AI safety · Last updated 3 September 2026
Authority is designed, not assumed.
AI can improve how work moves. It does not take over the judgement, relationships or accountability that make a creative business valuable.
Atlas builds supervised AI-assisted workflows for project- and roster-led creative businesses. We start with the work: its sources, handoffs, exceptions, owners and consequences. Then we define what a system may do, what it must bring back for approval and what remains human-only.
For us, AI safety is an operating discipline. The Atlas delivery standard puts it into the workflow specification, the release evidence and the controls agreed for live operation. The exact controls depend on the use case and are confirmed in the signed engagement documents.
1. The workflow comes before the model
Buying an AI tool is not the same as redesigning the work around it. We map the current workflow before choosing what to build. That map identifies the source information, people, decisions, failure modes and measures that matter.
We assess risk by use case, not by model name. The same technical capability can be low consequence in one workflow and inappropriate or regulated in another.
2. People keep consequential decisions
An AI build does not pass the Atlas design gate until decision rights are defined in writing. The client names the people who can approve consequential actions, and the specification records what the system may do alone, what it may only propose and what it must never do.
The Atlas default for external communications, publishing, production changes and actions with financial consequences is propose-only: a named person approves the action. Legal, safety and regulatory material requires review by appropriately qualified people. AI output does not approve itself.
3. Data and access have a boundary
Before client data enters a system, the engagement must identify the sources a workflow may use, who may access them, how sensitive material is handled and which providers are involved. Access is scoped to the work rather than granted by convenience.
The required contract position is that client data is not used to train or fine-tune shared models and is not moved between client environments. That position becomes an engagement commitment only after the selected architecture, provider settings and contract support it. The signed documents set the exact providers, locations, retention, deletion and exit terms for each client.
4. Work must be checkable
Every Atlas release plan starts with a written definition of what good looks like, how it will be tested and who will verify it. The evidence must cover the workflow’s real requirements, including known edge cases. Material work requires an independent check; the builder does not accept its own release.
AI outputs are probabilistic and can be incomplete, inaccurate or misleading. The safeguard is not a claim of infallibility. It is the combination of bounded authority, source visibility, testing, human review and a clear stop condition when the evidence is not good enough.
5. People know when AI is involved
Where a system interacts directly with people, or produces material that needs an AI disclosure, the design must put that notice into the workflow. The form depends on the audience, the use case and the law that applies. The release evidence makes provenance inspectable rather than hiding it in a policy no user sees.
6. Live systems need controls
A useful workflow still needs an owner. Atlas calls a system an operated service only when the agreement defines what is monitored, who receives an alert, what the fallback is and how an incident is handled.
When something goes wrong, the sequence is simple: detect, contain, communicate, recover and record. Recovery is checked before normal operation resumes, and the evidence is kept so the same failure can be tested for again.
7. Learning is controlled
Approved corrections are recorded so they can inform tests, instructions or reusable operating patterns for later runs. Reuse still needs a provenance and permission check: client-specific information, configurations and outputs do not become another client’s material.
The aim is an organisation that remembers what its work taught it without turning private context into a shared pool or removing the people who are accountable for judgement.
Map, Build, Run
Map
We map the workflow: its sources, risks, owners and decision rights. Where a proposed use raises material legal or regulatory questions, specialist review is required before work proceeds. Atlas is not a law firm or conformity-assessment body.
Build
The release plan starts with the smallest useful slice and names the evidence, independent verification and client approvals required before release.
Run
The operating agreement defines monitoring, alerts, records, approvals and incident handling. If those controls are outside scope, Atlas does not describe the workflow as a managed service.
What Atlas does not claim
- We do not claim that AI output is always correct.
- We do not treat autonomy as the measure of a good system.
- We do not promise that a workflow, client or organisation is compliant merely because Atlas helped design it.
- We do not provide legal, regulated safety, tax, accounting, employment or investment advice.
- We do not claim an AI, security or compliance certification we do not hold.
Legal role and classification depend on the particular system and how it is used. Atlas does not proceed with a use that raises material legal or regulatory questions unless appropriate specialist advice, controls and decision authority are in place.
The client’s role
Safe operation is shared work. Clients are responsible for providing lawful instructions and authorised access, naming suitable approvers, reviewing matters routed for approval, telling us when a use case or risk changes, and identifying sector-specific duties that apply to their organisation.
The exact responsibilities, controls and service boundary for a system belong in the signed engagement documents. This page explains our approach; it does not replace those terms.
Contact
If you are an existing client, use the incident or governance route recorded in your Atlas operating agreement. For a general question about this page, email hello@atlasstudios.ai.
For a new conversation, show us the workflow on screen rather than emailing sensitive material.