Practical governance guide

A calmer way to think about personal data and AI.

AI governance starts with a simple question: what information is leaving your organisation, and what control do you have before it does? This guide turns that question into an operating model.

Talk to our team

Start with the data

Map the information people actually put into AI tools. Do not begin with abstract policy language; begin with real workflows and real sensitivity levels.

  • Identity and contact information
  • Patient, customer, and student records
  • Account and transaction details
  • Confidential business information

Put controls at the point of use

A policy is easier to follow when the product helps people make the right decision. Block public submission, mask locally, and provide a clear protected alternative.

  • Give users an immediate explanation
  • Avoid asking people to memorise every rule
  • Make Safe Zone easy to reach
  • Keep support guidance free of raw PII

Measure the control

A pilot should reveal where policy and behaviour diverge. Use safe metadata and user feedback to improve the rules without collecting the sensitive content you are trying to protect.

  • Review blocked message counts
  • Track false positives and missed patterns
  • Test with synthetic values
  • Refresh the policy as AI use changes

Remember the human workflow

Responsible AI is not just a technical filter. Users need a fast path, understandable language, and confidence that a block will not erase their work.

  • Explain what happened
  • Offer masked text where appropriate
  • Provide a protected workflow for complex tasks
  • Give people a clear IT escalation path

Make safe AI the easy default.

Start with the workflow that fits your organisation, then add the controls your compliance team needs.

Read the getting-started guide