Resources
Responsible use and people
This pillar covers what neither technology nor contracts can settle: informing and consulting employees, the effect of AI on jobs and skills, the quality of and accountability for content produced in your name, the principles the organisation stands by, and its environmental footprint. It is often what customers, candidates and employees look at first.
General recommendations: the assessment selects those that match your situation and ranks them by priority.
Social dialogue and staff information
Introducing AI tools that change working conditions, the organisation of work or the monitoring of activity requires informing and consulting the works council. For high-risk systems, the AI Act adds the obligation to inform employee representatives and affected employees before the system is put into service. Beyond the obligation, a rollout that is explained is a rollout that is adopted.
What we recommend
- Add a “works council information and consultation” step to the AI use assessment grid, triggered as soon as the tool affects work or the monitoring of activity; prepare the presentation with the template provided.
- Write an information note for employees and candidates for each AI-assisted HR use: what the tool does, what it does not decide, who approves, how to challenge it.
- Set up a six-monthly AI meeting with employee representatives (uses, incidents, training, feedback); consider a company agreement on AI if uses become widespread.
Jobs, skills and support
AI shifts tasks more than it eliminates jobs, but it can deskill (people can no longer work without it), isolate (fewer interactions) or overload (faster turnaround is expected). Anticipating which roles are affected and supporting teams is as much a matter of workforce and skills planning as of AI governance.
What we recommend
- Map exposed roles with the grid provided (automatable tasks, augmented tasks, skills to preserve) in a workshop with managers; derive priorities for support.
- Add an AI component to the skills development plan (role-specific training, pathways for the most transformed roles) and present it alongside the AI policy.
Quality and accountability of generated content
A document, a customer reply or a publication produced with the help of AI commits the organisation as if it had been written by hand. Factual errors, reproduction of protected content, inappropriate tone: the rule is simple, published content is reviewed and owned by a named person.
What we recommend
- Add a review rule to the acceptable use policy: any content published externally is checked (facts, figures, commitments) and signed off by a person; AI produces drafts, not authors.
- Have a lawyer clarify the intellectual property rules that apply to your generated content (rights over outputs under each tool's terms, infringement risks) and summarise them on one page in the policy.
- Set up a monthly sample review of automated replies to customers (accuracy, tone, promises) with a quality indicator tracked by the owner of the use.
Principles and public commitments
What the organisation says about its use of AI — transparency, non-discrimination, human oversight, privacy, restraint — becomes a commitment to customers, candidates and partners. More and more tenders and customer questionnaires ask for it. This topic complements management's AI policy (Security pillar) with its external and ethical dimension.
What we recommend
- Write five to seven responsible use principles based on the template provided, have them approved by management and incorporate them into the policy and the AI policy statement.
- Prepare a standard answer to customer questionnaires about AI (principles, uses, providers, security measures, compliance) based on the results of this assessment; publish a short version on your website.
- Define an ethical escalation procedure (who raises issues, who decides, within what timeframe, traceability) attached to the AI committee or the risk committee, with a protected reporting channel in line with the internal whistleblowing system.
Environmental footprint
Generative AI consumes energy and water with every request, far more than a traditional search. For an organisation that consumes AI, the levers are simple: choose proportionate models, avoid unnecessary uses, ask providers for their impact data, and include AI in non-financial reporting where it exists.
What we recommend
- Add a restraint criterion to the AI use assessment grid (is the model proportionate to the task? is the use necessary?) and ask providers for their environmental impact data in the provider questionnaire.
- Estimate the footprint of your main AI uses using the AFNOR Spec 2314 framework and include it in your responsible digital or CSRD reporting; set a restraint target (for example, the share of requests handled by lightweight models).
Frameworks
- AI Controls Matrix (CSA)
- ISO/IEC 42001
- AI Act
- Other
Where does your organisation stand?
The assessment evaluates these points for your organisation and ranks the actions by priority. Free, about 15 minutes, no account needed.