Use approved tools for appropriate work
Organisations should define which AI services are permitted and what information may be processed. Confidential, personal, security-sensitive or commercially restricted data should not be entered into an unapproved service.
Verify important outputs
Generative AI can produce confident statements that are incomplete or wrong. Facts, calculations, technical instructions and references should be checked against reliable sources before they influence a decision or reach a customer.
Keep human accountability
The person using AI remains responsible for the final work. High-impact decisions involving employment, safety, finance, access or legal rights require appropriate human oversight and clear escalation.
Be transparent where it matters
Users should not imply that they personally conducted research, analysis or writing that was substantially produced by AI. Organisations need proportionate rules for disclosure, authorship and record keeping.
Protect fairness and quality
AI outputs may reflect gaps or bias in training data and prompts. Review whether recommendations disadvantage particular people, whether the data represents the population concerned and whether a human can challenge the outcome.