Skip to main content

The riskiest AI policy in circulation right now is the finished one. Signed off, filed, and quietly out of date.

I saw this first-hand a couple of weeks ago. A client sensible, well-advised, nobody’s fool walked me through their AI policy. It was a good document. It covered which generative AI tools were approved, what staff could and couldn’t paste into a chatbot, how AI-drafted content should be reviewed before it went anywhere near a client. On paper, sewn up.

One problem. The policy governed how people use AI. It said almost nothing about how AI now acts inside the business.

The gap in your AI policy: AI that acts, not just answers

The policy had been written for a world where AI meant a chat window: a person types, the model answers, the person decides what to do with it. That world is already behind us. The tools arriving now agentic assistants, autonomous workflows, AI features switched on inside the platforms you already run don’t wait to be prompted. They read inboxes, move files, rank candidates, raise and resolve tickets, and complete multi-step tasks across systems, often triggered by a vendor update rather than any decision your board ever saw.

Reviewing an AI policy at a desk with a laptop and notebook

Here’s the scenario I now use to test a policy. A mid-sized firm’s HR platform ships an update: “AI-assisted shortlisting.” A team lead, under pressure to fill a role, turns it on. Two hundred applications arrive; the system ranks them; the bottom hundred and twenty are never seen by a human being.

That is automated decision-making with significant effects on real people. Under UK data protection law, updated by the Data (Use and Access) Act, it carries specific obligations: the firm must be able to provide meaningful information about the logic involved, give individuals a route to challenge the outcome, and ensure there is genuine, not decorative, human intervention. The firm’s AI policy had nothing to say about any of this. It was a chatbot policy. No one logged the feature, no impact assessment was done, and no one owned the risk. The exposure was created by a checkbox.

Data protection has already drawn the map

The good news is that none of this requires inventing a new discipline. Data protection has spent the better part of a decade building exactly the habits AI governance needs: know what processing you’re running, assess it before you deploy it, establish a lawful basis, give someone accountable ownership, and respect the rights of the people on the receiving end. If your privacy programme is in reasonable shape, you already have the scaffolding. The task is to extend it to everywhere AI plays a part not just the places where staff log in and type.

Three moves I’d make before the quarter is out:

Inventory where AI acts, not just where it’s used. Include the features embedded in platforms you already own HR, finance, CRM, security tooling. Ask vendors directly what’s been switched on.

Extend the policy to agentic activity. Be explicit about what an AI agent may access and action on its own, and which decisions must pass through a human before they take effect.

Put a name against it. AI risk that belongs to everyone belongs to no one. Board-level oversight isn’t bureaucracy; it’s the difference between a policy and a piece of paper.

None of this is an argument for slowing down. The firms getting real value from AI are the ones whose governance keeps pace with their adoption because they can say yes quickly, and mean it.

If you’d like a second pair of eyes on your AI policy, or an honest view on whether it covers what your business is actually running, get in touch. It’s usually a shorter conversation than people expect.