Tech-N-AI Talks logo Tech-N-AI Talks

How to Stay in Control of AI: A Prosumer's Guide to AI Governance

Last month a friend asked [ChatGPT](https://chat.openai.com/) to draft a termination letter for an employee who had not actually done anything wrong. The model…

How to Stay in Control of AI: A Prosumer's Guide to AI Governance — illustrative featured image
Last month a friend asked [ChatGPT](https://chat.openai.com/) to draft a termination letter for an employee who had not actually done anything wrong. The model complied without a flicker of hesitation. No warning, no "are you sure," no request for context. That moment, more than any think-piece about superintelligence, is what AI control actually looks like in practice. The question is not whether machines will wake up and decide to enslave us. It is whether the humans holding the keyboard stay awake while the machine does the work. The BBC has been running a series of pieces asking whether humans can stay in control of AI. The framing is dramatic, but the underlying concern is mundane and urgent: as these systems get woven into hiring, medicine, policing, and creative work, who is actually steering? Right now, the answer is mostly "whoever typed the prompt," and that is a thinner layer of governance than most organizations want to admit. ## What AI control actually means AI control is not one thing. It is a stack of decisions made at different layers, by different people, with different incentives. Understanding the layers is the first step toward having any real influence over them. At the bottom sits the model itself: trained by a lab, shaped by data, constrained by a system prompt the user never sees. Above that sits the application layer, where a company like OpenAI, Anthropic, or Google wraps the model in guardrails, filters, and usage policies. Then comes the organizational layer, where your employer decides which tools are approved and what data can touch them. Finally, the user layer, which is you, deciding what to ask and what to do with the answer. Most public debate about AI ethics happens at the model layer, because that is where the drama lives. But the leverage for a prosumer is at the top two layers. You cannot retrain GPT-4. You can absolutely decide not to paste a client contract into it. ### The three failure modes When AI control breaks down, it usually breaks in one of three ways. - **Capability overreach**: the model does something technically impressive that nobody asked for, like inventing a citation or fabricating a policy number. - **Accountability drift**: a human decision gets laundered through a model so that no one feels responsible for the outcome. - **Context collapse**: the model applies a generic pattern to a situation that needed local judgment, like recommending a standard severance package in a jurisdiction where the law says otherwise. None of these require AGI. They happen every day, in ordinary workflows, to ordinary people. ## The prosumer control checklist You do not need a governance committee to run basic AI control. You need habits. Here is what we actually do. ### Before you prompt Ask three questions. What data am I about to expose? What decision will this output influence? Who will be accountable if it is wrong? If you cannot answer all three in one sentence each, stop. ### While you prompt Treat the model like a talented intern with no memory of your industry and no fear of consequences. Give it constraints explicitly. Ask it to flag uncertainty. If it produces something that sounds authoritative, verify the specific claims, not the vibe. ### After you prompt Log what you used, at least mentally. If the output shaped a decision that affects another person (a hire, a loan, a medical suggestion, a performance review), a human needs to own that decision by name. "The AI said so" is not a defense, and increasingly, [regulators agree](/tech/blog/when-ai-starts-scheming-understanding-the-risks-and-how-to-protect-yourself). ## Where the real governance happens Individual discipline only scales so far. The interesting AI governance work is happening inside organizations that are writing actual rules, not just principles. | Layer | Who owns it | What good looks like | |---|---|---| | Model | Labs (OpenAI, Anthropic, Google DeepMind) | Published system cards, red-team results, usage policies | | Application | Vendors and platforms | Clear data retention terms, opt-outs, audit logs | | Organization | Your employer | Approved tool list, data classification rules, incident reporting | | Individual | You | Prompt hygiene, verification habits, escalation when unsure | The gap most teams fall into is between the organization layer and the individual layer. Companies publish an AI policy, then nobody reads it, then someone pastes source code into a chatbot and the whole thing becomes a security incident. Responsible AI is not a poster. It is a workflow. ## Our take: tools we actually trust for control We have tested a lot of AI governance tooling, and most of it is either enterprise bloat or security theater. Here is what we recommend for prosumers and small teams who want real control without hiring a compliance officer. - **For personal AI use**: Claude and ChatGPT both offer data controls worth configuring. Turn off training on your conversations if the option exists, and use temporary chat modes for anything sensitive. Anthropic's usage policies are unusually readable, which matters when you are trying to figure out what you just agreed to. - **For team deployments**: Vanta and Drata now cover AI vendor risk alongside SOC 2, which is the pragmatic move if you already use them. If you do not, a simple shared spreadsheet of approved tools and their data terms beats nothing. - **For prompt-level control**: Microsoft's Azure AI Content Safety and similar guardrail APIs let you filter inputs and outputs before they reach a human. Overkill for a solo writer. Essential if you are shipping a customer-facing bot. - **For reading the fine print**: The EU AI Act text is dense but the risk-tier summaries from law firms like DLA Piper are genuinely useful, even if you are not in Europe. Global products tend to inherit the strictest regime anyway. The pattern across all of these: control comes from configuration and process, not from hoping the model behaves. ## The uncomfortable part Here is the thing nobody wants to say out loud. AI ethics frameworks are mostly written by people who are not the ones affected by the failures. The worker whose resume gets filtered, the patient whose scan gets misread, the tenant whose application gets auto-rejected, none of them sit on the ethics board. That asymmetry is the actual governance problem, and no amount of prompt engineering fixes it. What individuals can do is refuse to be a laundering layer. If you use an AI output to make a decision about a person, own it. If your employer deploys a system that does, ask who is accountable and get it in writing. If a vendor will not tell you how their model was trained or what data it retains, that is an answer. The BBC's question, can humans stay in control of AI, has a boring answer. Yes, if enough humans decide to. The technology is not the bottleneck. Attention is. ## FAQ ### What is the difference between AI control and AI governance? AI control is the practical act of directing what a model does, through prompts, configuration, and verification. AI governance is the system of rules, roles, and accountability that makes control repeatable across an organization. You can have control without governance, but it does not scale. ### Do I need to be technical to practice responsible AI use? No. The most important habits are non-technical: knowing what data you are exposing, verifying claims before acting on them, and keeping a human accountable for decisions that affect other people. Tools help, but judgment is the core skill. ### How do I know if an AI tool is safe to use at work? Check three things. Whether your employer has approved it, what its data retention and training policies say, and whether the output will influence a decision about a person. If any of those are unclear, escalate before you use it. The five minutes it takes to ask beats the incident report you write later.

Frequently asked questions

The three failure modes When AI control breaks down, it usually breaks in one of three ways. - **Capability overreach**: the model does something technically impressive that nobody asked for, like i

AI control is the practical act of directing what a model does, through prompts, configuration, and verification. AI governance is the system of rules, roles, and accountability that makes control repeatable across an organization. You can have control without governance, but it does not scale.

Do I need to be technical to practice responsible AI use?

No. The most important habits are non-technical: knowing what data you are exposing, verifying claims before acting on them, and keeping a human accountable for decisions that affect other people. Tools help, but judgment is the core skill.

How do I know if an AI tool is safe to use at work?

Check three things. Whether your employer has approved it, what its data retention and training policies say, and whether the output will influence a decision about a person. If any of those are unclear, escalate before you use it. The five minutes it takes to ask beats the incident report you write later.