Your baseline risk-surface audit
This is the anchor for everything that follows. Block 60–90 minutes and pull in one person from each of a few functions — you will miss things working alone. The goal is an honest inventory, not a clean one: surprises are the point. Start by mapping the footprint and listing every place AI is used, or plausibly used, in your area.
Why this is a leadership problem, not an IT ticket
- AI entered your organization through everyday decisions, not a strategy, so your real risk surface is wider and quieter than your tool list suggests.
- The exposure is governed by how AI is used — data sensitivity and decision stakes — not by which model you bought.
- The central tension is fast adoption against slow oversight; closing that gap is the whole job.
- You now have two artifacts to carry forward: a scored footprint audit and a baseline self-assessment number.
Four ordinary uses, four different exposures
Walk through how the same casual adoption produces very different stakes. These are role-based situations already happening in most mid-sized companies — like marketing drafting ad copy with a public chatbot, where data sensitivity and decision stakes both stay low.
The principles-to-practice converter
Run this on the highest-scoring workflows you flagged in your audit. Take one workflow and one pillar — fairness, privacy, security, or transparency — at a time. Try to do all four at once and you will write mush.
Draft your one-page operating commitments
Pull your top three workflows from the audit. For each, run the converter against the one or two pillars that scored highest in sensitivity or stakes — you do not need all four for every workflow.