Skip to main content
Skip to main content
Methodology

Govern: how to prove an AI assistant stayed safe, not just claim it

Assertion is cheap. Governance is what you can hand to a regulator, an auditor or a worried parent.

Andy Wake, Founder and Managing Director7 min read

Most published AI principles are indistinguishable from each other. Safety, fairness, transparency, accountability — nobody disagrees. The difference between an organisation that means it and one that does not is whether anything is recorded when the principle is tested.

Four questions governance has to answer

  1. What did the assistant do, and on what basis? A recommendation with no traceable reasoning cannot be reviewed.
  2. Who is accountable for that class of decision, by name or role? 'The system' is not an accountable party.
  3. What would have stopped it? Thresholds, refusals and escalation routes must exist before the incident, not after.
  4. How would we know it went wrong? Someone has to look, on a schedule, at cases nobody complained about.

Log the events that matter, not everything

Logging every token is both a privacy liability and useless in review. Log governance events: a recommendation issued, a refusal, a safeguarding escalation, a consent change, a memory write or deletion, a human override. Each with a timestamp, the rule invoked, and the outcome. That set is small enough to read and specific enough to defend.

The UK context

The UK has no single AI act. Instead, existing law applies: UK GDPR and the Data Protection Act 2018 for personal data, the Equality Act 2010 for discrimination, sector regulators for sector risk, and the cross-sector principles set out in the government's pro-innovation approach — safety and robustness, transparency and explainability, fairness, accountability and governance, and contestability and redress.

Practically, that means your evidence has to be organised by principle rather than by product. A regulator will not ask which model you used; they will ask who was accountable, what you assessed, and what a person can do if they disagree with the outcome.

A governance minimum you can stand up this month

  • A one-page AI use policy naming what is permitted, what is prohibited and who decides.
  • A named accountable owner for each AI-supported decision type.
  • An incident log — even a spreadsheet — with date, what happened, impact and action taken.
  • A short DPIA for anything touching personal data, children's data or significant decisions.
  • A monthly review of overrides, refusals and escalations.

Frequently asked questions

What should an AI audit trail contain?
At minimum: what was asked, what the assistant recommended, which rule or source it invoked, whether a human accepted or overrode it, and any refusal, escalation or consent change. Timestamps and a named accountable role make it reviewable; storing full conversation transcripts by default usually creates more risk than it resolves.
Who is accountable when an AI assistant gets something wrong?
The organisation deploying it, through a named human owner for that decision type. Accountability cannot be transferred to a supplier or to the model. This is why the govern stage insists on naming an owner per decision class before the assistant is switched on.

Sources and further reading

Where to go next

More articles on the insights index.

Try the demo