Analysis

AI usage charter: who is accountable when AI gets it wrong?

The question never comes up before the incident. It comes up the day a wrong answer has gone out to a client, and nobody knows who should have checked it.

A hand writing in pen on a printed document, on a wooden table
One signed page beats a ten-page policy

In a small business, AI does not arrive through a project. It arrives through one employee saving an hour, then a second, and six months later it is everywhere without a single AI charter having been written. As long as nothing goes wrong, the absence of rules costs nothing. The day a wrong answer goes out to a client, the question is not technical: who should have checked it, and on what basis?

An AI usage charter is not there to provide legal protection — that is neither its purpose nor its reach. It is there to answer that question before it is asked. The 2026 edition of Stanford’s AI Index measures the gap between usage and safeguards (Stanford HAI, AI Index 2026), and it is widening.

Incidents are growing faster than the safeguards

The reference database on AI-related incidents recorded 362 in 2025, against 233 in 2024 (AI Index 2026, p. 132). The rise is clear, and the measurement imperfect: the count relies on human curation and covers mostly English-language media. It therefore understates rather than overstates.

What matters for a business is not the total but the nature of these incidents. It is almost never a spectacular model failure. It is a plausible, wrong answer that served as the basis for a decision; confidential data pasted into a consumer service; a document produced without anyone knowing it had been. Three situations no technology prevents, and that a written rule makes markedly less likely.

One practical consequence before going on: what is not recorded does not exist. Keeping a log of internal incidents — three lines per case, the date, what happened, what was changed — costs a few minutes and is worth any dashboard. After six months that log shows where the process leaks, and it makes a far stronger case than intuition when a rule has to be tightened.

Safety and accuracy do not always go together

The report makes a finding that deserves wider circulation: improving one dimension of responsible AI, safety for instance, can degrade another, such as accuracy (AI Index 2026, p. 10). A model constrained to refuse sensitive topics will also refuse legitimate requests; a model made more cautious becomes less useful. These trade-offs are unavoidable.

The report adds that there is currently no established framework for arbitrating between these dimensions (AI Index 2026, p. 126). In other words: nobody will tell you where to set the cursor, and the supplier has set it for you, according to its own priorities. Inside a business, someone therefore has to take that arbitration back — not to redo it technically, but to state which errors are acceptable on which tasks. That is exactly what a charter settles.

The trade-off arises in very concrete terms. In a sales letter, an awkward phrase can be retrieved; in a tender response, an inaccurate sentence commits the business; in a regulatory document, it exposes it. Those three uses call for neither the same checking nor the same tool, and it is the charter’s job to say so — rather than leaving everyone to guess where the line lies.

Organisations are getting organised, more slowly than people think

Two figures give the measure of the movement. The share of organisations where a dedicated role leads AI governance rose from 14% to 17% in a year (AI Index 2026, p. 142): real progress, but it leaves more than eight organisations in ten with nobody responsible for it. On the other hand, the share with no responsible-AI policy at all fell from 24% to 11% (AI Index 2026, p. 128).

Read together, those two figures describe a common situation: many businesses have written something, few have named someone. Yet a document with no name against it produces no effect. In the small businesses we work with, the only line that really changes behaviour is the one saying who decides in case of doubt — and who can be reached.

Whom to name, in a business with neither a lawyer nor an IT department? Rarely the person most at ease with the tools, often the one who knows the relevant trade best. The role is not crushing: keep the list of tools, answer questions in case of doubt, read the incident log and trigger the annual review. Half an hour a month is enough, provided that half hour exists in someone’s calendar.

The reference frameworks are shifting, and not as expected

Asked which frameworks influence their practices, organisations cite first the GDPR, at 60%, down five points; then the European regulation on artificial intelligence at 43%, the ISO/IEC 42001 standard at 36% and the NIST framework at 33% (AI Index 2026, p. 146). The last two are new to the survey: their appearance says that AI compliance is ceasing to be a purely legal matter and becoming a management-system matter as well.

For a French small business, the practical order is the reverse of the media order. The European AI regulation imposes obligations depending on use, and it deserves attention. But what already applies, every day, is the GDPR, as soon as personal data enters a tool — the CNIL has published recommendations on deploying generative AI, and they can be read in an hour. We set out what this implies in governing the use of ChatGPT at work.

What an AI usage charter must contain

A useful AI charter fits on one page, and six headings are enough. The table below gives, for each, what you write and why it is there. It holds for a business of ten people as for one of two hundred; what changes is not the content but the time it takes to get it accepted.

SectionWhat you writeWhy it is there
Approved toolsThe named list of accepted services, and the business plan required where relevant.With no list, everyone picks their own tool, and nobody knows where the data is.
Forbidden dataWhat must never be pasted: health data, named client data, trade secrets, contractual documents.It is the most read and most memorable rule. It prevents most incidents.
Human validationThe categories of output that never leave without review: quotes, client letters, regulatory documents.It says where the tool’s autonomy stops, and when a person commits the business.
Named ownerA name, a role, and how to reach them in case of doubt.A charter with no name against it has never changed a behaviour.
Procedure when it goes wrongWho to alert, within what time, and what to keep in order to understand afterwards.The incident is not the problem: the problem is learning about it from a client.
ReviewA date, once a year, and the name of whoever puts it in the calendar.Tools change every quarter. A frozen charter becomes wrong, then ignored.

One point of form, because it decides the rest: this charter is not one more legal document. It is written in the language of the business, it fits on one page, and it can be read in five minutes by someone who did not follow the project. A ten-page policy reviewed by a law firm produces exactly the opposite effect to the one intended: nobody opens it, and usage continues without rules.

Two points of articulation, to close. If your business already has an IT usage policy, the AI charter is not a competing document: it is a chapter of it, and our guide to the IT usage policy gives the framework, with a template. And the choice of tasks handed to AI is prepared with the grid described in the limits of AI: a charter governs uses, but the uses still have to be chosen.

We have drafted this kind of document, with the accompanying security framework, for a life sciences services company whose teams work on devices supplied by their clients. The constraint there is stronger than elsewhere; the method does not change — and it extends what the article that opens this series describes.

It still has to be adopted, and that does not happen by email. The charter is presented in a team meeting, in ten minutes, explicitly asking for objections — there always are some, and they are what make it workable. It is then kept where the work happens, not in a document space nobody opens. A rule you find at the moment you need it is a rule that gets followed.

Who is accountable when AI gets it wrong? The answer was never in the model, and no supplier will provide it. It is in a page nobody has written yet, and that costs half a day. The rest — AI governance, frameworks, audits — comes afterwards, and only if the business justifies it.

Common questions

What is an AI usage charter?

An internal document setting the rules for using artificial intelligence in the business: approved tools, forbidden data, cases where human validation is mandatory, a named owner and a procedure when something goes wrong. It addresses the teams, not a judge.

Is an AI usage charter mandatory?

No text requires this document as such. The GDPR applies as soon as personal data enters a tool, and the European AI regulation sets obligations depending on use. The charter is the simplest way to make those rules workable day to day; the legal qualification of your situation is a matter for a legal professional.

What should an AI usage charter contain?

Six headings are enough: approved tools, data that must never go in, outputs subject to human validation, the owner’s name, what to do when something goes wrong, and the review date. One page, in the language of the business.

Source: Stanford HAI, Artificial Intelligence Index Report 2026, published on 29 June 2026 under a CC BY-ND 4.0 licence. Page numbers refer to the PDF file. The incident count comes from the AI Incident Database, whose coverage favours English-language media; the shares of organisations cited come from a self-reported survey run by the AI Index team, excluding China. This article is an analysis by Maeliom; it is neither a translation nor an adaptation of the report, and is neither affiliated with nor endorsed by Stanford University.


Next article

IT asset management: the method before the tool

Read

A transformation to support?