Skip to content
Is there an AI for this?

Field note · FDE practice

Handing over an AI system responsibly

A deployment that only its builder can operate has not been delivered. This note sets out what has to exist at handover — runbook, evaluation set, ownership, upgrade path, and the decision log — and why human oversight is a duty to staff rather than a line in a slide.

Source
Written by us. Method and judgement — no statement on this page rests on a fetched document.
Evidence
none on this page — it links to the pages that hold it

01The bar

Handover is not a meeting. It is a state the deployment is in: a named person inside the organisation can restart it, change the model, explain to a colleague why an answer was wrong, and tell whether last week was worse than the week before.

Each of those four is testable, and the test is to have the internal owner do it while you watch and say nothing.

  • ASSESSMENT

    We assess a handover as complete when the internal owner has performed a restart, a model change, an error investigation and an evaluation run without assistance — not when the documentation has been delivered.

    BasisRests on the four operations above being the ones an operator actually needs in the first quarter. Documentation is evidence that the knowledge was written down, not that it transferred.


02What has to exist

ArtefactAnswersTest that it works
RunbookHow do I start, stop, restart and restore this?The owner restarts the system from the runbook alone
Evaluation setIs it still as good as it was?The owner runs it and reads the diff after a model change
Decision logWhy is it built this way, and what was rejected?The owner can answer "why not a hosted product?" without you
Upgrade pathWhat happens at the next version, and who decides?A dated review in the owner’s calendar, with a rollback
Access and secretsDo we hold our own credentials?Your access is revoked and the system still runs
Named ownerWho is accountable when it is wrong?A person, in the organisation chart, who has agreed
Handover artefacts and the question each one answers — our assessment, not a vendor comparison chart

03Human oversight is a duty, not a slide

Where a deployment falls into a regulated category, the person who ends up overseeing it inherits obligations that were decided during the build. Handover is when those obligations become somebody’s job, so the competence and authority to do it have to be part of what is handed over.

  • ASSESSMENT

    The AI Act requires deployers of high-risk systems to assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • ASSESSMENT

    The Privacy Commissioner’s model framework recommends that organisations formulate appropriate policies, practices and procedures when they procure, implement and use AI solutions.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • RECOMMENDATION

    We recommend naming the overseeing person during the design, not at handover, and writing down what authority they have to stop the system.

    BasisDepends on the deployment affecting people rather than only internal documents. Rests on the two instruments cited above: both place the obligation on the organisation deploying, and both describe competence and authority rather than presence.


04The first quarter after you leave

  1. Week 1: the owner runs the evaluation set once, with no changes, to establish that they can.
  2. Week 4: a deliberate small change — a prompt or a retrieval setting — run through the evaluation set and released by the owner.
  3. Week 8: a model upgrade rehearsal in a copy of the environment, including the rollback.
  4. Week 12: a review of what staff actually asked, and one decision to add, narrow or remove a corpus.
  • ASSESSMENT

    We assess a scheduled rehearsal as the difference between a system that is maintained and one that is frozen at the version it was delivered at.

    BasisRests on the upgrade path being the artefact most likely to go unused: unlike a restart, nothing forces it to happen, so it happens only if it is dated.

  • RECOMMENDATION

    We recommend agreeing this calendar before the engagement ends and putting the dates in the owner’s calendar rather than in the report.

    BasisDepends on there being a named internal owner. Rests on the four rehearsals above, each of which exercises one of the handover artefacts while help is still reachable.