alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533
Become a Member
alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533

How do you approve a new AI use case?

How do you approve a new AI use case?

To approve a new AI use case, take it through five steps: a written request, a quick risk triage, testing, a limited pilot and a decision by a named owner. Low-risk requests can take a shorter route, but every approval ends with a person who is accountable for it.

A use case here means a specific tool used for a specific purpose. The same chatbot can be low-risk when it drafts internal notes and high-impact when it answers customers about their contracts, so approve the use, not just the tool.

Five steps to approve an AI use case

  1. Request. The person who wants the tool fills in a short form (see the template below). It makes them think through the purpose, the data and the people affected before anything is bought.
  2. Risk triage. The person who owns the AI programme reads the request and chooses between fast-track and full review, using the criterion below. For a full review, run an AI risk assessment.
  3. Testing. Try the tool on realistic but safe examples, avoiding real personal or confidential data where possible. Record what worked, what went wrong and how often the output needed correcting.
  4. Pilot. Before any pilot, check separately that the data it will use may lawfully be used this way. For personal data that means a legal basis and purpose under the GDPR; for any data it means permission under contracts, confidentiality duties and the vendor’s terms. A small pilot does not remove these questions. Then let a small group use the tool for a limited period, with a person reviewing its outputs, and collect errors, complaints and questions from users.
  5. Decision. A named owner approves, approves with conditions or rejects the request, and sets a date for the next review. The decision and its conditions go into the AI inventory.

Who should hold this decision in a small team is covered in who should be responsible for AI.

When a fast-track approval is enough

Recommendation. Fast-track means triage, a short test and a decision, without a formal pilot; the separate data check from step 4 still applies. It is enough only when all of the following are true:

  • the tool uses only public or internal data, not personal or confidential data;
  • a person checks every output before it is used or leaves the company;
  • the output does not feed decisions about individual people;
  • the tool cannot act on its own, for example by sending emails or changing records;
  • the vendor’s terms on data use and retention are known and acceptable;
  • stopping the tool would be easy and would harm no one.

If any condition is not met, a full review is needed. The same applies where the use could fall into a high-risk area listed in Annex III of the EU AI Act, such as recruiting or evaluating staff; obligations for these high-risk AI systems apply from 2 December 2027 (AI Act, Annex III). The full timeline is in what the EU AI Act requires. A clear “no” at triage is also a valid outcome: some uses should not go ahead at all.

Voluntary standards and frameworks. For a more thorough triage, ISO/IEC 23894:2023 gives guidance on AI risk management, and the NIST AI Risk Management Framework offers a voluntary structure for mapping and measuring AI risks.

Next step: put the next new tool anyone asks for through the request form below, and record the decision and the name of the person who made it.

Template

AI use case request form

Field What to fill in
1. Use case name and description The tool and what it will be used for, in one or two sentences
2. Requester and proposed owner Who is asking and who will be accountable for the use case
3. Purpose and expected benefit The problem it solves and how success will be judged
4. Tool and vendor Product name, vendor, plan type (consumer or business) and cost
5. Data used Public, internal, confidential or personal data; whether special-category data is involved; who confirmed the data may lawfully be used this way, and when
6. People affected Staff, customers, job applicants or the public, and how the output affects them
7. How the output is used Draft for a person to edit, input to a decision, or automatic action
8. Human review Who checks the output, when, and whether they can reject it
9. Company role (provisional) Whether the company is likely to be a provider or a deployer for this use
10. Triage and decision Fast-track or full review; approved, approved with conditions or rejected; decided by; date; next review date

Sources and further reading

Event

AI Horizon Conference

The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.

November 11, 2026
Lisbon, Portugal
Register Now
AI Horizon
alt alt

Join Us in Shaping the Future of Ethical AI!

Join us as a member and play a vital role in shaping a future where AI is created responsibly, with integrity, transparency, and fairness at its core.

Apply Now