Most published governance language about artificial intelligence is written to be unobjectionable, which makes it useless for deciding anything. Two commitments are specific enough to be held to, so those are the two stated here.
The first is human oversight proportionate to consequence. Where a system's output affects a person's access to employment, credit, care or a public service, a human decision-maker must be able to see why the system produced that output, must hold the authority to override it, and must be expected to use that authority. Oversight that exists only to satisfy a policy is worse than none, because it distributes accountability without transferring it — the person named as the reviewer carries the responsibility for a decision they were never equipped to inspect.
The second is that we will say when a model is the wrong instrument. A significant proportion of what arrives scoped as an AI problem is a data quality problem, a process problem, or a decision nobody has yet been willing to make explicit. Naming that reduces the work we are engaged to do, which is precisely the point at which this commitment either operates or does not.
Where an engagement falls under a specific regime — the EU AI Act, sectoral regulation, or a client's own model-governance standard — the obligations are identified during scoping and written into the engagement, rather than treated as covered by a general assurance.