Guide · Responsible AI
Using AI responsibly in your business — with a human in the loop
Artificial intelligence has crossed from novelty to genuinely useful. It drafts, summarises and answers in seconds, and the time it saves on real work isn't hype. But for anyone running a business, the interesting question isn't whether to use AI — it's how to take it as far as it will go without giving up control, accuracy or accountability. The answer increasingly has a name: keeping a human in the loop. Done well, that isn't a brake on AI — it's what lets you use it to the full: more time back for your people, better results for the business, and the workers behind every record protected rather than sidelined.
The productivity is real
Used well, AI is very good at the slowest part of many tasks: starting. It turns a blank page into a first draft you can react to, compresses long material into a summary, and answers "how do I…?" in the moment. A policy that took a morning to draft begins as a solid first version to edit. A pile of notes becomes a structured summary. A question that used to mean digging through a manual gets answered on the spot. None of that is imaginary — the hours saved are real, and they add up.
So is the risk
The same tools can be confidently wrong. They generate plausible text, not verified truth — and plausible- but-wrong is the dangerous kind, because it reads as if it's right. Anywhere accuracy matters, that's a problem, and in a business accuracy matters everywhere: a wrong figure in a document, an invented requirement, a "decision" no person actually made. Two risks stand out:
- Over-trust — treating a confident draft as a finished decision, and letting it onto the record unchecked.
- Data exposure — sending confidential or personal information to a tool without knowing where it goes, who can see it, or whether it's used to train someone else's model.
The answer is a human in the loop
"Human in the loop" means a person reviews, edits and owns every AI output before it counts. The AI assists; the person decides. In practice that's three habits:
- Treat AI output as a draft, never a decision. It's a starting point to check, not an answer to accept.
- Keep a named person accountable for anything that ends up on the record. Responsibility should never rest with a tool.
- Label what's AI-generated, so no one mistakes a suggestion for a verified fact.
Put simply: AI drafts, people decide, and the record shows who decided.
Why this maps to ISO 42001
This isn't just good manners — it's becoming a governance expectation. ISO/IEC 42001 is the international management-system standard for artificial intelligence, and it's about exactly this: governing how an organisation uses AI responsibly — human oversight, transparency about where AI is used, clear accountability, and keeping records of that use. If you already run a management system for quality, safety or information security, responsible AI is an extension of the same discipline: decide who's accountable, keep humans in control of decisions, be open about where AI is used, and log it so you can show what happened. Because AI also touches data, it sits close to information security, too.
For more: ISO 42001 explained · ISO 27001 vs ISO 42001.
What responsible AI looks like in practice
A short checklist you can hold any AI tool — or your own use of one — against:
- Opt-in, not on by default. AI is switched on deliberately, not sprung on people.
- Clear labelling of anything AI-generated.
- Human review before anything commits to a record, with higher-risk actions always needing a person.
- A named person accountable for decisions.
- Minimise the data you send, and know what's excluded.
- Know your provider and their data terms — including whether your inputs are used to train their models.
- Log AI use — feature, who and when — so there's a record to review.
The principle in one line: AI should make your people faster, not make your decisions. The moment a tool is deciding rather than drafting, the loop is broken.
Where Kavvy fits
Kavvy is Kavorly's in-product AI assistant, built on exactly this principle: AI drafts, people decide, records prove it. It drafts first versions of policies, procedures and risk ideas tailored to the standards you run, and answers "how do I…?" questions grounded in the product handbook rather than roaming free. For those how-to answers it sees only the question text and the current page name — never the organisation's records. Every output is labelled as AI, with this always-visible line: Kavvy is AI and can be wrong. Its answers and suggestions are guidance only — always review them, and a responsible person must make and own the final decision.
Kavvy is off until you switch it on. By default nothing is written to a record until a person accepts it, and medium- and higher-risk actions always require a person.
On data: when AI is off, nothing is sent to the model. The encrypted personal-data vault, tenant identifiers and company names are never sent; other personal identifiers are minimised and stripped where detected. The model is Anthropic's Claude API (in the United States) under standard contractual clauses and the UK IDTA, and inputs are not used to train Anthropic's models. Every use is logged — feature, who and when — which is the kind of record a standard like ISO 42001 expects.
See the platform underneath → · ISO 42001 software →
This guide is a general introduction to using AI responsibly, not legal, compliance or AI-governance advice. For the authoritative requirements of ISO/IEC 42001, refer to the published standard or a certification body.