7 questions to ask before you approve a new AI tool

A short checklist for whoever signs off AI tools: seven questions that keep data leaks, shadow AI and EU AI Act duties in view before you say yes.

Sooner or later someone asks to use a new AI tool, and you are the one who says yes or no. Most of the risk in AI adoption is decided at that moment, not later. These seven questions are the ones worth asking before you approve anything, and together they are most of what an AI policy is for.

1. What data goes into it, and where does that data go?

Start with the data, because it is the part you cannot take back. What will staff paste or upload, and does the tool send it to a third party, use it to train a model, or store it outside the UK? Anything covered by UK GDPR, customer information, or commercially sensitive material needs a clear answer before a single account is created.

2. Does it make or influence a decision about a person?

A tool that drafts marketing copy is a different proposition from one that screens job applicants, scores creditworthiness, or ranks people in any way. Systems that make or materially influence decisions about individuals are the kind the EU AI Act treats most seriously, and they carry obligations others do not. If the answer is yes, the approval bar rises.

3. Who checks the output before it reaches a customer?

AI-assisted work still needs a human who is accountable for what goes out. Decide who reviews it and against what standard, before the tool is in daily use rather than after a mistake. “The model is usually right” is not a review process.

4. Does anyone need to be told they are dealing with AI?

The EU AI Act’s transparency duties, in Article 50, can require you to tell people when they are interacting with a chatbot, to label synthetic or manipulated media, and to disclose emotion recognition or biometric categorisation where you use it. If the tool talks to your customers or generates content they will see, work out what has to be disclosed.

5. Is it on the approved list, and who signs off if it isn’t?

Every tool approved outside a known route is how shadow AI starts. Keep a list of what staff may use, and a single, quick way to request a new one. The point is not to say no to everything; it is to make sure the yes is a decision someone made on purpose, and that you can see the pattern across teams.

6. What happens when it gets something wrong?

Assume it will. Who does a member of staff tell, and what happens next? A tool without a route for reporting a bad output or a data slip means problems surface late, if at all. A one-line reporting path is cheap to set up and worth a great deal when you need it.

7. Who owns it after today?

An approval is not the end. Someone has to own the tool, keep it on the right list, and revisit the decision when the tool changes, the vendor changes its terms, or your obligations do. Name that person, and give the decision a review date, or the approval quietly goes stale.

Turn the answers into a policy

Asked once, these questions protect a single decision. Written down, they become the policy that lets everyone else make the same call without coming to you each time. The free AI policy generator turns your answers into an editable draft, and the EU AI Act check works out which of the Act’s duties reach your tools. Both are starting points for internal review, not legal advice.