5. Putting it into practice
Workplace scenarios
Scenario 1: The resourceful analyst
During a one-to-one, an analyst mentions that she has been using a free AI chatbot on her personal account to summarise client meeting notes. It saves her an hour a week, nobody ever told her she couldn't, and the firm has no approved alternative.
What good looks like: her manager thanks her for being open and treats the discovery as information about genuine demand, not as a disciplinary matter. He establishes exactly what data went into the tool and whether any of it was client confidential, and escalates that question if it was. He then pushes for an approved tool and a clear one-page policy, so the safe path becomes the easy path instead of the unofficial one.
Scenario 2: The urgent rollout
A team lead is excited about an AI transcription tool and wants everyone using the free tier by Friday. It would record client calls, and the vendor's website says little about data handling.
What good looks like: the firm slows down just enough to do it properly. Someone gets written answers on whether input trains the vendor's models, where data is stored, and how long it is retained, and compares the free tier's terms against a business tier. Because call recordings contain personal data, a proportionate DPIA is done. A small pilot with success criteria that could genuinely fail runs before any firm-wide rollout.
Scenario 3: The pasted spreadsheet
A junior pastes a spreadsheet containing customer names and contact details into a consumer chatbot to tidy the formatting, then realises the tool was not approved and tells his manager the same day.
What good looks like: the manager stays calm and treats the honest report as exactly the behaviour she wants repeated. The incident is assessed promptly as a potential personal data breach, remembering that UK GDPR's 72-hour ICO notification clock applies where a breach is reportable. The use is contained, the facts are recorded, and the fix targets the gap that allowed it, such as training or an unclear policy, rather than blame theatre.
Scenario 4: The CV sifting shortcut
HR proposes using an AI tool to rank job applications and automatically reject the bottom half, so managers only read the strongest CVs.
What good looks like: the firm recognises this as a significant decision about people. Recruitment is exactly the kind of use the EU AI Act treats as high-risk, and under UK GDPR applicants are generally entitled to meaningful human involvement. Automatic rejection with no human review is redesigned so a person with real authority, time, and information reviews outcomes and can reach a different conclusion. A DPIA is completed, and the tool's fairness across different groups is examined before anyone relies on it.
› Course contents
Why AI needs governing
The regulatory landscape
Building your AI policy and approving tools
Running AI day to day
Putting it into practice