AI Data Use Rules Sprint

Clear rules for what your team can put into AI — built around the tools and workflows you actually use.

If your team uses tools such as ChatGPT, Microsoft Copilot, Gemini or Canva AI, a generic policy may not answer the question that comes up in real work:

“Can this information go into this AI tool or account?”

For: Small service organisations in England and Wales where staff and managers need clear rules for routine use of generative AI.

£1,250 fixed fee

The standard Sprint covers 3–5 representative low- or moderate-risk workflows, a 45-minute discovery session, a 45-minute team briefing and five work-like scenario checks.

Planned delivery: within five working days once the required information and discovery session are complete.

Practical rules · clear boundaries · no legal opinion, DPO function or compliance certification

What changes

The intended result is simple: your staff and managers have one organisation-specific rule for routine AI data-use decisions.

USE
Your organisation's own approved conditions permit the use.

CHECK
The decision needs confirmation from the appropriate person in your organisation.

STOP
The matter needs specialist judgement or a different route.

The Sprint does not decide legal permissibility for your organisation. It turns the requirements and decisions your organisation is competent to approve into a practical rule people can use.

What you will receive

Working materials representing AI Data Use Rules Sprint.
Working materials representing AI Data Use Rules Sprint.

Tool and account map

A concise map of the AI tools and account types covered by the Sprint.

3–5 workflow review

A review of 3–5 representative low- or moderate-risk workflows and the practical decisions within them.

USE / CHECK / STOP rule

One organisation-specific decision rule that turns your approved requirements into clear day-to-day guidance.

Manager note and briefing

A short manager action note and one 45-minute remote briefing for one group.

Scenario verification

Five work-like scenarios to check whether people can apply the rule consistently, plus a clear list of anything that needs specialist advice or a different route.

WORKED EXAMPLE

See how this can work

Example situation: If your team uses tools such as ChatGPT, Microsoft Copilot, Gemini or Canva AI, a generic policy may not answer the question that comes up in real work:

We would start with what is happening now and the information already available, then work through the service described on this page. If the problem needs a different route, we would say so before broadening the work.

A clearer result: The intended result is simple: your staff and managers have one organisation-specific rule for routine AI data-use decisions.

What you could receive: Tool and account map, 3–5 workflow review, USE / CHECK / STOP rule, Manager note and briefing, and Scenario verification.

Illustrative example — shown to explain how the service can be applied. It is not a customer testimonial or measured result.

Where this could lead next

This service is complete in its own right. You do not need another service for this one to be worthwhile. If the work uncovers a separate problem worth solving, these are the most likely next steps.

AI Policy & SOP Implementation Service

If the data-use questions reveal a wider gap in organisational AI rules, responsibilities or procedures, this can help you turn those governance requirements into practical policy and SOPs.

Explore AI Policy & SOP Implementation Service →

Responsible AI Workplace Training

If the rule is clear but staff still need practice applying responsible judgement in ordinary work, this can help you build a practical responsible-AI workplace baseline.

Explore Responsible AI Workplace Training →

If the work resolves the problem and no separate need remains, no further House of Carol service is needed.

Not sure what follows? You do not need to choose another service now. Start with the problem in front of you.

What the engagement looks like

Service type
Professional service
Delivery
Remote sprint
Pricing
£1,250 fixed fee
Scope
The standard Sprint covers 3–5 representative low- or moderate-risk workflows, a 45-minute discovery session, a 45-minute team briefing and five work-like scenario checks.
Planned delivery
Within five working days once the required information and discovery session are complete.

The standard Sprint covers one organisation, one accountable manager and the defined scope above.

Before anything is agreed, we confirm that your organisation and the problem fit the standard Sprint. If they do not, we will tell you rather than stretch the service beyond its intended scope.

House of Carol — People, Ideas, Solutions, Real Progress. Intelligence for a kinder, more capable world.
What needs to be in place?

A named manager or decision owner who can approve your organisation's working rule.

The AI tools and account types currently in use.

Descriptions of 3–5 representative workflows.

Any relevant internal policies, client requirements or procurement restrictions.

The standard journey includes a 45-minute discovery session and a 45-minute briefing.

Where examples are useful, we ask for workflow descriptions and anonymised or redacted material wherever possible rather than unnecessary raw information.

What is outside the scope?

The Sprint is not legal advice, DPO support, a DPIA or DPIA sign-off, compliance certification, penetration testing, technical cyber assurance or a regulated-sector professional opinion.

We do not need your passwords, MFA codes or other credentials.

We do not ask for unnecessary raw personal, special-category, confidential or secret information.

If a question depends on disputed lawfulness, health or special-category information, safeguarding, clinical judgement, high-impact decisions about people or another specialist matter, we stop and identify the appropriate specialist route rather than pretending the Sprint can answer it.

Is this the right service?

Is this the right service for our organisation?

The Sprint is designed for a small service organisation where:

more than one generative-AI tool or account type is already in use;

managers repeatedly face uncertainty about what information may go into which tool;

the organisation wants one practical working rule rather than another generic information pack; and

a manager is able to approve the organisation's own working rule.

If your existing IT, privacy, legal or other specialist support already gives your people clear, usable answers to these questions, you may not need this Sprint.

What this service does not promise

The Sprint does not decide legal permissibility for your organisation. It turns the requirements and decisions your organisation is competent to approve into a practical rule people can use.

FROM INTEREST TO A CLEAR DECISION

How to get started

Start with the problem, not a purchase decision. We will check whether this service fits before anything is agreed.

1. Tell us what is happening

Share the problem you are trying to solve, what you already have and any deadline or constraint that matters.

2. We check the fit

We check the scope, the information we would need, the fee and whether this is genuinely the right service. If it is not, we will say so.

3. You decide with the facts clear

Nothing starts until you know what is included, what is not, what you need to provide and what happens next.

There is no pressure to add another service. The useful next step is simply to decide whether this one solves the problem in front of you.

Start with the problem

What is your recurring “can this go into AI?” question?

Tell us which AI tools and account types are in use, what decision keeps causing uncertainty and what organisational requirements already apply.

We will first establish whether the Sprint fits the problem and whether it sits within the standard £1,250 scope.

Discuss your AI data-use question