DANEREE
STRATEGIC ADVISORY
Artificial intelligence

What will you say about how you use AI?

Companies and public bodies are being asked to account for their use of artificial intelligence before the regulatory framework is settled. The challenge is knowing what you can credibly say — and what must stand behind it.
The external challenge

The question is arriving before the rules.

For many organisations, AI accountability will first become real not through an enforcement notice, but through a question.

A customer

Does AI touch the product or service we are buying?

An employee

Does AI influence recruitment, assessment or monitoring?

An investor

How is the board governing AI risk and opportunity?

A journalist or regulator

What does “human oversight” actually mean in practice?

The difficulty is that there is rarely one simple answer. AI may already be embedded in software the organisation buys. Different systems may touch different decisions. Some risks arise from how the organisation deploys the technology; others arrive embedded in the model or product it has been supplied.

What can the organisation credibly say about its use of AI?
The positioning challenge

Saying too much. Saying too little.

Reassurance becomes a claim.

Claim
Responsible AIWhat governance, testing and accountability actually sit behind the phrase?
Claim
Human oversightWhat does the human see, what can they change, and can they genuinely disagree?
Claim
Rigorously testedTested for what, by whom, against which failure modes, and how recently?

Blanket silence carries a different risk. Once procurement, diligence, employees, investors or media begin asking direct questions, saying nothing can be read as uncertainty or absence of governance.

The strongest position begins with evidence. Know where AI sits, what it touches, what the organisation controls, what depends on suppliers, what has been tested and what remains uncertain. Then decide what to say.

The risk landscape

AI is not one risk.

Four different problems are often collapsed into one debate.

01

Known harms

Bias, discrimination, fraud, surveillance, abusive synthetic imagery, privacy loss and unfair decisions. AI can change the scale, speed and reach of harms we already understand.

02

Misuse

The system may work as intended; the problem is the user’s objective. Powerful AI can increase the capability of bad actors in fraud, cyber operations, surveillance and potentially dangerous weapons-related activity.

03

Unexpected behaviour

More autonomous systems may find unforeseen routes to an objective: exploiting loopholes, bypassing controls, obtaining credentials, modifying code or taking actions that were not intended.

04

Loss of control

The most uncertain category: whether future systems could become sufficiently capable and autonomous that meaningful human control becomes difficult. Uncertain does not mean irrelevant.

Different risks need different controls — and different claims.
Responsibility

The organisation using AI cannot be the only organisation responsible for it.

Much of existing law reaches artificial intelligence at the point where it is deployed: the employer, lender, insurer, public authority or business using the system.

The absence of a single UK AI Act does not mean an absence of law. Depending on the use and the facts, existing data protection, equality, employment, consumer, sector-specific and public-law obligations can already bear on AI-touched activity and decisions.

For central government, transparency has already moved further. The Algorithmic Transparency Recording Standard is mandatory for government departments and in-scope arm’s-length bodies, and for qualifying algorithmic tools with significant influence on public-effect decisions or direct interaction with the public.

But the cause of a harmful outcome may sit much further upstream. A model developer controls some capabilities. A product company determines how those capabilities are packaged and constrained. An integrator decides what the system connects to. A deployer determines how it is used in practice.

Parliament’s Joint Committee on Human Rights has recommended differentiated obligations across the AI lifecycle and supply chain, alongside stronger scrutiny of high-risk and powerful systems. Those recommendations are not yet UK law.

Evidence has to move through the chain because accountability does.

That matters to external positioning. A company cannot credibly explain the safety, limitations or oversight of a system if critical information stops with its supplier. An AI provider cannot credibly treat every downstream consequence as somebody else’s problem while controlling the evidence its customers need.

The precedent

We have seen part of this argument before.

Building the environment creates responsibilities of its own.

The analogy with social media is imperfect but useful. Regulation eventually moved beyond a binary argument about whether platforms were responsible for everything users posted. It began examining the systems and processes through which harms were created, amplified and managed.

AI takes the question further because the system can contribute directly to the outcome rather than merely distribute somebody else’s content.

Building the system does not necessarily place you outside responsibility for what the system predictably enables.
International cooperation

National regulation meets a global technology.

The model may be developed in one country, run on infrastructure in another, incorporated into a product elsewhere and deployed across Britain and Europe. The person attempting to misuse it may be anywhere.

Countries will keep different laws. But evaluation standards, incident information, dangerous capabilities and minimum safeguards cannot sensibly stop at borders.

The systems cross jurisdictions more easily than their regulators do.
Where you sit

Your position changes both your responsibility and your external account.

01

You build powerful models.

Capability, evaluation, safeguards and the evidence made available downstream are central. The external challenge is to explain capability without exaggeration, safety without false certainty and uncertainty without making the product impossible to trust.

02

You build AI products.

Some risk comes from the underlying model; some from your own product design, permissions, integrations and data. Distinguish what you have established yourself from what you rely on the model provider to tell you.

03

You use AI in decisions about people.

Credit, insurance, recruitment, claims, public services and assessment create immediate questions about fairness, transparency, contestability and whether human review is meaningful in practice.

04

You buy AI inside other products.

You may be an AI deployer without having consciously decided to become one. The first challenge is discovery: where is AI operating, what does it affect, what does the supplier know, and what changes when the model changes?

05

You use AI mainly for internal work.

Drafting, research, analysis, coding and summarisation generally create a lighter position, but clients and counterparties may still ask whether AI touches the work they receive and how confidentiality and review are controlled.

06

You govern an organisation using AI.

The board does not need to understand every model architecture. It does need to know where consequential AI sits, what the organisation depends on, who owns the risk and what evidence supports the external account.

Different audiences

There is no single AI disclosure.

A customer may ask whether AI touches the product they are buying. An employee may care whether it affects hiring or monitoring. An investor may focus on governance and operational risk. A regulator may ask for evidence about a particular decision. A procurer may ask about evaluation, data and suppliers.

Good positioning is not repeating the same statement to everybody. It is giving different audiences an accurate account of the same underlying reality.
Ask next

What to establish before somebody asks.

01
Where is AI already being used?Include systems embedded inside products and outsourced services.
02
Which uses matter most?Where does AI touch people, money, access, safety, security, rights or material public-facing outputs?
03
Which risk are you actually managing?Known harm, misuse, unexpected system behaviour or a frontier capability question?
04
What do you know from upstream?What has the supplier actually evaluated, and what remains unknown?
05
Who is named as answerable?A person, not an ambient committee responsibility.
06
What would you say tomorrow?If a customer, employee, investor, regulator or journalist asked how you use AI, what would your answer be — and what would stand behind it?
AI Position Map

Where do you sit in the AI chain?

Identify which risks bear on your position, what you need to understand upstream, what others may need from you and what you should be able to evidence.

Find your position →
Sources and status
Joint Committee on Human Rights — Human Rights and the Regulation of AIFourth Report of Session 2026–27, published 14 September 2026. Committee recommendations are proposals, not settled UK law.UK AI Security InstituteCurrent institutional information on advanced AI evaluation and security.Algorithmic Transparency Recording Standard — GOV.UKMandatory for government departments and in-scope arm’s-length bodies for qualifying algorithmic tools; broader public-sector use remains recommended.EU AI Act — European CommissionThe Act is in force and applies progressively; which obligations bear on an organisation depends on its role, system, use and timing.
General information only. Daneree publications and tools are provided for general information and discussion purposes. They do not constitute legal, regulatory, compliance, tax, financial, investment or other professional advice and should not be relied on as such. Information may be incomplete or become out of date. Obtain appropriate independent advice before acting. See Terms of Use.