Governance & risk

Light-touch AI governance: enough to be safe, not enough to slow anyone down

A thirty-person company does not need an ethics board. It needs everyone to know which account to use, what not to paste, whose number is real, and what a machine may never do without a person saying yes. Two pages, in your voice, with the evidence beside each rule.

The nine themes

One recommended way

The standard setup, how a new starter gets it, where shared prompts live.

Company accounts, not personal

Company work through company accounts, and a sanctioned route for the tools the company one is not good at.

What may go in, in three tiers

Fine to paste. Fine with care. Never. One page, for a person choosing in five seconds.

The official number

One named source and owner per headline metric. Ad hoc analysis encouraged, and labelled.

A human before the outside world

Anything that emails a supplier, pays money or touches a customer waits for a person’s yes.

Check before you rely

Output is checked before it is acted on, and AI critique of a colleague’s work is done with them, not to them.

Access and logging

Who can read what, who can write what, and where the record of what an automation did lives.

Bringing in new tools

One person checks three things first: does it train on inputs, can it be turned off, does the existing tool already do it.

Parked, not ignored

What is out of scope, why, and what people are already doing there.

Tell me what you're dealing with

Three lines is plenty. I reply personally, usually within a day, and the first call is free.

Frequently asked questions

Do we need an AI policy?

You need people to know which account to use, what may go in, whose number is official, and what a machine never does alone. If two pages do that, you have a policy. The forty-page version gets signed and never read.

What about the Privacy Act?

The three-tier data rule and the access table are written with your obligations in mind. For anything beyond that you want a lawyer, and the note is short enough that they can read it too.

Can we see what staff do in AI tools?

On most team plans you see usage, not conversations. You can see the effects from your Workspace or Microsoft audit logs. The note says plainly what is visible and relies on the check-before-you-rely norm for the rest.

How do you handle the fear that this is a prelude to cuts?

The leader frames it honestly at the start: roles change for the better, headcount is not the target. Then nothing is measured by name and survey answers are never used against a person.

Is this a one-off document?

Produced at the audit, maintained on the retainer. The tools change monthly; the note changes when it needs to.

A forty-page policy nobody has read, or no policy at all?

Either way, send me what exists. I will tell you what the two-page version would say.

Back to the form