Straight answers about AI control
If your question is not here, ask it directly - the complimentary discussion exists for exactly that.
The problem
We already have an AI policy. Isn’t that enough?
A policy establishes expectations. It can define acceptable behavior, prohibit certain activities, require human review and remind employees to protect confidential information. What it cannot do is operate.
A policy does not show you where AI is already in use, identify which tools employees have opened on personal accounts, prevent sensitive information from being entered into the wrong platform, or verify that anyone followed the rules. Treat an AI policy as the beginning of the process, not the end.
We’ve banned AI. Doesn’t that solve it?
Rarely, because the ban is usually unenforceable and frequently already untrue. AI arrives embedded in software you already licensed, added by vendors and carriers through updates nobody separately purchased, and adopted informally by employees on personal accounts.
A prohibition you cannot verify produces the worst of both outcomes: none of the benefit, and no visibility into the use that continues anyway. Controlled non-adoption is a legitimate posture - but it has to be enforced and evidenced, not just declared.
We require human review of AI output. Isn’t that the control?
Only when the reviewer knows what wrong looks like. An AI answer can be polished, professional and almost correct - omitting the one endorsement that changes the conclusion, or relying on a superseded source. The reviewer approves because nothing looks obviously wrong. A person was involved; you did not have control.
The structural version of this failure is worse: if the AI determines when human review is required, control has been handed to the thing being controlled.
What if we don’t know where AI is being used?
That is the normal starting position, and it is the first thing we fix. The AI Inventory covers embedded features in software you already licensed, vendor and carrier assistants, deliberately adopted tools, and informal use on personal accounts.
Nobody is penalized for what the inventory finds. An organization that cannot identify where AI operates cannot credibly claim to control it - so establishing the picture is the work, not a test you pass or fail.
The control system
What exactly do we receive?
Seven components, each an artifact you can hold, hand to an underwriter, or produce in response to a question: the AI Inventory, the Decision-Point Map, the Authorization Register, Policies & Authority Rules, Controls & Guardrails, the Evidence & Exception System, and Continuous Engagement - plus the Four Walls Environment, the enforced boundary, scoped separately.
Together they form the AI Control System. It is built to be demonstrated, not described.
Do we need to buy new software?
Usually not. Commercial technology already exists for identity and access, managed devices, browser restriction, data-loss prevention, monitoring, logging and alerting - and most organizations already own more of it than they use.
The work is coordinating those tools around your own AI rules and risk decisions. Where additional technology is genuinely required, it is quoted separately and transparently, and it is never a product we sell you.
Will this slow our team down?
It should do the opposite. The instinct to review everything is what makes governance collapse under its own weight; the alternative is to review what matters, with oversight matched to risk.
The controls are also built so the approved path is the convenient one. If following the rule is harder than breaking it, the rule loses - so we build the compliant route into the environment rather than relying on willpower.
Who owns the documentation you build?
You do. The inventory, the decision-point map, the register, the policies and the evidence trail are yours, in your systems, in editable form. They remain useful and defensible whether or not we continue working together.
Working with us
How does an engagement start?
With a complimentary AI risk pre-assessment discussion - a structured conversation about where AI already operates in your business and where control is missing. No written assessment, no recommendations, no obligation and no cost.
If it makes sense to continue, the AI Risk & Controls Assessment produces the current-state review, the initial inventory and decision-point map, the gap analysis and the engagement scope. From there, the managed engagement builds and launches the system.
What does it cost?
Pricing scales by size, users, locations, AI tools in use, workflow complexity and implementation requirements - so a published figure would be wrong for most readers. We quote against your actual scope after the fit call.
The assessment fee is credited in full against a managed engagement commenced within 30 days, and at 50% between days 31 and 90. Third-party technology, IT and security services, legal services, travel and taxes are excluded unless expressly included.
How long does it take?
The assessment is measured in weeks, not months, and the managed engagement is scoped against what the assessment finds. Governance is not installed and finished, though - models change, vendors ship updates, regulations move and staff turn over.
That is why Continuous Engagement is a component rather than an upsell. Maturity runs visibility, then consistency, then optimization. The objective is demonstrable improvement, not a certificate.
How is this different from a cybersecurity assessment?
Security asks whether the wrong people can get in. This asks whether the right people, using approved tools correctly, can still produce an indefensible outcome - and where in the workflow that happens.
The two overlap in the enforcement layer and complement each other everywhere else. A clean penetration test tells you nothing about whether an AI summary dropped the endorsement that mattered.
Certification
Is AI GuardWorks Certification a training certificate?
No. Training and competency are required components, but organizational certification also requires implementation and verification of operational controls.
Does certification guarantee that AI will never make an error?
No. Certification verifies that the organization has implemented a defined system for governing, reviewing, documenting and responding to AI activity.
Does an organization need enterprise governance software?
Not necessarily. Requirements are proportionate and tailored to the organization’s size, services, risk profile and AI use. Some controls may be procedural, while others may require technical enforcement.
How long will certification remain valid?
The planned certification term is 12 months, subject to renewal, material-change requirements and reassessment after a significant AI-related incident.
Is the certification endorsed by a trade association?
Any accreditation, endorsement, recognition, continuing-education approval or formal partnership will be identified by name only after it has been granted.
Scope and limits
Is this only for insurance agencies?
No. Our experience spans insurance, healthcare, real estate, legal, restoration and technology, among others.
The model applies to any organization where advice, documentation and judgment carry consequence. Coverage for an AI-related loss frequently turns on how a claim is pleaded rather than on the technology, and that is true in every sector.
Can this help with insurance underwriting or renewals?
It gives you something to bring to the conversation. An organization that can show approved tools, controlled data, risk-based review, verification, logging, exceptions and continuous improvement is better prepared for the questions underwriters, brokers, clients, regulators and courts are likely to ask.
As the market matures, documented controls may carry direct economic value in the way cyber-hygiene and telematics controls already do. That remains an emerging possibility rather than established market practice, and we will always describe it that way.
Do you provide legal or compliance advice?
No. We are not a law firm and we do not provide legal advice, regulatory opinions or coverage determinations. Nothing we produce is a substitute for counsel, and questions about what a specific policy covers belong with your broker of record and your attorney.
What we build is operational: where AI is used, what it may do, who decides, what gets verified, and what evidence exists. That work supports your legal and compliance advisers rather than replacing them.
What happens after the engagement ends?
You keep everything - the artifacts, the procedures and the evidence trail, all editable and all yours. Many organizations continue with a Continuous Engagement subscription for ongoing advisory, exception guidance, training and periodic re-authorization as tools and rules change.
Others take it in-house. Both are legitimate outcomes, and we would rather build something durable than something dependent.
Our point of view
The positions behind the answers
Each of these appears in context somewhere on this site. Collected here and read in order, they are the argument in short form.
What is actually happening
AI is no longer confined to a tool someone deliberately opens. It is embedded in Microsoft 365 and Copilot, Google Workspace, email, search, CRM, document platforms, workflow systems, and AI assistants.
Like an iceberg, the visible concerns - drift, hallucinations, fabricated answers, and false confidence - are only the beginning. The greater risk is what is operating below the surface, multiplying faster than most organizations can see or control.
AI risk does not grow one task at a time.
Every user, tool, workflow, source, device, client interaction, and unchecked output creates another path for error. The risk does not merely increase. It multiplies.
AI does not have to invent the whole answer to create a loss.
It only has to miss the fact that changes the decision.
We’ve heard AI Governance Experts say: Think of AI as the best administrative assistant you’ve ever had.
We say: Think of AI as the assistant who appears to be the best administrative assistant you ever had, is a people pleaser, and may confidently tell you exactly what you want to hear - not what you need to know. Your job is not to admire the answer. Your job is to find what is true.
Why the standard answer fails
A policy can state what people should do.
It cannot prove what tool was used, what information it touched, what was reviewed, who approved it, or what was escalated. Policy expresses intent. Controls create evidence.
Human-in-the-loop (HITL) only works when the human knows what wrong looks like.
That is why verification starts by assuming the answer is wrong and forcing AI to prove it right.
If AI decides when human review is needed, the fox is guarding the henhouse.
Human oversight only works when people - not AI define what must be reviewed, verified and escalated.
Business leaders are often advised to ask vendors: “How are you using AI safely?”
The question that matters is: Can you identify every point where AI can make or influence a judgment - and the control that prevents it from deciding on its own? If the vendor cannot answer, that is not merely a red flag. It is an evacuation alarm.
What changes when control exists
The right AI controls are not determined by company size or industry alone.
They are determined by what AI touches, who relies on the output, and what happens when the answer is wrong. The greater the consequence, the stronger the control must be.
The insurance market is moving toward a familiar question: Is AI silently included, specifically restricted, or affirmatively covered with defined limits and conditions?
Insurers cannot confidently assess or price a risk they cannot see. Organizations that can demonstrate visible, documented, and enforceable AI controls will be better prepared for the questions coming at renewal.
The same documented controls that protect the business also improve its risk story.
They show where AI is used, what is permitted, when human review is required, what was documented, and how exceptions are handled. Good governance makes risk easier to understand, evaluate, price, and defend.
If you are not using AI, you NEED to talk to us.
If you are using AI and believe you have it under control, you REALLY NEED to talk to us.
Still have a question
AI is here. The risk is real. Control is possible.
A structured conversation about where AI already operates in your business and where control is missing. No written assessment, no obligation, no cost.
Complimentary Pre-Assessment See the control system →