One tool, three risks

The same software. Three deployments. Three different answers.

The most expensive assumption in this field is that a tool has a compliance status. It does not. The deployment does — and one licence can produce three unrelated obligation sets inside the same organisation.

One licence, three deployments

A general-purpose assistant, rolled out across a mid-sized organisation.

Nothing about the software changes between these three. Everything about the determination does.

Deployment 01

Drafting internal documents

Used by the operations team to draft process notes. No personal data of consequence, no decision about any individual, no external effect.

Likely outcome: little or nothing attaches — and the valuable artefact is the dated record saying so.

Deployment 02

Summarising customer complaints

The same assistant reading customer correspondence and producing summaries that route cases. Personal data throughout, and a decision that influences how a person is handled.

Now in scope: privacy duties, transparency expectations, and questions about automated handling.

Deployment 03

Screening job applicants

The same assistant ranking candidates. A consequential decision about identifiable people, in whichever jurisdictions those applicants live.

A different universe: employment-AI instruments, bias-audit expectations, notice duties, and per-state divergence.

What this breaks

Three habits that all assume the tool is the unit.

Each of these is standard practice somewhere, and each produces a register that cannot answer the question it exists to answer.

01

The approved-tools list

A list of software the organisation has cleared. It cannot be right, because clearance was granted against one use and the licence permits all of them. The list is not wrong so much as it is answering a different question.

02

The vendor questionnaire

Perfectly good for security. Silent on the thing that determines regulatory exposure, because the vendor does not know what your departments will do with it.

03

The annual review

A deployment added in March and reviewed the following January was unassessed for ten months, and the assessment date will say so.

What this is not. LegisGate produces regulatory intelligence and assessment-preparation materials. Nothing we produce is legal advice, a legal opinion, a certification, or a determination of compliance, and no document we deliver satisfies a legal obligation on its own. Sufficiency is determined by your counsel.

A dark office behind glass

The practical consequence

Your inventory is longer than your tool list.

If twenty tools are each used for two things, the unit of work is forty, not twenty. That is uncomfortable arithmetic and it is the arithmetic that determines what the programme actually costs.

The organisations that get surprised are the ones that budgeted per licence.

Run the one that worries you

Assess the deployment, not the licence

Three determinations, not one approval.

Each takes about fifteen minutes and produces a record specific enough to defend. An approval covering all three defends none of them.

Talk to usWe're here to help
One AI Tool Can Carry Three Different Risks | LegisGate