Give each use a named owner

Start with an inventory of AI uses, including experiments and third-party software with embedded AI features. Record the purpose, users, data categories, supplier and systems affected. A single organisation-wide statement cannot explain the different risks of drafting an internal announcement and helping assess an employment application.

Assign responsibility for the business outcome, technical operation and data protection review. These responsibilities may sit with different people, but the boundaries should be clear. Someone must be able to approve a material change, suspend the service and decide whether an incident needs escalation beyond the delivery team.

Use recognised references carefully

The NIST AI Risk Management Framework organises its core around Govern, Map, Measure and Manage. It can help structure questions about purpose, context, evaluation and response. It is a voluntary risk-management reference, not a certificate that proves a system is safe or legally compliant.

For UK personal data, consult the ICO’s AI and data protection guidance. Consider the UK GDPR, the Data Protection Act and any relevant sector requirements. Where a service reaches other jurisdictions, obtain advice on additional obligations rather than assuming a UK assessment settles every legal question.

Define acceptable data use

Specify what staff may enter into approved services and what must stay out. Distinguish public material, internal information, confidential records and personal data. Explain how the rule applies to attachments, copied emails and conversation histories, not just to the initial prompt.

Review supplier processing terms, sub-processors, retention and international transfers before sending data. A setting labelled “private” does not replace a contractual assessment. A data protection impact assessment may be required where processing is likely to create a high risk to people’s rights and freedoms. A qualified privacy adviser should determine the legal requirements for the particular use.

Make human review meaningful

Define when an output can be used directly and when a person must check it. The reviewer needs sufficient context, competence and authority to reject the output. A rushed approval step that hides the evidence is not a strong control simply because a human clicks a button.

Pay particular attention to decisions affecting employment, access to services or other significant interests. Keep this site’s guidance separate from legal advice about automated decision-making. Explain limitations to users, give them an escalation route and avoid presenting generated content as an authoritative determination when it is only a suggestion.

Prepare for misuse and mistakes

Security controls need to cover prompt injection, inappropriate disclosure, excessive permissions and unsafe handling of outputs. The OWASP project on risks in large language model applications is a useful reference for application-level threats. Use it to inform threat modelling, not as a substitute for reviewing your own design.

Write an incident procedure that identifies who can disable access, preserve relevant records and contact affected teams. Distinguish an incorrect answer from a data leak or unauthorised action. Record the cause, containment and corrective work without collecting unnecessary personal information in the investigation itself.

Keep the controls current

A scoped governance engagement can include an AI-use inventory, draft acceptable-use guidance, responsibility mapping, supplier review questions and a change-control process. Agree the included documents and review boundaries in writing. This is operational support, not legal certification, an audit opinion or a guarantee of compliance.

Revisit the assessment when the purpose, model, data source, access level or user group changes. Training should show staff how to recognise uncertainty, protect sensitive information and report a problem. Connect these controls to technical integration and workflow design. Governance works best when it changes what the system and its users can actually do.