AI Guides › Judgement & Guardrails
By Nigel Guy · 2 min read
AI tools tend to arrive in a workplace one at a time, adopted individually by whoever found them useful, plugged into whatever task was in front of them that week. Nobody sits down and decides the overall footprint. Which means, months later, there's usually no single person who could actually answer "everywhere AI touches our work, what goes in, and who checks what comes out" — until something goes wrong and everyone realises that question should have had an owner.
The rule: build one map of everywhere AI touches your actual work, once, and keep it current — the risk isn't any single tool, it's the sprawl nobody has looked at all at once.
Build a simple table, one row per tool or workflow:
| Tool / workflow | What data goes in | What the output is used for | Who reviews before it's acted on | Reversible if wrong? |
|---|---|---|---|---|
| e.g. drafting client emails | client names, correspondence history | sent directly or lightly edited | — | usually not |
| e.g. meeting summaries | full transcript | shared with the team | one person skims it | mostly |
Skip trying to audit every personal, low-stakes individual use of AI across the team — that's not proportionate and it isn't what causes incidents. Focus on where the output leaves your control: client communication, published content, financial figures, anything feeding a decision someone else relies on. Skip treating this as a one-off exercise too; a map from a year ago is a map of a different set of tools.