Service line 01
For EHS leaders being asked about AI by a board that has already decided it wants some.
1
Line 1 of 5
"Everyone's asking what our AI strategy is. Nobody's asking whether our data could support one."
And underneath that, the second problem: it's already in use. Someone is drafting risk assessments with a general-purpose assistant. A feature in your platform is classifying incidents by severity, and it was switched on in a release note. Approved by whom? Checked against what? Nobody's quite sure, and nobody wants to be the one who asks.
An AI actor is a member of the team, not a tool.
Treat it that way and the questions stop being technical and start being ones you already know how to ask. What is it for, and what's the evidence it can do that here rather than in the vendor's demo? Who supervises it, and can they really override it? How would you know if it changed, and how do you take it off duty?
The second idea follows from the first. Readiness is a property of your foundations, not of the model. Whether you can rely on AI for safety work is decided by who owns the risk, whether your data is fit, whether the system fits the work as it's done, and whether anyone is competent to oversee it.
Which is why the day is really a foundations diagnostic; AI is just the reason the board agreed to it. It's also why it's the cheapest useful thing you can buy from us: it tells you what to fix next, and quite often that isn't AI at all.
One day, your leadership team, and a room that isn't only safety people: at least 2 line leaders, IT or data, and HR or data protection if you can get them. A room of only safety people gives you a safety-team view of a business problem, and I'll say so if that's what's offered.
Before the day, an anonymous census of what's already being used for H&S work, approved or not, with no names attached and a written agreement that the answers are never used for discipline. On the day: an inventory of your AI actors, including the ones nobody signed off; a readiness grade the room gives and I challenge against the evidence; a triage of each use to the level of human supervision it needs; governance for the uses that survive; and a verdict.
Optional: a 90-day and 12-month roadmap, in your hands within 10 working days.
Some tasks don't get a dial. These 5 don't move towards less human involvement without written approval from a named owner in your top management, after consultation:
deciding whether a report is recorded, or closed
classifying severity for statutory reporting or for your indicators
determining causes, or corrective actions
deciding anything about an individual worker
touching a physical control
That position isn't squeamishness about the technology. Each one is a place where an unreviewed output rewrites what your organisation believes about its own risk, and nobody sees it happen.
3 outcomes: ready, conditionally ready with the preconditions named as work items, or not yet, with the reason stated plainly. A workshop that returns the yes the room wanted is worth nothing to you, so if the answer is not yet, that's what you'll hear, and exactly what would have to change.
The gaps the day surfaces mostly aren't AI gaps. Data preconditions route to Data & Insight, system fit to System Selection, oversight competence and single points of failure to Team Competency, and a framework so overgrown that the fix is pruning rather than automating to Simplification & Ownership. Sometimes nothing routes anywhere and you get on with it yourselves; in my experience that's a result too.
Simple Foundry governs adoption. We don't build, configure or prompt AI tools, and we don't sell platforms or take a penny from anyone who does.
This isn't legal advice on the AI Act, UK GDPR or employment law. You'll get an orientation on what applies, dated and sourced, and your counsel advises.
We don't design or endorse systems that infer emotion from workers.
A fixed fee for the day, agreed before work starts; scoped in a conversation rather than a rate card.