Before you deploy an AI assistant
Work through this before a model touches real people or real records. Every line should have a named owner and a written answer.
- Write down the decision the assistant supports, and the decision it must never make alone.
- List the data it can read, where that data lives, and the lawful basis for using it.
- Record whether personal data is involved and complete a DPIA if it is.
- Name the human who reviews outputs, and the escalation path when they disagree.
- Decide what is logged: prompts, outputs, approvals, overrides and retention periods.
- Test the assistant on your own worst cases, not the vendor's demo cases.
- Agree how users are told they are talking to AI, in plain language.
- Set the review date and the conditions that would trigger switching it off.