Most organisations beginning to take AI seriously eventually write an AI policy.
That is sensible.
The policy might say which tools employees can use, what information must not be entered into them, when human review is required, and who is accountable.
But there is a problem.
A policy can tell you what should happen.
It does not necessarily tell you how to design the work so that it actually happens.
As AI moves from helping people write and research towards making recommendations, using tools and executing parts of business processes, that distinction becomes increasingly important.
The question is no longer simply: “Are we allowed to use AI?”
It becomes: “How do we put AI into real work without losing control of judgement, accountability and risk?”
That is the problem the TRIAI AI Governance Playbook is designed to address.
And many of its underlying ideas align closely with principles set out in the UK Government's Artificial Intelligence Playbook.
The UK Government starts with ten principles
The UK Government's Artificial Intelligence Playbook sets out ten principles for the safe, responsible and effective use of AI within government and public-sector organisations.
In summary, they call on organisations to: understand AI and its limitations; use AI lawfully, ethically and responsibly; use AI securely; maintain meaningful human control at the right stage; manage the full AI lifecycle; use the right tool for the job; be open and collaborative; involve commercial expertise from the start; have the necessary skills and expertise; and put appropriate policies and assurance around AI.
There is an important qualification here.
The Government Playbook is guidance for government and public-sector organisations. It is not a regulatory code for private businesses.
But it provides a useful reference point because it shows how the UK Government itself thinks about responsible AI adoption.
Several of its principles are highly transferable: use AI for a defined purpose; understand its limitations; maintain meaningful human control; manage risk throughout the lifecycle; use appropriate assurance.
The principles are relatively easy to agree with.
Putting them into practice is harder.
Where exactly should the human sit?
Take one of the Government Playbook's strongest principles: have meaningful human control at the right stage.
Few boards would disagree.
But immediately another question appears: where exactly is the right stage?
Imagine AI being introduced into invoice processing.
Should a person check every field the AI extracts? Review every invoice? Approve every coding decision? Review only exceptions? Approve payments? Or intervene only when a transaction exceeds a defined risk threshold?
“Keep a human in the loop” does not answer those questions.
They are operating-model decisions.
Put humans everywhere and the organisation may retain much of the cost and delay it hoped AI would remove.
Remove humans everywhere and it may automate decisions for which somebody still needs to exercise judgement and remain accountable.
The real challenge is therefore not simply keeping humans involved.
It is deciding: where does human judgement genuinely belong?
Judgement Architecture
This is where the TRIAI Playbook starts.
It distinguishes between two broad categories of work.
Machine execution — routine decisions, repeatable actions, classification, extraction, routing, standard-path processing.
Human judgement — trade-offs, exceptions, risk ownership, context, consequential decisions, accountability.
The objective is neither to keep every decision human nor to maximise machine autonomy.
It is to establish the right boundary between the two.
We call this Judgement Architecture.
For important decisions in a redesigned process, we should be able to answer: What can the machine prepare or execute? What requires human judgement? Who is the named human accountable? When must the machine escalate? What evidence needs to be retained?
That turns “human in the loop” from a principle into an operating design.
Human approval is not necessarily human control
There is a subtler problem.
Putting an approval button into a workflow does not automatically create meaningful human control.
Imagine an AI system makes hundreds of recommendations every day.
A person must click Approve on each one.
Initially they inspect the recommendations carefully.
Then the system proves reasonably accurate.
Review time falls.
Overrides become rare.
Eventually the person approves recommendations almost automatically.
Technically, there is still a human in the loop.
Operationally, the machine is making the decision.
The human has become a rubber stamp.
That is why the TRIAI Playbook uses a stronger principle: named humans remain accountable. Machines prepare — and may execute within bounds.
And why governance should watch for signals such as declining review time, weak override rationale, unusually low challenge rates, and language such as “the system says…”
Meaningful human control has to be meaningful in practice, not merely visible on a process diagram.
Autonomy is not the enemy
This does not mean AI should only provide decision support.
Modern AI systems can retrieve information, use tools, interact with software, plan sequences of work and execute actions.
There are many situations where allowing them to do so is precisely where the business value lies.
The principle should instead be: AI may execute autonomously within defined boundaries. Accountability cannot be delegated to a machine.
The important questions are therefore: how much authority should the system have? Under what conditions? What must it escalate? What happens when confidence is low? And what evidence do we require before giving it more autonomy?
The TRIAI Playbook approaches this through a maturity path: Assist → Route → Act → Orchestrate → Govern.
The principle underneath it is more important than the labels: earn the right to move right.
An organisation should not move from AI assistance to autonomous execution simply because the technology makes it possible.
Greater autonomy should follow evidence — capability tested, risk understood, architecture and security reviewed, decision traces examined, human ownership established, controls demonstrated.
Only then should authority expand.
This becomes particularly important with agentic AI.
An AI system drafting a paragraph and an AI system capable of changing a customer record may use similar underlying intelligence.
But they do not create the same operational risk.
Capability can increase quickly. Authority should increase deliberately.
Start with the problem, not the AI
Another Government Playbook principle is: use the right tool for the job.
It sounds obvious.
In practice, AI adoption frequently starts the other way around.
An organisation acquires an AI platform.
Someone demonstrates an impressive model.
Then comes the question: “Where can we use this?”
The Government Playbook takes a more disciplined view. Generative AI is not the answer to every problem. The goal and user need should come first.
That is also central to the TRIAI approach.
We start with: what outcome are we trying to improve? Then: how does the work currently get done? Where are the important decisions? Where does human judgement create value or carry accountability?
Only after that should we determine what AI should do.
Sometimes the answer will be generative AI. Sometimes an agent. Sometimes conventional automation. Sometimes redesigned workflow.
And sometimes the responsible answer will be: don't use AI here.
Knowing when not to deploy AI is part of responsible AI adoption.
Ethics becomes real at the point of decision
“Ethical AI” can easily become abstract — fairness, transparency, accountability, explainability, human control.
These principles are important, but businesses eventually have to translate them into actual processes.
Consider an AI system recommending whether a customer receives a particular outcome.
The ethical questions suddenly become concrete.
What information is the system allowed to consider? Could the process unfairly disadvantage particular people? Can somebody challenge the outcome? What happens when confidence is low? Who owns the final decision? What evidence is retained?
This is where ethical AI becomes operational.
TRIAI does not replace legal counsel, privacy specialists, cybersecurity teams, risk functions or specialist ethics expertise.
An Owner's Engineer should not pretend to possess every specialist discipline.
Our role is to ensure that the relevant questions and disciplines are brought into the design — and that the implemented system does not quietly bypass the resulting decisions.
Safe adoption needs independent challenge
Good design is not enough.
There can be a significant gap between what the organisation intended and what eventually gets implemented.
That is familiar in engineering.
The organisation paying for an asset has different interests from the supplier designing or building it.
This is the origin of the Owner's Engineer concept.
Applied to AI, the principle is similar.
TRIAI does not sell the AI platform. We do not build the customer's AI system. We do not host it.
We represent the organisation adopting AI.
Our role is to help establish what outcome the organisation is trying to achieve; how the work should be redesigned; where human judgement should remain; what authority AI should receive; what risks and controls need consideration; and what evidence should demonstrate that the intended design has actually been delivered.
Then comes Implementation Assurance.
In simple terms: design what should happen. Let the chosen implementation team build it. Verify that what was built matches what was approved.
The people selling or building a system naturally have an interest in demonstrating that it works.
The organisation adopting it needs somebody asking a different question: does this actually serve the owner's interests?
That is the independent side of the table.
Assurance should test outcomes, not intentions
The Government Playbook also calls for appropriate assurance.
For TRIAI, assurance should not mean producing a governance document and filing it away.
It means testing claims.
If a system is supposed to escalate low-confidence decisions, prove that it does.
If a human must approve high-risk transactions, verify that the system cannot bypass the control.
If AI is supposed to use only approved information, test the boundary.
If management expects an audit trail, inspect whether the evidence actually exists.
If a pilot is supposed to improve an outcome, measure the outcome.
The distinction is simple: governance describes the intended control. Assurance provides evidence that the control works.
This is why controlled pilots should be evidence-generating exercises, not demonstrations designed to prove that AI is impressive.
A pilot that concludes AI should not be deployed in a particular process can still be successful.
It may have prevented a bad investment.
Governance does not end at go-live
The Government Playbook also stresses management of the full AI lifecycle.
That matters because AI systems change — models, data, prompts, integrations, business processes, user behaviour, and threats.
And organisations may gradually give AI more authority.
A system that was relatively low risk when it summarised information can become substantially more consequential once it can update customer records or execute transactions.
Governance therefore cannot end when the system goes live.
The questions continue: is the system still performing as intended? Are humans still exercising meaningful judgement? Are override patterns changing? Has the model changed? Has the risk profile changed? Should autonomy expand, contract, or stop?
This is why TRIAI treats adoption as a progression rather than a deployment event — Assess → Redesign → Scale, with continuing review.
From principles to operating reality
The relationship between the Government Playbook and the TRIAI Playbook can be summarised simply.
Not every Government principle maps directly to TRIAI — nor should it.
The Government Playbook is a broad framework for the responsible use of AI within government.
The TRIAI Playbook has a different purpose: an owner-side discipline for turning responsible-AI principles into operating decisions and implementation evidence.
Read the operating detail in the TRIAI AI Governance Playbook.
UK Government principle → TRIAI operating response
| UK Government principle | TRIAI operating response |
|---|---|
| Understand AI and its limitations | Test capability before increasing reliance |
| Use AI lawfully, ethically and responsibly | Bring risk, accountability and specialist disciplines into process design |
| Use AI securely | Require architecture and security consideration before authority expands |
| Meaningful human control | Design explicit judgement boundaries and named ownership |
| Manage the AI lifecycle | Assess → Redesign → Scale, with continuing review |
| Use the right tool for the job | Start with the business outcome, not the AI |
| Have appropriate skills | Bring together business, technical, risk and specialist expertise |
| Have the right assurance | Independently verify implementation against the approved design |
Having AI governance is not the same as governing AI adoption
This may be the most important distinction.
An organisation can have an AI policy, an AI committee, approved tools, a risk framework, and mandatory training — and still implement AI badly.
Because serious adoption eventually requires decisions about the work itself.
What should AI do? What should it not do? Which decisions remain human? Who remains accountable? How much autonomy is appropriate? What evidence is required? How will we know whether the implementation is working?
Those questions cannot be answered by technology alone.
They are questions about how the organisation chooses to operate.
That is the purpose of the TRIAI AI Governance Playbook.
It is not an argument against AI autonomy.
It is not a claim that risk can be eliminated.
And it is not a substitute for legal, security, privacy or regulatory expertise.
It is a discipline for putting AI into consequential business processes without allowing capability to run ahead of control.
The UK Government gives us an excellent principle: meaningful human control at the right stage.
The next questions are ours: Where is that stage? Who owns the judgement? What can the machine do without them? How much autonomy has it earned? And how do we know the boundary actually works?
Those are not principally AI questions.
They are management questions.
And answering them is becoming one of the central challenges of serious AI adoption.
We advise on adoption. We do not supply the technology.

