The organization must formally define and document its internal processes that govern the responsible use of AI systems by its personnel.
The purpose of these documented processes is to provide clear, actionable rules and guidance to ensure that all use of AI within the organization is ethical, safe, and aligned with legal requirements and organizational policies.
These processes should specify, for example:
- How to ensure the AI system is only used for its intended purpose as described in the user documentation.
- Rules for handling input and output data, especially personal or sensitive information.
- The procedures for human oversight, intervention, and decision verification that operators must follow.
- Steps for identifying and reporting unexpected behavior, incidents, or potential misuse of the system.