Your business, out of your head.Founding clients: a few spotsSubscribe

Guides / Guides

Guide

AI diligence is three jobs: the tools you pick, what you disclose, and what you verify

Diligence is the AI-fluency skill of using AI responsibly, and it splits into three jobs. Creation diligence is choosing tools and settings with your data in mind. Transparency diligence is being honest about AI's role with anyone who has a right to know.

Deployment diligence is verifying and vouching for whatever ships under your name. The short version lives on our primer; this goes deeper into each, with the edge cases that catch owners out.

Responsibility stays with you, so diligence splits into three jobs

An AI has no license, no liability, and no relationship with your customer. You have all three, which is why diligence matters: the tool cannot be responsible on your behalf, so the care has to come from you.

Our primer on using AI responsibly introduces the three parts in a paragraph each. This article is the long version, with the examples and the edge cases that the short answer skips.

The three jobs are creation, transparency, and deployment. Creation is what you do before you start. Transparency is what you owe the people around you. Deployment is what you check before anything goes out. They are separate habits, and most AI accidents come from dropping exactly one of them.

  1. CreationThe tool you pick decides what leaks
  2. TransparencyDisclose before someone feels tricked
  3. DeploymentYou own what goes out under your name
Three jobs, not one virtue. Each has its own failure: the wrong tool leaks, the missing disclosure feels like a trick, and the unreviewed output goes out under your name.

Creation diligence: the tool you pick decides what leaks

Creation diligence is being deliberate about which tools you use and how you talk to them. Two questions settle most of it.

  • Does this tool train on what I put in? On several consumer plans the default answer is yes, and you have to go find the setting and turn it off. If you paste a client's contract, your supplier pricing, or a customer's medical detail into a tool that trains on inputs, you have handed private information to a model you do not control. Check the setting before the first paste, not after.
  • How much access am I granting? A connector that can read and send from your inbox is convenient and a real risk the moment the AI acts on a wrong assumption. Start every connection read-only. Widen it one scope at a time, and only when a specific job needs it.

Here is what that looks like on a normal Tuesday. You want help answering a customer email. The grounded, low-risk version is a paid assistant with training turned off, a project that holds your policies, and read-only access to the inbox so the AI drafts but you send.

The version that bites you is a free tool with default settings, fed the customer's full account history, wired to send on its own. Same task, very different exposure.

Team settings add a wrinkle. On a business plan, an admin sets the training and retention defaults once, for everyone, which is safer than trusting each person to find a toggle.

But shared projects also mean a part-time hire can see whatever you loaded into the knowledge base. Scope access to the role. Your bookkeeper does not need the file of customer complaints, and your front-desk hire does not need supplier margins.

A business knowledge base, a written brain of your rules, voice, and numbers, is only as safe as who you let read it.

Choosing trustworthy tools is part of creation too. Prefer tools that publish a clear data policy, that let you opt out of training, and that are specific about where your data is stored. A tool that is vague about all three is telling you something.

Transparency diligence: disclose before someone feels tricked

Transparency diligence is being honest about AI's role with everyone who has a right to know: customers, clients, and your own staff. Some of this is now law. Most of it is trust. Both matter, and the legal floor is lower than the trust bar.

Start with the law, because it is concrete. The FTC's rule on consumer reviews and testimonials took effect on October 21, 2024.

It bans fake reviews and testimonials outright, and it names AI-generated ones: a testimonial from a person who does not exist, or who never used the product, is illegal, with civil penalties per violation.

A generated "happy customer" is not a marketing gray area. It is the exact thing the rule prohibits.

Voice is regulated too. In February 2024 the FCC ruled that AI-generated voices in robocalls count as an artificial voice under the TCPA, so the same consent rules apply.

California went further: since January 1, 2025, AB 2905 requires that a prerecorded call using an AI-generated or significantly AI-altered voice disclose that at the start of the call, with a $500 penalty per undisclosed call.

If you run appointment reminders or sales calls with a synthetic voice, that disclosure is not optional in California, and other states are drafting similar rules.

Past the law, one test covers the rest: if a customer would feel misled to learn AI was involved, tell them first. The cases sort cleanly.

  • Fine with a light note. An AI avatar of you reading a script you wrote, about your own business. You said it; the avatar delivers it. A short line like "made with an AI avatar of the owner" costs nothing and removes the sting.
  • Fine, no note needed. AI that helped you draft an email you then reviewed and sent. You are the author. The customer is talking to you.
  • Never fine. A made-up customer, a fake review, a synthetic testimonial. No disclosure fixes it because the thing itself is a lie.

Staff are owed transparency too, and this one gets skipped. If you use AI to draft schedules, screen applicants, or summarize performance, the people affected should know AI is in the loop and that a human makes the call. Told plainly, most people are fine with it. Discovered on their own, it reads as something you hid.

Deployment diligence: you own what goes out under your name

Deployment diligence is the last gate: you take responsibility for verifying and vouching for anything you use or ship. Vouching means you checked it, not that the tool sounded certain. AI is fluent and confident even when it is wrong, and fluent-and-wrong is the dangerous combination, because it reads as true.

The rule is simple to state: nothing customer-facing, financial, or legal ships without a human pass. Making that pass fast is where the design work goes, and the fix is to keep a human in the loop by structure, not willpower.

Our playbook for handling customer comms safely lays out the draft-and-review loop: the AI drafts from your files, you approve, you are the one who sends. When verifying takes seconds, a wrong answer becomes a private edit instead of a public incident.

What a real pass checks:

  • Every number against a source. Prices, dates, hours, totals, quantities. A grounded draft can cite where each figure came from, which turns verification from rewriting into spot-checking.
  • Names and specifics. Customer names, product names, the details of their actual order. This is where a confident AI quietly guesses.
  • Claims you would have to stand behind. Anything that promises, guarantees, or states a fact about your business. If you would not put it in writing yourself, do not let the AI put it in writing for you.

Record-keeping belongs here. In a regulated trade, keep the human sign-off visible: who reviewed the output, when, and against what. If a customer or a regulator ever asks how a claim got made, "the AI wrote it" is not an answer. "I reviewed and approved it on this date against these records" is.

Regulated industries raise the bar on all three parts at once. In health, legal, financial, or insurance work, some outputs cannot ship on your sign-off alone, and some client data cannot go into a general tool at all.

If a professional body governs your advice, its rules sit on top of everything here, and they win. When in doubt, the safe default is that AI drafts the internal version and a licensed human produces the client-facing one.

Where diligence actually breaks

Naming the failure modes matters, because each one is a habit dropped, not bad luck.

  • The quiet default. You never checked the training setting, and months of client data has been feeding a model. This is a creation failure, and it is silent until it is not.
  • The scope that crept. A connector you granted for one job still has full send access a year later. Access widens easily and is rarely walked back. Review your connected tools on a schedule.
  • The disclosure you meant to add. The avatar video ships without the note, or the AI voice line goes live in California without the opening disclosure. Transparency skipped under deadline is the most common miss.
  • The pass you rushed. The draft looked right, so you sent it, and the one number you did not check was wrong. Deployment diligence fails when review feels optional, which is why it has to be built into the workflow rather than remembered.

None of these require you to distrust AI. They require you to treat the three jobs as three jobs, and to notice which one you are tempted to skip today.

How this fits the rest of AI fluency.

The four skills work together: deciding what to hand off (delegation), briefing it clearly (description), judging what comes back (discernment), and owning the result (diligence). You run any of them in one of three modes (automation, augmentation, or agency). The pillar guide ties them together.

The three parts here (creation, transparency, and deployment diligence) adapt the AI Fluency Framework, an open framework by Rick Dakan, Joseph Feller, and Anthropic, published under CC BY-NC-SA. We use it as an organizing idea; the writing and examples are our own.

Questions

Asked before reading this far.

What are the three parts of AI diligence?

Creation, transparency, and deployment. Creation diligence is choosing tools and settings with your data in mind, like turning off training on your inputs and starting connectors read-only. Transparency diligence is being honest about AI's role with customers, clients, and staff, including where the law requires it. Deployment diligence is verifying and vouching for anything that ships under your name. Skip any one and you have found the usual source of an AI accident.

Do I legally have to disclose that I used AI?

Sometimes, and the rules are specific. The FTC's rule effective October 21, 2024 bans fake AI-generated reviews and testimonials outright, with civil penalties per violation. The FCC treats AI-generated voices in robocalls as an artificial voice under the TCPA, and California's AB 2905, effective January 1, 2025, requires disclosing an AI voice at the start of a prerecorded call, with a $500 penalty per undisclosed call. Beyond the law, the test is simpler: if a customer would feel tricked to find out, tell them first.

Who is responsible when AI gets something wrong in my business?

You are, every time. The AI has no license, no liability, and no relationship with your customer, so the responsibility never transfers to the tool. That is why deployment diligence keeps a human between the AI and anything that ships: the AI drafts, you verify against real sources, and you send. Vouching for an output means you checked it, not that the tool seemed sure.

Is it safe to put client data into an AI tool?

Only after you check the settings and the industry rules. First confirm the tool does not train on your inputs and that you have granted the tightest access the job needs. In regulated trades like health, legal, or finance, some client data cannot go into a general tool at all, and a professional body's rules sit on top of everything else. When in doubt, let AI draft the internal version and have a licensed human produce anything client-facing.

Sources

The part no tool does for you

The setup is the product. That is what month one builds.

Your rules, voice, and numbers written down, the tools wired, drafts you approve. Priced by fit · Book a discovery call · See what changes in 30 seconds