The five controls to sign off before AI talks to a customer
1. The permission model. Every action sorted into autonomous, approval-gated, or prohibited, with monetary caps that apply across the whole conversation rather than per tool, and identity verification as a precondition on any account action. 2. The data boundary. What the AI sees on the customer record, where that data sits, which model providers process it by name, and how long any of it is kept. 3. The audit trail. Every action attributable to a named identity with the authorization that permitted it, and every answer reconstructable months later. 4. Escalation as policy. A written list of categories that always reach a human, owned by legal and CX, not tuned by a vendor. 5. Change control. Anything that alters what the AI says is a reviewed, versioned, testable, reversible change.
The test that separates a real control from a written one: can the platform block the thing your policy forbids, with nobody watching? This guide is informational and not legal advice; your obligations depend on your jurisdictions, sectors, and contracts.
Why the policy document is not the control. Most AI governance material aimed at customer service is written for a different reader: a data science function standing up model risk management, or a committee drafting responsible-AI principles. Both are useful, and neither answers the question you were actually asked in the review. That question is narrow and operational. What can this thing do on its own, what stops it doing something expensive or illegal, and when it does, who is accountable and how do we prove what happened?
What this guide is not: it is not a hallucination guide, which is the accuracy problem and is covered in AI hallucination defense. It is not a vendor scoring rubric, which is the 40-question AI RFP template. It is not sector compliance, which for health data is HIPAA-compliant AI customer service. It is the layer those three sit on: the authority model, which survives whichever vendor you pick.