Your organisation's AI doctrine
One common rule that can be enforced, instead of each department deciding on its own.
The problem
Uses are multiplying without a common rule. Each department arbitrates on its own between a convenient online service and a confidentiality requirement it interprets in its own way. Nobody can say what is allowed.
How we proceed
- 01
Inventory of real uses, including those that escape the IT department. It is the starting point, and often the most instructive moment of the engagement.
- 02
Decision grid between a hosted open model and a third-party service, use case by use case, according to data sensitivity and the performance genuinely required.
- 03
Data and retention policy: what comes in, what is kept, for how long, and what never leaves.
- 04
Governance and decision bodies: who arbitrates, how often, against which criteria.
- 05
AI Act compliance: classification of systems, provider and deployer roles, technical documentation, traceability, risk assessment.
- 06
An enforceable internal usage charter, written to be read by the business and not by lawyers.
Deliverables
- Doctrine document
- Decision grid usable by the business
- Internal usage charter
- AI Act compliance roadmap
Indicative duration
Four to six weeks.
Who this is for
Executive management, general secretariats, legal and compliance departments.
