Legal
Responsible use starts with authority and scope.
Keep a named person accountable for decisions and operations involving AI agents.
Delivery principles
- Authorise tests and changes before running them.
- Minimise access to data and systems.
- Keep consequential decisions with the responsible human or client process.
- Document limits, failed tests and untested paths.
- Distinguish recommendations from permission to execute.
- Review the effect of capability changes before widening access.
Boundaries
Security assessment does not replace privacy, safety, fairness, accessibility or legal reviews. Relevant requirements and accountable owners must be identified for each engagement.