
Your AI demo works. Then it meets real data, deadlines, more users, a changing supplier - and the owner is absent when something goes wrong.
A demo proves possibility. Production requires ownership of the outcome, evidence, operating limit and stop decision.
Answer in 60 seconds
- Start with one business workflow, not a company-wide AI programme.
- Choose an operating default: allow, assist, review, disclose, restrict or block.
- Do not release until ten questions about ownership, data, testing, review, security, monitoring and fallback have usable answers.
- Apply different controls to operations, public content and production code.
- Pause for legal, privacy, employment, IP, security or sector review when the facts trigger it.
For an SME, governance can be one current operating record with owners and workflow evidence - not a compliance badge or safety promise.
In this article
- A working AI demo is not a production system
- Choose: allow, assist, review, disclose, restrict or block
- Use this ten-question production gate
- Operations, content and code need different controls
- What to do in the first ten working days
- When to pause and bring in a specialist
- Conclusion
- Frequently asked questions
- Sources
1. A working AI demo is not a production system
AI use is already material: Eurostat reported that 20.0% of covered EU enterprises with at least ten people employed used AI in 2025. The frame excludes smaller micro-enterprises and some sectors; it measures use, not maturity, demand or return.
A demo has favourable inputs and a builder nearby. Production adds workload, unusual cases, customer consequences, provider changes, incidents and maintenance.
Govern the complete workflow: people, process, data, model, retrieval, tools, suppliers, destinations and recovery. The voluntary, non-prescriptive NIST AI Risk Management Framework connects governance, context, measurement and response; using it does not prove a control works in your system.
Could a named owner explain the release, supporting evidence, stop condition and who can execute it?
2. Choose: allow, assist, review, disclose, restrict or block
Approve a use, not a tool in the abstract.
| Default | Use it when | Minimum control |
|---|---|---|
| Allow | Reversible, low-consequence internal work | Approved tool, owner, input rules, user check |
| Assist | A person remains the primary creator or analyst | Task boundary, approved sources, competent owner |
| Review | Output may affect customers, operations or brand | Tested cases, approver, traceability, correction |
| Disclose | The context creates a transparency decision | Scope decision, relevant notice or marking, record |
| Restrict | Sensitive data, code, privileges or material actions | Least privilege, stronger tests, staged release, specialist input |
| Block | Ownership, lawful use, critical tests or recovery are missing | Redesign or qualified decision before re-evaluation |
Categories can combine: allow ideation, review publication, restrict confidential inputs and block automatic publishing.
Set control depth from consequence, reversibility, sensitivity and agency. Small-company status does not make a consequential use harmless. Binding rules override the default. The EU AI Act and GDPR can create role- and use-specific duties; this table neither classifies your system nor establishes compliance.
3. Use this ten-question production gate
Before a workflow receives production data, reaches an external audience, changes code or acts through tools, answer these questions:
- Purpose and owner: what task and outcome are in scope, and who owns the decision?
- Baseline: what happens without AI, including rework, review burden and failure consequence?
- System boundary: which service, version, instructions, sources, plugins and destinations are involved?
- Data and rights: what personal, confidential or protected material enters or leaves the flow?
- Consequence and authority: what may the system propose or do, and what remains human-owned?
- Acceptance evidence: which normal, edge, refusal and abuse cases were tested; which failures remain?
- Human responsibility: can the reviewer recognise and reject an error under real workload?
- Security and supplier controls: which permissions, components, changes, incidents and exit conditions are controlled?
- Operations: which signals have an owner, threshold, permitted response and appropriate retention rule?
- Fallback and change: how will the team restore a known-safe or manual route, and which change reopens approval?
Keep one production record linked to tests and decisions. The cited guidance does not provide a universal score, test-set size or risk-reduction percentage; evidence must fit the use and consequence. The NIST AI RMF Playbook is a voluntary resource, not a checklist that produces a release verdict.
4. Operations, content and code need different controls
One policy cannot replace workflow-specific control.
Operations
Limit what the system may see, recommend and execute. Start in an isolated route; name abort conditions, alert owners and a manual fallback. Measure review, correction, incidents, maintenance and operating cost - not generation speed alone. The NCSC secure-AI guidelines are principle-level guidance, not assurance.
Content
Separate factual checks, rights, brand review, disclosure and correction. Fluency passes none by default. The final Article 50 transparency code is voluntary and scope-specific; not every AI-assisted item is covered. The Commission and AI Board assessed it as adequate for relevant obligations, but adherence is not conclusive evidence of compliance. Scope remains a specialist decision.
Code
Treat AI-assisted code as an untrusted contribution under human ownership. Protect repositories and credentials, review the full diff, derive tests from requirements and keep secure-development gates. The NIST Secure Software Development Framework is a high-level structure, not certification.
5. What to do in the first ten working days
Use the first ten working days to make one workflow visible and testable:
- Name the business owner, technical owner and specialist contacts.
- Select one bounded use with a visible baseline and reversible pilot path.
- Inventory users, data, versions, retrieval, plugins, permissions and destinations.
- Record affected people and screen legal, privacy, employment, IP, security and sector triggers.
- Set the allow/assist/review/disclose/restrict/block defaults.
- Define accepted outcomes, severe failures, refusal cases and review.
- Confirm approved data, rights, retention, provider reuse and transfer questions.
- Create an isolated pilot with least privilege and a manual fallback.
- Agree signals, owners, permitted actions, incident authority and change triggers.
- Route unresolved consequential decisions before exposure.
This is not a ten-day production promise. It exposes the first real control gap; the outcome may be a pilot, redesign, specialist decision or stop.
6. When to pause and bring in a specialist
Pause before exposure when the workflow involves:
- prohibited- or high-risk-use questions, provider/deployer roles, conformity or Article 50 scope;
- personal or special-category data, automated decisions, transfers, monitoring or a possible data protection impact assessment (DPIA);
- hiring, worker evaluation, allocation, surveillance or material changes to work;
- training or source-data rights, licences, reservations, similarity or important output ownership;
- privileged actions, internet exposure, sensitive architecture, vulnerabilities or an incident; or
- health, finance, insurance, education, critical infrastructure, public services or regulated products.
IZZY can map the workflow, evidence and decision points. Qualified specialists own the legal, privacy, employment, IP, security, conformity and sector conclusions.
Conclusion: production requires ownership
A policy matters only when it changes a workflow. Set one operating default, close the ten-question gate and preserve a working fallback.
Sometimes the answer is a smaller AI role - or none. That is still a useful decision.
Bring one AI workflow. We’ll give you an honest read.
Bring your policy or tool list and available evidence. In 30 minutes, we’ll give you an initial, bounded read on whether the workflow is ready for a bounded pilot, is missing a production control, needs a specialist decision or should stay out of production.
Frequently asked questions
A demo shows capability on selected inputs. A production-ready workflow has an owner, defined boundaries, acceptance evidence, competent review, monitoring, an incident path and an executable fallback.
A small business needs operating rules when AI affects staff, customers, data, content, code or systems. Keep them proportionate and connect approved uses to owners, evidence, escalation and stop authority.
Include approved tools, permitted and prohibited uses, data restrictions, review responsibility, content and code rules, incident reporting, supplier changes and stop authority.
Ask where unregistered use occurs and why. Offer a usable approved path, protect sensitive inputs and escalate consequential uses; prohibition alone may not remove the underlying need.
SME status is not a universal exemption. Applicability and duties depend on the system, intended purpose, role, modifications and facts. Obtain qualified advice for client-specific classification or legal conclusions.
Sources
- Eurostat: The use of artificial intelligence technologies in the European Union - key results, 2026 edition
- NIST: Artificial Intelligence Risk Management Framework 1.0
- NIST: AI RMF Playbook
- UK NCSC and international partners: Guidelines for Secure AI System Development
- NIST: Secure Software Development Framework 1.1
- European Union: Regulation (EU) 2024/1689 - Artificial Intelligence Act
- European Union: Regulation (EU) 2016/679 - General Data Protection Regulation
- European Commission: Code of Practice on Transparency of AI-Generated Content
- European Commission and European AI Board: assessment of the Transparency Code
How this was prepared: evidence-led synthesis from official statistics, public frameworks, regulator and legal sources, and IZZY’s signed internal evidence dossier. Sources and legal/guidance status checked 13 July 2026. This is general operational information, not legal advice, a security or conformity assessment, or a forecast of commercial results.