Skip to content
Get in touch 

Write the AI charter before you buy the AI

An AI charter decides your position before you buy: what your AI policy allows, what stays human, who signs it, and how it filters vendors.

Ibrahim Mizi Ibrahim Mizi  · 5 min read
A written charter with a seal beside its closing lines

An AI charter is the decision you make before you buy any AI tool: what your company uses AI for, what it never uses it for, what it discloses, and what happens to your data. OpenKit writes these as the governance layer that runs beneath every other piece of AI work. Most companies buy first and argue about the rules later, then wonder why nothing sticks.

Here is the pattern we see most. A company decides it is time to “do AI”, licences get bought, and a pilot gets announced. Within a quarter a few people are using the tools constantly, most people have not touched them, and nobody can say out loud what the company’s position is.

Meanwhile AI is already in the building on personal accounts, outside whatever rules IT thought applied, with the liability sitting on individuals. Your team is already using it, so the decision left to make is how.

A charter is short enough to quote in a meeting

It fits on a page, and it settles the arguments that otherwise restart every time somebody wants to try a new tool: what we use AI for, what we never use it for, what we disclose, and what happens to data along the way. Anyone in the company can carry that much in their head.

When we wrote one with House of Hackney, a design house whose entire value is the human hand, the harder half was the list of work that stays with people. No print is generated, the brand voice is written by people, and customer data stays out of any tool that has not been cleared. Writing that down is what made the rest adoptable: the team could use AI on the boring volume without wondering whether they were eroding the thing that makes the company worth buying from.

The charter is a procurement filter

Once it exists, every vendor pitch gets measured against a written position instead of a mood. Does this tool respect the data rules we set, and does it touch work we have declared human? Half the pitches answer themselves before anyone books a second demo.

It also does the work a compliance regime asks of you. The acceptable use policy stops being something you write under pressure after an incident, because the decisions are already made and already applied. That matters more as the rules arrive. The EU AI Act catches UK companies by the role they play, whether that is placing a system on the EU market or producing output that gets used there, and the charter is where you have already written down which of those you do.

A charter has to be kept alive, though. It needs an owner, a date to revisit it as the tools change, and a walkthrough with each team so it lands as an agreement rather than an announcement. A charter nobody revisits is just a policy with better typography.

Where this fits

Writing the charter is one of the smallest pieces of work we do, and it is usually what decides whether the rest of the AI work gets adopted. It is the same discipline behind our AI governance and compliance work, and if you want to see where your position has gaps before you write anything down, the free AI readiness check is a reasonable place to start.

Ibrahim Mizi

Ibrahim Mizi

Co-founder & CEO · Full-Stack AI Engineer · OpenKit

Co-founded OpenKit in 2020 and runs the consultancy side end to end. Eight years of full-stack development, then production AI for SMEs and the public sector.

What is the difference between an AI charter and an AI policy?

A policy is the long document that gets filed and quoted at people after something has gone wrong. A charter is the half page underneath it that the company agreed, and once it exists the policy is mostly the write-up of a decision already made.

What should an AI acceptable use policy cover?

The part that decides whether it works is data: what may and may not go into which tools, and who says so. Most shadow AI use is people pasting confidential material into consumer accounts nobody sanctioned, so a policy that lists approved tools without naming the data rules leaves the actual exposure where it was.

Do UK businesses need an AI policy?

Practically, yes, because AI is already in the building whether or not anyone agreed to it. The written position earns its keep when someone outside the company asks for it, and that is usually a client's procurement team or an insurer at renewal. Both want the same thing, which is what you decided, in writing, with a date on it.

Who should own the AI charter?

One named person who can say out loud what the company's position on AI is. Committees blur that, because when everyone owns the charter nobody can tell you what it currently permits. The owner also sets the date it gets revisited, which is what stops it going stale as the tools change.

Settle the rules before you buy.

If this raised a question about what your own team is allowed to do, the answer is an AI Charter. It is four decisions with names against them, short enough that people actually read it. One Charter, agreed once, governs every system we build with you and every one your team runs after we have gone.

Find your first workflow.

We start with a conversation, audit where AI actually pays back, and build the first automation into how your team already works. We reply within one working day.