Before an AI pilot goes near daily operations
Twelve things that have to be true. Drawn from what we have seen stall pilots in rail and public transport organisations, and from what we settle before any system we build goes live. Use it as a review list for a pilot you already have, or as the agenda for the first conversation with your security team.
- 1. The process is named. Not "AI for maintenance" but "drafting the first version of the incident report from the depot log". If the process cannot be named, the pilot cannot be measured.
- 2. The data is inventoried and classified. Which documents, which fields, which of them are personal data, which are safety-relevant, which are contractually confidential.
- 3. It is decided where the model runs. On your own hardware, in a hardened European cloud, with a European provider or with a non-European frontier model — or a split between them — chosen against the classification in item 2, and written down.
- 4. The contract terms are known.
- 5. Access is controlled.
- 6. Every answer carries its source.
- 7. A person checks the right things.
- 8. It is logged.
- 9. Someone owns it.
- 10. There is an evaluation set.
- 11. There is a way back.
- 12. The people are told.
Get the checklist as a PDF, and an update when it changes.
Almost done: check your inbox and confirm your address. The PDF follows once you do.


