand the data

    Identify what information the system receives, whether it contains personal, confidential or commercially sensitive data, and where that data is processed.

  3. Assess the consequence

    Consider what happens when the model is inaccurate, biased, unavailable or confidently wrong.

  4. Design the human role

    Decide who reviews the output, who can override it and who ultimately owns the result.

  5. Test it

    Test real scenarios, awkward scenarios and failure cases rather than judging a system from a handful of impressive demonstrations.

  6. Keep reviewing it

    Models, products, pricing and terms change quickly. An AI system that was appropriate six months ago shouldn't automatically be assumed to be appropriate today.

The reality of shadow AI

If useful AI tools exist, people will use them. Blocking everything usually doesn't remove AI from an organisation; it removes visibility of how AI is being used.

A better approach is to give people safe ways to experiment, clear boundaries around sensitive information, approved tools where appropriate and somewhere to ask questions when the answer isn't obvious.

Build, buy, or don't use AI at all

One of the most important governance decisions happens before a model is ever used.

Sometimes an off-the-shelf AI product is the fastest and safest option. Sometimes an API integrated into an existing workflow gives better control. Sometimes a deterministic piece of software will be cheaper, faster and considerably more reliable.

AI should earn its place in the architecture.

What this looks like in an organisation

I favour lightweight governance that teams can actually follow:

  • A small set of clear AI principles.
  • Guidance on sensitive and confidential data.
  • An understood set of approved tools and accounts.
  • A simple way to assess higher-risk use cases.
  • Named human ownership for AI-assisted processes.
  • Testing and review appropriate to the potential consequence.
  • A record of significant AI systems and why they are being used.
  • Regular review as tools, regulation and organisational needs change.

The result should be enough governance to know what is happening without creating an AI committee that has to approve every prompt.

AI is a capability, not a strategy.

The organisations that get the most from AI won't necessarily be the ones that use the most of it. They'll be the ones that understand where it creates an advantage, where it creates unnecessary risk, and how to make that distinction repeatedly as the technology changes.

That's the role I think AI governance should play: not putting the brakes on adoption, but giving an organisation the confidence to accelerate in the right places.