THE AI PRACTITIONER
← All policies

AI Usage & Governance Policy

Reference
AIP-PS-006 · Version 1.0
Effective
31 July 2026
Owner
Tim Parkin, Director
Next review
31 July 2027, or sooner on material change
Applies to
All AIP personnel, contractors and associates using AI tools in connection with any AIP business activity, including client delivery, research, administration, marketing and business operations

1. Introduction and Purpose

The AI Practitioner (“AIP”, “we”, “us”, “our”) is an AI consultancy: our credibility depends on using AI tools responsibly, transparently and to a higher standard than we ask of our clients. This policy sets out how AIP personnel, contractors and associates must use AI tools — including large language models, AI writing and research assistants, and AI-enabled features within other software — when carrying out AIP business.

This policy governs AI as a tool used by a human to do their work. It is a companion to, and should be read alongside, the Digital Workers Policy (AIP-PS-007), which governs AI operating as a registered, semi-autonomous member of AIP’s digital workforce. Section 14 explains the boundary between the two.

2. Classification of Ambiguous AI Capabilities

Where there is uncertainty as to whether an AI capability should be governed as a human-operated AI tool under this policy or as a registered Digital Worker under the Digital Workers Policy (AIP-PS-007), it shall be governed under the Digital Workers Policy (AIP-PS-007) until its classification has been determined by the Director. Until the Director determines the correct classification, the requirements and controls of AIP-PS-007 apply to that capability.

3. Policy Hierarchy and Interpretation

This policy forms part of AIP’s integrated governance framework. Where policies overlap, they must be read together wherever possible. Where an actual conflict exists, the policy dealing most specifically with the subject matter takes precedence. Where uncertainty remains, the Director will determine the applicable interpretation pending formal clarification or amendment.

The Director’s interpretation is an interim governance determination and does not replace the formal policy amendment process.

4. Scope

This policy applies to:

  • Tim Parkin and any future employees of Groundframe Ltd;
  • Contractors, freelancers and associates engaged to deliver AIP work;
  • Any AI tool, model or AI-enabled feature used in connection with any AIP business activity, including client delivery, research, administration, marketing and business operations, including general-purpose assistants (for example Claude, ChatGPT, Gemini, Perplexity) and AI features embedded within other business software (for example Notion AI, AI features in office or CRM tools).

It does not cover AI tools used by clients within their own organisations, which remain the client’s responsibility, although AIP may advise clients on their own AI governance as part of its consultancy services.

5. Definitions

The following terms have the meanings set out below wherever they are used in this policy.

  • AI Tool. Any AI model, application or AI-enabled feature used by a human under their direct, session-by-session control to support their work, including general-purpose assistants (for example Claude, ChatGPT, Gemini, Perplexity) and AI features embedded within other business software.
  • AI-assisted. Describes work to which an AI Tool has contributed — for example drafting, research or analysis — where a human has directed, reviewed and taken responsibility for the final output.
  • AI-generated. Describes content produced substantially or wholly by an AI Tool with limited human authorship, as distinct from AI-assisted content; see Section 10.
  • Human Review. The check a qualified human must carry out on AI-generated or AI-assisted content before it is relied upon, published or delivered, as required under Section 9.
  • Human Authority. The person(s) authorised to make governance decisions under this policy and the Digital Workers Policy (AIP-PS-007); currently the Director, Tim Parkin, with this authority expected to extend to a future Governance Board as AIP grows.
  • Digital Worker. An AI capability registered as a member of AIP’s digital workforce under the Digital Workers Policy (AIP-PS-007), which governs its creation, authority, supervision and retirement; see AIP-PS-007 for the full definition and governance model.

6. Guiding Principles

  • Human accountability. A human is always accountable for work AIP delivers, regardless of how much AI assistance was used in producing it. AI tools support AIP’s judgement; they do not replace it.
  • Proportionate transparency. We are open with clients about our use of AI where it is material to the engagement or the deliverable, in line with Section 10.
  • Data minimisation. We give AI tools no more client or personal data than a task genuinely requires.
  • Verify before you rely. AI-generated content is checked by a human before it is relied upon, published or sent to a client.
  • Use the right tool for the sensitivity of the task. Higher-sensitivity data requires a higher-trust tool and tier. See Section 8.

7. Approved AI Tools and the Tool Register

AIP maintains a working list of AI tools approved for use in AIP business. A tool must meet the following minimum bar before it is added to the list:

  • A published privacy policy and terms of service that AIP has reviewed;
  • An appropriate paid or organisational account wherever the tool will handle client-identifiable, confidential or commercially sensitive information. The applicable terms must provide suitable data protection, security and confidentiality controls and, where required, confirm that submitted content is not used to train the provider’s general models;
  • Multi-factor authentication support;
  • A clear basis for any international data transfer, consistent with the Data Protection Policy (AIP-PS-003).

AI Tool Register

AIP maintains an internal AI Tool Register recording approved AI tools used within the organisation. As a minimum, the register records the tool name, supplier, subscription tier, approved business purpose / approved use cases, approver, approval date and current status. The register is maintained as an operational governance record and is not published as part of this policy.

8. Client Data and Confidentiality

AI tools must be treated as a third-party processor of any data placed into them. The following rules apply:

  • No client-identifiable or confidential data in free or consumer-tier AI tools. Only tools meeting the Section 7 bar may be used for anything beyond publicly available or fully anonymised information.
  • Apply data minimisation, even to approved tools. Only the minimum information necessary to complete the task should be entered into any AI tool, even where the tool has been approved for handling client data.
  • Anonymise or generalise where possible. Before entering client material into an AI tool, consider whether client names, identifying details or commercially sensitive figures can be removed or replaced without losing the value of the task.
  • Check the client contract first. Where a client engagement letter or NDA restricts the use of third-party tools or AI specifically, that contract takes precedence over this policy and must be followed.
  • No training data for AIP’s competitive material. Do not input AIP’s own commercially sensitive methodology, pricing or unpublished intellectual property into tools whose terms permit the vendor to use inputs for model training.

This section operates alongside, and does not replace, the Privacy Policy (AIP-PS-001) and Data Protection Policy (AIP-PS-003).

9. Human Oversight and Verification of AI Outputs

AI-generated or AI-assisted content must always be reviewed by a human before it is used, published or delivered. The level of review should be proportionate to the importance, risk and intended use of the AI-generated output. In particular:

  • Fact-check AI-generated claims, figures, citations and quotations before they appear in any client deliverable, proposal, or public content — AI models can produce plausible but incorrect statements (“hallucinations”).
  • AI output must never be the sole basis for advice that is legal, financial, regulatory, medical or safety-critical in nature. Such advice is either provided directly by a qualified human or clearly flagged to the client as requiring independent verification.
  • Code, data analysis, or calculations produced with AI assistance are tested or checked before being relied upon.
  • Where AI is used to summarise or analyse a client’s own documents, the summary is checked against the source material before being presented as fact.
  • Human review should also consider whether the output is appropriate for its intended audience, purpose and context, and whether it reflects AIP’s expected professional standards.
  • Human review must be undertaken by a person with appropriate competence, knowledge or authority for the subject matter being reviewed.

10. Disclosure to Clients

AIP is a business built on AI expertise, and reasonable use of AI tools in delivering our own work is expected and unremarkable. We will nonetheless be transparent with clients:

  • Our Terms of Business (AIP-PS-005) records that AIP may use AI tools in the course of delivering services, subject to this policy.
  • Where a client asks how AI was used in a specific deliverable, we will answer honestly.
  • Where a deliverable is substantially AI-generated with limited human authorship (for example, a first-draft report intended for the client’s own further work), this will be made clear to the client rather than presented as fully human-authored analysis.

Disclosure should be proportionate to the significance of AI’s contribution to the engagement and the client’s legitimate need to understand how the work was produced.

11. Intellectual Property and Third-Party Content

  • Do not input third-party copyrighted material into an AI tool in a way that would breach the rights holder’s terms or applicable copyright law.
  • Treat AI-generated output as a draft that requires human editorial and intellectual contribution before it is considered AIP’s own work product; this also reduces the risk of inadvertent similarity to another party’s AI-generated output.
  • Ownership of AI-assisted deliverables produced for clients is governed by the intellectual property terms in the Terms of Business (AIP-PS-005).

12. Security

AI tools are subject to the same security expectations as any other business system:

  • Multi-factor authentication is enabled on every AI tool account wherever the provider supports it.
  • AI tool accounts use a unique, strong password managed through a password manager — not a password reused from another service.
  • Browser extensions, plugins and third-party integrations connected to an AI tool are reviewed before installation, since they can widen the tool’s access to AIP or client data.

This section will be superseded by the Information Security Policy (AIP-PS-009) once adopted, which will set out AIP’s wider security controls.

13. Quality, Bias and Professional Judgement

AI models can be confidently wrong, can reflect biases present in their training data, and can produce generic or superficial output if prompted poorly. AIP personnel remain professionally responsible for the quality, accuracy and fairness of any work product, however it was produced. Where AI is used to support advice on sensitive topics (for example, hiring, performance, or any topic touching on the protected characteristics set out in the Equality, Diversity & Inclusion Policy, AIP-PS-008), outputs are reviewed with particular care for bias before use.

14. Relationship to the Digital Workers Policy

AIP distinguishes between two categories of AI use, governed by two separate policies:

This policy (AI Usage & Governance, AIP-PS-006)Digital Workers Policy (AIP-PS-007)
Governs AI used as a tool by a human, under that human’s direct, session-by-session control.Governs AI operating as a registered digital worker with an ongoing role, identity and delegated authority within AIP.
Example: drafting a proposal with an AI assistant.Example: Hermes, AIP’s registered supervisory and governance worker.
No registration required.Registration in the Digital Workers Register (DB01) is mandatory before deployment.

Where an AI tool moves from occasional assisted use towards an ongoing, named role with standing responsibilities, it should be assessed for registration as a Digital Worker under AIP-PS-007.

15. Incident Reporting

Any material AI-related incident, suspected incident or control failure — including but not limited to any suspected unauthorised disclosure, contractual breach or other material failure affecting client confidentiality, personal data, security or the integrity of AIP’s work — must be reported to Tim Parkin as soon as it is identified. This includes, in particular:

  • Client-identifiable or confidential data entered into an AI tool that did not meet the Section 7 or Section 8 bar;
  • An AI-generated error, fabrication or hallucination that reached a client before being caught;
  • Any suspected security incident involving an AI tool account or its connected data.

Incidents will be handled in line with the breach-response approach in the Data Protection Policy (AIP-PS-003) and, once adopted, the Information Security Policy (AIP-PS-009).

16. Training and Awareness

As AIP grows beyond a sole-director operation, every person covered by Section 4 will be briefed on this policy before being given access to AIP’s AI tools, and on any material update to it thereafter.

17. Roles and Responsibilities

  • Director (Tim Parkin): owns this policy, approves new AI tools, and is the point of escalation for incidents.
  • All personnel and contractors: responsible for following this policy and for the quality and accuracy of any work product they deliver, whatever AI assistance was used to produce it.

18. Controlled Exceptions

Exceptions to this policy are expected to be exceptional and infrequent. Any temporary departure from the requirements of this policy must, wherever practicable, be approved in advance by Human Authority (currently the Director), documented with the reason, scope and duration of the exception, and reviewed once the exceptional circumstances have ended. Permanent changes to policy must be made only through the formal policy review and approval process.

Where advance approval is genuinely impracticable, the record and review should be completed as soon as reasonably possible under AIP’s established governance arrangements.

19. Review and Changes to This Policy

This policy will be reviewed at least every 12 months, and sooner if AIP adopts a materially new AI tool, if a relevant law or regulator guidance changes (for example, further ICO guidance on AI and data protection), if there is a material change in recognised industry standards or the wider AI governance environment, following any incident reported under Section 15, or where a material change to the Digital Workers Policy (AIP-PS-007) or the underlying Digital Workforce Governance Framework affects the distinction between AI tools and Digital Workers.

20. Contact

Policy owner: Tim Parkin, Director, Groundframe Ltd t/a The AI Practitioner

Email: info@theaipractitioner.ai

This policy is published by Groundframe Ltd, registered in England and Wales, company number 09715227. Questions about it go to info@theaipractitioner.ai.