Responsible AI
Use AI where it creates value—and govern the risks it introduces.
Responsible AI should cover use-case selection, data, models/providers, evaluation, access, human oversight, deployment and monitoring.
01Responsible AI principles
Human agency
- Body
- Preserve meaningful human control for high-impact or irreversible decisions.
Privacy & data governance
- Body
- Use data lawfully, minimize unnecessary data and control access.
Security
- Body
- Address prompt injection, tool abuse, data leakage and non-human identity risks.
Transparency
- Body
- Make material AI use visible where appropriate.
Evaluation
- Body
- Test representative tasks and failure modes before production.
Fairness
- Body
- Assess material bias/unequal impact where the use case creates those risks.
Reliability
- Body
- Use monitoring, fallbacks and escalation appropriate to the use case.
Proportionality
- Body
- Increase controls as potential harm and autonomy increase.
Accountability
- Body
- Assign business and technical owners.
02Illustrative AI risk tiers
- Drafting assistance
- Non-sensitive summarization
- Level
- Low
- Controls
- Basic review
- Approved tools
- Enterprise search
- Customer-service assistance
- Code assistance
- Level
- Moderate
- Controls
- Access control
- Evaluation
- Human review
- Monitoring
- Material decision support
- Agents executing sensitive actions
- Level
- High
- Controls
- Formal risk assessment
- Stronger evaluation
- Least privilege
- Human authorization
- Audit trail
- Legal review
03AI lifecycle controls
- Use-case assessment
- Data/privacy assessment
- Provider/model review
- Security threat model
- Evaluation plan
- Human-oversight design
- Deployment controls
- Monitoring and incident handling
- Periodic re-evaluation
- Retirement/change management
04Prohibited/restricted uses
Review required
High-impact AI use requires explicit assessment.
Fuchsius reviews AI uses that could materially affect people, sensitive data, security or consequential decisions before design or deployment. Controls and approval requirements depend on the specific use case.
Discuss an AI use caseThis document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.