Skip to content

Trust and governance

Responsible AI needs a clear boundary.

Assessed practice uses synthetic records. No production connection or real organisational or personal data is required. An accountable human owns every decision.

Current facts are separated from conditional product acceptance criteria.

Current course boundary

What is true now

AidGPT is developing a visible training environment where learners can practise more capable AI workflows using fictional records. Publication of connected features follows product acceptance testing.

  • Synthetic practice Assessed practice uses fictional and synthetic records.
  • Production boundary No production connection is required.
  • Data boundary The course does not require real organisational or personal data.

Later own-data use

Apply the discipline through authorised routes

The course does not require real organisational or personal data. Learners may later apply the disciplines to approved work through their organisation’s authorised tools, policies and authority.

That later own-data use sits outside assessed practice.

Responsible practice

How responsible practice is governed

These principles apply at the level where people choose tools, handle information and own decisions.

  • Use the least power needed for the task.
  • Work only through approved tools and permissions.
  • Check claims against the source.
  • Stop when authority, data or purpose is unclear.
  • An accountable human owns the decision and the result.

Conditional technical assurance

What product acceptance must establish

Before stronger connected-feature claims can be published, product acceptance must establish the full control set.

Acceptance criteria only. This is not evidence that connected controls exist today.

MCP provides the connection pattern between an AI workspace and purpose-built training services. It is not itself a security boundary. The relevant controls are the accepted combination of isolation, authentication, bounded tools, read-only behaviour, evidence and operational testing.

MCP is a connection protocol and pattern. It is not itself a security boundary.

Practical governance evidence

AI Disclosure and Use, version 2.3

The free guide sets out practical disclosure, permission and verification habits for managers and staff. It is available in the browser and as the canonical PDF.