AI Use on This Project

Purpose

This document sets out how this project approaches the use of AI tools: our position, the people responsible for AI governance, and where to find the framework we follow.

We use the Practical Risk-Based Approach to AI Use on Delivery Projects framework to assess and manage AI use. This document summarises our local application of that framework.

Our approach

AI tools can improve the quality and efficiency of delivery work when used responsibly. Our approach is:

Responsible people

Role Name Responsibilities
Senior Responsible Owner (SRO) [Name] Overall accountability for AI use on the project. Approves medium- and high-risk use cases, and new tools.
Delivery Lead [Name] Day-to-day oversight of AI use. Reviews the project's risk assessments periodically.
Technical Lead [Name] Assesses technical risks, tool suitability, and security implications. Reviews mitigations for coding and product feature use cases.
Data Protection Lead [Name] Advises on data classification, PII handling, and DPIA requirements. Reviews use cases involving personal data.

Tool register

The following AI tools have been assessed. Each has a profile recording what it does and what its supplier promises. A profile is not permission to use the tool for a given task. That is decided by the risk assessment for each specific use.

Tool (and tier) Highest classification cleared What it is, in short Full profile Last reviewed
[e.g. GitHub Copilot Business] [e.g. OFFICIAL] [e.g. Cloud-hosted, EU processing, no training on inputs, can run an agent mode that edits files and opens PRs] [Link] [Date]

Do not use a tool that is not on this register. If you want to use a new one, speak to the Technical Lead and complete a profile using the tool profile template.

If your data is above a tool's cleared classification, escalate to the SRO before using it.

Do not use free or consumer versions of AI tools (e.g. free ChatGPT, consumer Claude) for any work-related information.

How to assess a new AI use case

Before using AI for a new activity, follow the four-step assessment process:

  1. Scope your use: define the activity, categorise it, record how much the AI is allowed to do on its own, and assess what code and data you will share
  2. Check the tool: confirm it is on the register, not excluded, and cleared for your classification, and pick up the facts its profile records
  3. Assess the risks: identify the risks that apply to your use, then take each one through the same loop: rate it before mitigations, choose mitigations, and re-rate what is left
  4. Approve, record and do the work: get the sign-off the overall inherent level requires, save the assessment, follow the relevant checklist, and share what you learned

For full details, see the framework documentation.

Training and awareness

Before using AI tools on this project, all team members should:

Review

This document should be reviewed when:

Date Reviewed by Changes
[Date] [Name] Initial version