A defined role, not unlimited autonomy
An AI website employee should be configured for a specific customer-facing job. Its responsibilities, supported topics, tone, escalation rules, and success measures should be documented before deployment.
Approved knowledge and visible boundaries
Answers should be grounded in approved business information. Teams remain responsible for source accuracy, permissions, maintenance, and deciding which information is suitable for customer-facing use.
The system can produce incomplete or incorrect output. High-impact, sensitive, ambiguous, or unresolved matters should be routed to a qualified person rather than presented as certain.
Human oversight and evaluation
Teams should review conversations, evaluate answer quality and harmful failure modes, monitor escalation performance, and update knowledge and controls using real evidence.
- Disclose that visitors are interacting with an AI assistant where appropriate
- Provide a practical route to human support
- Avoid collecting information that is not needed for the defined task
- Test the system before expanding its responsibilities
- Record ownership for knowledge, incidents, and model or provider changes
Framework alignment
The operating principles are informed by established risk-management themes such as governance, transparency, privacy, security, measurement, and ongoing human accountability. They are not a certification or guarantee of compliance.