How to Build an AI Tool Approval Process Your Team Will Actually Use

 

In most companies, the decision to start using an AI tool is made by the person who discovers it, not by the person who should be approving it. Someone comes across an application in a demo, tries it, sees its potential and, within a few days, is using it with real company data. When there is no clear and straightforward way to request approval, people simply start using the tool. Putting a proper process in place is what separates a company that knows which AI tools it is using from one that only discovers what has been in use when something goes wrong.

Why the absence of a process creates more risk than AI itself

When there is no approval process, every tool that enters the organisation does so without anyone having checked what data it processes, where those data are stored, what the provider’s contract says or what safeguards it offers. The result is a silent accumulation of risks that the organisation may not even have identified, simply because it does not know what tools are being used.

The problem also feeds on itself. If the only official way to introduce a tool is slow, bureaucratic or non-existent, teams will bypass it out of sheer necessity. Unauthorised use then becomes the norm. The most effective way to reduce this kind of shadow use is not to impose stricter bans, but to offer an alternative that is so straightforward and agile that bypassing it is no longer worth it.

What does a process that people actually use look like?

An approval process works when it is fast, clear and proportionate to the level of risk.

Fast means that requesting a tool review takes no more than a short form and that the response arrives within days, not weeks. A process that takes a month simply encourages people to bypass it.

Clear means that everyone knows who to contact and what information they need to provide.

And proportionate to the risk means that you do not examine a tool that does not process sensitive data with the same level of scrutiny as one that will handle customer information. The first may be approved almost immediately; the second warrants closer review. A process that treats every tool in exactly the same way will only end up being slow for low-risk cases and superficial where scrutiny actually matters.

What should you look at during the assessment?

When assessing an AI tool, there are several questions that should always be answered.

  1. What data will it process, and how sensitive are they? This becomes much easier to determine if the organisation already has a data classification system in place.
  2. Where will those data be processed and stored, and will they leave the European Union?
  3. What does the provider’s contract say about the use of the information, particularly whether it may be used to train its models, and does the provider offer a data processing agreement that complies with the GDPR?
  4. Who within the organisation will be responsible for the tool once it has been approved? This is not a technical interrogation. It is the minimum information needed to understand what the organisation is committing to when it says yes.

Who decides, and how is it documented?

A process requires someone to have the authority to say yes or no, and for that decision to be recorded. You do not necessarily need a dedicated committee. In many organisations, a designated person — often in IT or compliance — can centralise requests and make decisions, escalating only the cases that carry greater risk.

What matters is recording which tool has been adopted, for what purpose, under what conditions and who approved it.

This documentation is not bureaucracy. It is what allows an organisation to demonstrate due diligence if, one day, a client, an auditor or a data protection authority asks why a particular tool was being used.

It also means maintaining an active, searchable catalogue of approved applications, rather than relying on knowledge that exists only in someone’s head.

Frequently asked questions

How can I prevent my team from using AI tools without authorisation?

Offer an approval process that is so agile that bypassing it is not worth the effort: a short form and a response within a few days. Unauthorised use tends to grow when the official route is slow or does not exist. The solution is therefore not simply to prohibit more forcefully, but to make authorised use easier.

What should I assess before approving an AI tool?

What data it will process and how sensitive they are; where those data will be stored and whether they will leave the EU; what the provider’s contract says about the use of those data; whether it offers a data processing agreement that complies with the GDPR; and who will be responsible for the tool within the organisation.

Do I need a committee to approve AI tools?

Not necessarily. In many organisations, a designated person — typically within IT or compliance — can centralise requests and escalate only the highest-risk cases. What matters is that someone has the authority to make the decision and that each decision is properly documented.

Raquel López Hernández, fundadora de Ethiceye y consultora en IA responsable

Raquel López Hernández

Raquel López Hernández is the founder of Ethiceye, a consultant and trainer specialising in responsible AI, AI governance and AI literacy. With a long career in education, she collaborates with the European Commission’s European Digital Education Hub on initiatives relating to AI literacy and ethics.

She has trained teachers from across Europe at the Europass Teacher Academy (Florence) and supports schools and organisations in developing frameworks, policies and strategies to integrate AI in line with their own criteria.

Contact with Raquel López
Privacy Summary

This website uses cookies so that we can offer you the best possible user experience. The information from the cookies is stored in your browser and performs functions such as recognising you when you return to our website or helping our team to understand which sections of the website you find most interesting and useful. You can see our Privacy Policy.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

Analytics

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.