I used to explain our AI risk approach with frameworks and matrices. Eyes glazed, meetings ran long, and people left no clearer about what they could actually do on Monday. Now I explain it with one word: zones.
The idea is almost embarrassingly simple. Not all AI use carries the same risk, so it shouldn’t carry the same rules. We divide use into zones and attach expectations to each.
The green zone is where mistakes are cheap and reversible: drafting, summarising your own material, brainstorming, learning. Here the rule is go, with our approved AI tools. Use it freely, build your skills, no approvals needed. Your judgement is the control.
The amber zone touches other people or feeds decisions: analysis informing recommendations, content being communicated. Here you can proceed, but with named conditions: verification steps, disclosure, specific data rules.
The red zone is where errors could hurt someone or compromise the essential services we run: safety-critical decisions, regulatory obligations, operational control systems. Here nothing happens without deliberate design, formal governance, and accountable ownership. Most of the red zone remains, for now, simply off limits, and we say so plainly.
Why does something this basic work so well? Because most people don’t want a risk framework, they want an answer to one question: can I do this? Zones give that answer instantly, without a committee. And because the green zone is truly free, people stop experiencing governance as prohibition. The rules are concentrated where the risk actually lives.
There was a second benefit I didn’t anticipate. Zones gave our risk-averse people a way to say yes. Before, every AI question carried the full weight of every AI risk, so caution demanded refusal. Now, “that’s green” is a complete and defensible answer.
The nuance, of course, is in the boundaries, and we adjust them as we learn. But the architecture holds.
If your people can’t tell you, in one sentence, which uses of AI are free and which are forbidden, no framework document is compensating for that.