AI risk discussions often become either alarmist or meaningless. A blanket ban prevents useful work; unrestricted experimentation creates invisible exposure. SMEs need a simpler way to decide how much evidence, review and permission a task requires.
The Reliability Triangle is a practical test for every AI-supported output. It does not promise certainty. It helps a team respond proportionately.
Evidence
Can the answer be grounded in an approved source? Is that source current, relevant and visible to the reviewer? If the model cannot show where a material claim came from, treat it as unverified.
Context
Did the system receive the business facts, definitions, examples and boundaries needed for this task? A plausible answer can still be commercially wrong because the model did not know your price, policy, audience or exception.
Consequence
What happens if the output is wrong? A rough internal brainstorm is not the same as a customer promise, financial decision, legal statement, hiring judgement or action that changes another system.
Consequence sets the review level.
Low-consequence work can move quickly. Use AI to organise notes, produce options or create a first draft, provided the material is appropriate for the tool.
Medium-consequence work needs an identified reviewer and an approved source. Examples include customer communications, project plans and operational recommendations.
High-consequence work needs narrow permissions, explicit evidence and accountable human approval. In some cases AI should assist only with retrieval or formatting, not the decision itself.
Fluency changes how an answer feels, not whether it is true. Ask for supplied-source citations, uncertainty and missing information, then verify what matters.
The five controls that matter first.
- Approved tools: define which services may be used for which kinds of work and data.
- Data boundaries: label material and prevent unnecessary access to personal, confidential or sensitive information.
- Source priority: state which files are authoritative and what happens when information conflicts.
- Human approval: name the person responsible before an output is sent, published or allowed to change a system.
- Incident path: make it easy to report a bad output, exposure or unexpected action and stop the workflow.
The UK Government's voluntary AI cyber security code emphasises human responsibility, protection of assets, documentation of data, models and prompts, appropriate testing, monitoring and proper disposal. It recommends granting connected AI systems only the permissions required for their function.
Where personal data is involved, data-protection duties still apply. The ICO's AI risk toolkit helps organisations reduce risks to people's rights and freedoms. The ICO notes that its guidance is being reviewed following the Data (Use and Access) Act, which is a reason to maintain governance rather than write a policy once and forget it.
A useful test for this week.
Choose a real answer that sounds correct but has no visible source. Give the model only approved material, ask it to answer again, cite that material and state uncertainty. Compare both outputs with the person who owns the work.
The lesson is not a magic phrase. It is whether better evidence and context change the answer, and whether the consequence justifies further review.
Sources and further reading
Start safely, not slowly.
Use the starter kit to organise approved sources and maintenance rules before connecting another system.
Get the free starter kit