Responsible AI

10 Practical Principles for Responsible AI

A compact operating guide for using AI at work or building it into a product — focused on controls that still make sense as models change.

Ten principles you can actually use

Define the task and the boundary

Be explicit about what the AI is allowed to decide, recommend or execute — and what remains a human responsibility.

Ground important claims

Connect factual work to trusted documents, data or current sources. Verify the evidence, not just the wording of the answer.

Use the least privilege

Give agents only the data and tools required for the current task. Read-only is safer than write access; scoped access is safer than administrator access.

Put approvals before irreversible actions

Payments, deletion, publishing, external messages and permission changes should have an explicit approval boundary where appropriate.

Minimize sensitive data

Do not send or retain more personal, confidential or secret information than the task requires.

Test failures, not just demos

Evaluate edge cases, ambiguous inputs, adversarial content, prompt injection, missing data and tool errors.

Make uncertainty visible

Design outputs so users can distinguish sourced facts, inference, estimates and unknowns.

Keep useful logs

For automated workflows, record what the system received, which tools it used, what it changed and when approvals occurred.

Provide a way to recover

Prefer reversible actions, drafts, versioning and rollback. When something cannot be undone, raise the approval standard.

Re-test after change

New models, prompts, tools and data sources can alter behavior. Important workflows should be evaluated again after material changes.

For personal use

For teams and products

Before you automate

Ask three questions: What can it read? What can it change? What happens if it is wrong? Those answers should determine permissions, approvals and monitoring.