Governance & risk
Light-touch AI governance: enough to be safe, not enough to slow anyone down
A thirty-person company does not need an ethics board. It needs everyone to know which account to use, what not to paste, whose number is real, and what a machine may never do without a person saying yes. Two pages, in your voice, with the evidence beside each rule.
The nine themes
One recommended way
The standard setup, how a new starter gets it, where shared prompts live.
Company accounts, not personal
Company work through company accounts, and a sanctioned route for the tools the company one is not good at.
What may go in, in three tiers
Fine to paste. Fine with care. Never. One page, for a person choosing in five seconds.
The official number
One named source and owner per headline metric. Ad hoc analysis encouraged, and labelled.
A human before the outside world
Anything that emails a supplier, pays money or touches a customer waits for a person’s yes.
Check before you rely
Output is checked before it is acted on, and AI critique of a colleague’s work is done with them, not to them.
Access and logging
Who can read what, who can write what, and where the record of what an automation did lives.
Bringing in new tools
One person checks three things first: does it train on inputs, can it be turned off, does the existing tool already do it.
Parked, not ignored
What is out of scope, why, and what people are already doing there.
Tell me what you're dealing with
Three lines is plenty. I reply personally, usually within a day, and the first call is free.
Thanks for reaching out!
I'll get back to you soon.
Frequently asked questions
Do we need an AI policy?
You need people to know which account to use, what may go in, whose number is official, and what a machine never does alone. If two pages do that, you have a policy. The forty-page version gets signed and never read.
What about the Privacy Act?
The three-tier data rule and the access table are written with your obligations in mind. For anything beyond that you want a lawyer, and the note is short enough that they can read it too.
Can we see what staff do in AI tools?
On most team plans you see usage, not conversations. You can see the effects from your Workspace or Microsoft audit logs. The note says plainly what is visible and relies on the check-before-you-rely norm for the rest.
How do you handle the fear that this is a prelude to cuts?
The leader frames it honestly at the start: roles change for the better, headcount is not the target. Then nothing is measured by name and survey answers are never used against a person.
Is this a one-off document?
Produced at the audit, maintained on the retainer. The tools change monthly; the note changes when it needs to.
A forty-page policy nobody has read, or no policy at all?
Either way, send me what exists. I will tell you what the two-page version would say.
Back to the form