Start by finding out what's actually in use, because it's always more than the official list.Then sort it by what could go wrong. Someone drafting an internal email with ChatGPT doesn't need the same sign-off as a model that helps decide who gets credit. Put the heavy controls where customers, money or regulators are involved, and keep the rest light. One named exec should own it. In our experience a sign-off gate bolted on at the end just gets worked around. Built in from the start, it tends to speed teams up.
4 briefings this month, with 4 new figures that passed our source checks.
subscribers read every briefing in full, and get each one on WhatsApp. subscribe free · how we research and check sources
| risk | examples | controls |
|---|---|---|
| Low | Drafting internal documents, summarising meetings | Approved tools, clear data rules, basic training |
| Medium | Customer-facing content, internal decision support | Human review, logging, regular quality checks |
| High | Credit, hiring, pricing or medical decisions | Documented risk assessment, human oversight, monitoring and an audit trail |
Governance built as a gate slows everything and gets worked around. Governance built into delivery, with controls designed alongside the use case, lets teams move faster because the rules are clear.
Regulation such as the EU AI Act raises the bar for high-risk uses, but most of what it asks for, an inventory, risk classification, documentation and human oversight, is simply good practice.
how we help: realise the value. →our frameworks: the Lumo method · the value framework
An inventory of AI in use, a risk classification, policies for data and acceptable use, approval routes proportionate to risk, human oversight for high-impact decisions, and monitoring once systems are live.
It can. It applies to organisations that place AI systems on the EU market or whose AI output is used in the EU, wherever they are based. UK businesses selling into or operating in the EU should check their exposure.
A named executive, with a small cross-functional group spanning technology, risk, legal and the business. Ownership sitting only with IT or only with legal tends to produce either no controls or too many.
Find out what is in use before banning anything. Provide approved tools that meet the need, set clear rules for company data, and make it easy to request new tools so shadow use has somewhere to go.