Skip to content

Write the AI charter before you buy the AI

An AI charter decides your position before you buy: what your AI policy allows, what stays human, who signs it, and how it filters vendors.

Ibrahim Mizi Ibrahim Mizi  · 5 min read
An AI charter setting a company's position before buying AI tools

An AI charter is the decision you should make before you buy any AI tool: what your company uses AI for, what it never uses it for, what it discloses, and what happens to your data. OpenKit writes these as the governance layer that runs beneath every other piece of AI work, because alignment beats tooling. Most companies buy first and argue about the rules later, then wonder why nothing sticks.

Published 8 July 2026.

Here is the pattern we see most. A company decides it is time to “do AI”. Licences get bought, a pilot gets announced, and within a quarter three things are true at once: a few people use the tools constantly, most people don’t touch them, and nobody can say out loud what the company’s actual position is. The tools arrived before the agreement did.

Meanwhile AI is already in the building, on personal accounts, outside any data perimeter, with the liability sitting on individuals. The question was never whether your team uses AI. It is whether anyone has agreed how.

A charter is a decision, not a policy document

Policies get written to be filed. A charter gets written to be quoted. It is short enough that anyone in the company can carry it in their head, and concrete enough to settle real arguments: what we use AI for, what we never use it for, what we disclose, and what happens to data along the way.

When we wrote one with House of Hackney, a design house whose entire value is the human hand, the important column wasn’t where AI helps. It was the other one: no generated prints, no synthetic brand voice, no customer data in uncleared tools. Writing down what stays human is what made the rest adoptable. The team could finally use AI on the boring volume without wondering whether they were eroding the thing that makes the company worth buying from.

The charter is a procurement filter, and an AI policy that holds

Once the charter exists, something useful happens to every vendor pitch: it gets measured against a written position instead of a mood. Does this tool respect our data rules? Does it touch work we have declared human? Can we disclose its use without embarrassment? Half the pitches answer themselves, and that filter alone usually pays for the exercise.

It also does the work a compliance regime asks of you. The acceptable use policy stops being a document you write under pressure after an incident, because the decisions are already made and already applied. That matters more as the rules arrive: the EU AI Act catches UK companies by the role they play, from placing a system on the EU market to producing output that gets used there, and a charter is what turns that from a scramble into a filter you already run.

A charter has to be kept alive, though. It needs an owner, a review cadence as tools change, and walkthroughs so it lands as an agreement rather than an announcement. A charter nobody revisits is just a policy with better typography.

Where this fits

Writing the charter is one of the smallest pieces of work we do, and for companies whose value is human, which is more of them than the industry admits, it is often the most important. It is the same discipline behind our AI governance and compliance work, and it pairs naturally with a free AI readiness check if you want to see where your position has gaps before you write anything down.

Start with an audit

Most engagements start with an AI Audit and Transformation, a fixed-scope, fixed-fee piece of work that finds where AI earns its place in your business and where it does not, then puts the first of it into service. You leave with a written report and a prioritised 12 month roadmap.

Ibrahim Mizi

Ibrahim Mizi

Co-founder & CEO · Full-Stack AI Engineer · OpenKit

Co-founded OpenKit in 2020 and runs the consultancy side end to end. Eight years of full-stack development, then production AI for SMEs and the public sector.

What is the difference between an AI charter and an AI policy?

A policy is written to be filed. A charter is written to be quoted. The charter is the short, agreed decision underneath the policy: what the company uses AI for, what it never uses it for, what it discloses, and what happens to data. Once that is settled, the acceptable use policy is mostly documentation of a decision already made.

What should an AI acceptable use policy cover?

Four things at minimum: which tools are approved and for what, what data may and may not go into them, what work stays human, and what you disclose to customers and staff. The hard column is usually the second one, because most shadow AI use is people pasting confidential data into consumer accounts nobody sanctioned.

Do UK businesses need an AI policy?

Practically, yes, because AI is already in the building whether or not anyone agreed to it. A written position also does real work under incoming rules: the EU AI Act catches UK companies by the role they play, whether that is placing an AI system on the EU market, deploying one from an EU establishment, or producing output that gets used in the EU, and a charter is what turns compliance from a scramble into a filter you already apply to every tool.

Who should own the AI charter?

A named person, not a committee, with a review cadence as the tools change and walkthroughs so it lands as an agreement rather than an announcement. A charter nobody revisits is just a policy with better typography. The owner keeps it alive and is the one who can answer, out loud, what the company's position actually is.

Find your first workflow.

We start with a conversation, audit where AI actually pays back, and build the first automation into how your team already works. We reply within one working day.