Policy, risk & rollout
The governance half: what should never go into an AI tool, the risks that never show on a usage dashboard, and ready-made policy, reporting and rollout material.
What should never go into an AI tool
Everything else on this page is about spending money well. This part is about not creating a much more expensive problem. Efficiency matters far less than getting this right.
Stop
- Personal data about clients, staff or third parties — names, contact details, health, HR or financial records
- Anything covered by a confidentiality agreement or legal privilege
- Credentials, API keys, passwords or access tokens
- Unreleased financial results, M&A material or price-sensitive information
- Anything you'd hesitate to forward to someone outside the business
Care
- Internal documents that could be de-identified first — strip names and figures, keep the structure
- Client work where the sector or facts could identify them
- Anything going into a personal account rather than the company tenancy
- Third-party material you don't own the rights to
- Outputs you plan to rely on without checking — always verify before use
Fine
- Public information and published material
- Your own drafting, notes and rough thinking
- Anonymised or invented examples that mirror the real problem
- General questions about law, process or best practice
- Formatting, structuring and proofreading non-sensitive text
Company account ≠ personal account
Business and enterprise tenancies are normally configured so your inputs aren't used to train models, with retention controls and audit logs. Free and personal accounts often work differently. The same prompt can carry very different risk depending on where it's typed — always use the company tooling for work.
De-identify, don't avoid
You rarely need the real names to get a useful answer. Replace parties with "Company A" and "Supplier B", round the figures, and strip identifiers. You keep the analytical value and remove most of the risk — and the prompt gets shorter and cheaper too.
The output is a draft, not advice
AI output can be confidently wrong. It doesn't know your matter, your client or your obligations. Anything client-facing or decision-bearing needs a human check by someone qualified to give it — that's a professional responsibility no tool transfers.
This is general good practice, not legal advice, and it doesn't replace our own policies. UK data protection obligations depend on the specifics of what you're handling — if you're unsure about a particular document or dataset, ask our data protection lead or legal team before pasting it anywhere.
Cyber and intellectual property
Two risks that don't show up on any usage dashboard, and which cost far more than tokens when they land. Both are worth a named owner rather than general awareness.
Cyber exposure
Prompt injection
Hidden instructions inside a document, email or web page that the AI reads and obeys — telling it to ignore its rules or leak what it's seen. The more an AI tool can browse, read files or use connectors, the more this matters. Treat AI-read content as untrusted input.
Agents and connectors
Tools that browse, click, send email or reach into systems widen the blast radius considerably. Grant the narrowest access that works, review what each connector can actually reach, and keep a human approving anything that sends, pays or deletes.
Credential leakage
Keys, tokens and passwords pasted into a prompt for convenience. Assume anything pasted may be logged somewhere. Rotate immediately if it happens — and never paste them in the first place.
Shadow AI
Personal accounts and unsanctioned tools sit outside every admin console, DLP rule and audit log. This is where most incidents originate. Sanctioned tooling that's actually good is the best control — people route around friction.
Better phishing
AI has removed the spelling mistakes and awkward phrasing that staff were trained to spot, and makes convincing voice and video impersonation cheap. Verification procedures for payment and data requests now matter more than spotting a badly written email.
Supply chain
Browser extensions, plugins, MCP servers and AI features bolted onto existing SaaS all process your data. Each is a third party with access. Review them the way you'd review any other processor, and keep a register.
Intellectual property
Who owns the output?
Vendor terms usually assign output rights to the customer, but that isn't the same as the output being protectable. Purely AI-generated material may attract weak or no copyright protection in some jurisdictions — which matters if it's meant to be a defensible asset.
Inbound infringement
Output can reproduce material from training data, particularly for code, brand assets and distinctive style. Anything going into a client deliverable or public campaign deserves a check rather than an assumption.
Your IP going out
Pasting proprietary methods, source code or unpublished material into a tool that may retain or train on it can weaken trade-secret protection. Confidentiality is often maintained by behaving confidentially — casual pasting undermines that argument later.
Client contracts
An increasing number of client agreements now restrict or require disclosure of AI use in delivered work. Check the engagement terms before using AI on client matters — the obligation may already exist and be unmet.
Third-party material
Feeding in licensed content, someone else's documents or paywalled material may breach the licence you hold it under, regardless of what the AI then does with it.
Disclosure and attribution
Decide as a business whether AI-assisted work is disclosed, to whom, and how. Deciding once is far better than each person improvising when a client asks.
General guidance, not legal advice. IP and data protection positions vary by jurisdiction, by contract and by the specific facts — take proper advice before relying on any of this for a live matter.
Prompt templates
The Prompt-Builder Method in practice: let a lighter model build the prompt, let the stronger model do the thinking, then let a lighter model tidy up. Copy any of these and paste them straight into whichever tool you're using.
Build a Gen AI policy
Answer a few questions and get a drafted policy you can drop into the staff handbook. It's a starting point written in plain English — not a finished legal document.
Policy generator
Draft policy
A drafting aid, not legal advice. Have it reviewed by whoever owns HR policy and by legal before it goes into the handbook, and check it sits consistently with your existing data protection, IT and confidentiality policies.
The board pack page
AI spend and AI risk are now board-level items in most organisations, but they rarely get reported consistently. This builds a one-page template you can paste into the pack and reuse each quarter.
Board reporting template
Board pack template
Report the same handful of measures every quarter rather than a new selection each time. A board can see a trend in three numbers it recognises; it can't see anything useful in twelve it's meeting for the first time.
Automating board and governance reporting
Board reporting is repetitive, deadline-driven and largely built from the same inputs every cycle — which makes it an obvious candidate for automation. It's also where a company keeps its most sensitive material and where directors carry personal, non-delegable duties. Both things are true at once, so the question isn't whether to automate but which parts.
Governance automation map
Safe to automate
Human must own
The specific risk
From the CFO's chair
The reporting cycle is the prize
Variance commentary, KPI narratives, cash and covenant summaries and the "what changed since last month" section follow a stable structure and draw on numbers you already trust. Drafting those from a clean data extract is where most of the time goes and where AI genuinely helps — because the arithmetic stays in the model or the ledger, and AI only writes the words around it.
Never let it do the maths
Numbers should come from the system of record and be pasted in as fact, not calculated by a language model. Ask it to explain, structure and narrate figures you supply — never to compute, reconcile or total them. This single rule removes most of the risk in financial reporting automation.
Consistency checking is underrated
One of the strongest uses is comparison rather than creation: does this month's commentary contradict last quarter's? Does the narrative match the numbers in the appendix? Has a risk that was flagged as closed quietly reappeared? That's tedious for a person and quick for a model.
Under the 2024 Code, evidence matters more
Provision 29 of the UK Corporate Governance Code applies to financial years beginning on or after 1 January 2026, moving boards from asserting that controls were reviewed to demonstrating that they operated effectively, on evidence, with weaknesses disclosed. If AI sits anywhere in the reporting chain, it is part of that control environment and needs the same documented discipline.
Across a group or portfolio
Consolidation is a formatting problem
Portfolio and subsidiary reporting usually fails not because the data is missing but because every entity presents it differently. Normalising twelve differently-structured monthly packs into one comparable format is a genuine AI strength, and it's low-risk when the underlying figures are carried across unchanged.
Ask for the same fields every time
Automation only works against a stable template. Agreeing a fixed reporting schema across the group — same KPIs, same definitions, same periods — delivers more than any tool will. The tool then becomes trivial; without it, no tool helps.
Watch definitional drift
When a model normalises figures across entities it may silently reconcile things that shouldn't be reconciled — different EBITDA adjustments, different revenue recognition, different period ends. Require it to flag definitional mismatches rather than smoothing them, and check that it has.
Obligation extraction genuinely works
Pulling reserved matters, consent thresholds, information rights and reporting deadlines out of shareholders' agreements and facility documents into a single tracker is high-value and well suited to AI — provided a person verifies each extracted clause against the source before anyone relies on it.
The part most people miss
You may be creating a second record
Minutes are a deliberate, approved account of a meeting. An AI transcript is a verbatim one. Run both and the company now holds an unapproved, text-searchable record of everything said — including the tentative view a director later withdrew. That record is discoverable. Decide deliberately whether transcripts are created, who sees them, and when they are deleted.
Privilege can be lost
Legal advice put through a consumer-grade AI tool may forfeit privilege and work-product protection, and vendor-held data can in some circumstances be preserved for third-party litigation regardless of a user's deletion settings. Legal papers going to a board are exactly the material where this matters most.
The chilling effect is real
Boards need candid discussion. If directors believe everything is being transcribed and processed, they say less, or say it elsewhere. That's a governance cost that won't appear on any dashboard, and it's worth weighing before introducing recording tools into the room.
Accountability doesn't transfer
Legal responsibility for what a system does does not pass to the vendor when the contract is signed. Directors' duties are personal and cannot be delegated to a tool. In financial services, senior manager accountability has been read as extending to decisions made by algorithms — the individual remains answerable.
The test is process, not technical mastery
Directors aren't expected to understand model architecture. They are expected to make a good-faith effort to design, validate and supervise the company's reliance on a system given its opacity. The inquiry is into process and documentation — which is a reassuringly familiar standard.
The gap worth closing
Survey work in 2026 found roughly two-thirds of directors using AI tools while only around a fifth reported a formal governance framework for it. If your board is in the first group and not the second, that gap is the finding — and it's a cheap one to fix relative to what it exposes.
General guidance for discussion, not legal advice. Directors' duties, privilege and disclosure obligations vary by jurisdiction, entity type and circumstance, and the regulatory position on AI is moving quickly. Take proper advice before changing how your board creates or retains its records.
Getting a team from here to there
Knowing what good looks like is the easy part. Most of these habits fail to spread not because people disagree with them, but because nobody owns the change and it competes with everything else on a Tuesday. A workable sequence, assuming you start from nothing.
First — give it an owner
One named person, with a small amount of protected time. Not a committee, and not "everyone's responsibility." They don't need to be technical; they need to be able to ask finance for the spend numbers and get an answer. Without this step nothing else on this list happens.
Find out what's actually happening
Pull the admin console data you do have, and run the survey on this page. Expect the answer to be messier than you assumed — usage concentrated in a few people, several tools nobody approved, and at least one person who's been doing something clever that nobody knew about.
Fix the policy gap early
Draft the policy before you push adoption, not after. It takes an afternoon with the builder above plus a legal review, and it means the answer to "can I put this in ChatGPT?" exists before someone has to guess. Most data incidents come from that gap.
Teach three habits, not ten
People will not remember a ten-point list from a slide deck. Pick the three with the biggest effect — start a fresh chat per task, match the model to the risk, ask for the length you need — and repeat them until they're boring. The rest can live on a page people consult.
Make the good path the easy path
If the approved tool is worse or slower than what people can reach on their phone, they will use their phone. Shadow AI is usually a symptom of friction, not defiance. Sort access, sort the licence, and put the prompt templates where people already work.
Report it, then repeat it
Take the board template above and use the same measures every quarter. Re-run the survey at six months against the same twelve questions. A trend on three familiar numbers will do more to sustain attention than a new analysis each time.
Don't lead with cost. A programme that arrives as "you're spending too much" gets treated as a budget exercise and quietly ignored. The same programme framed as "here's how to get more out of the allowance you have" gets engagement, and delivers the saving anyway. The efficiency is a by-product of people using the tools better — that's the honest framing and it happens to be the effective one.