PERSPECTIVE / PRACTICE NOTE

Before your business adopts an AI tool

A useful review begins with the intended use, not the product demo.

Four AI approval questions: intended task, permitted data, human review and changes requiring reassessment.
A practical review structure. The scope depends on the proposed use.

Name the decision

Write down what the tool will do, who will use it and what decisions depend on its output. A drafting assistant and a tool that takes actions raise different questions.

Follow the information

Identify the information sent to the provider, who can access it and the terms governing retention, training, subprocessors and deletion. Compare the contract with the actual product settings.

Define the review

Decide which outputs require a person to check them, what evidence supports that review and who can suspend the use. Record unresolved questions before approval.

Revisit material changes

Changes in the model, vendor terms, data or intended use may call for a fresh assessment. Give that responsibility to an identified person.

ILLUSTRATIVE EXAMPLE

The same tool. Two different uses.

A support team wants an AI assistant to draft replies. In the first proposal, it works only from public help articles, and a staff member checks every draft. In the second, it receives complete customer records and sends replies without review.

The second proposal introduces personal information and gives the system authority to communicate directly. An approval of the first proposal does not answer the questions raised by the second.

The business decision: define which data and actions are authorized, preserve the agreed human review, and require reassessment before expanding the use. That gives the team a usable approval boundary.

Further reading: NIST AI Risk Management Framework. These questions are a general starting point, not a complete compliance checklist or legal advice for a particular matter.

START WITH THE QUESTION

A consequential decision
deserves a clear answer.

Discuss your matter