The 2026 AI Index, from Stanford University, recorded 362 incidents involving AI in 2025 — against 233 the previous year, a 55% jump in twelve months. The report does not say how many of those cases would have been avoided by a review step, and that honesty matters: the number shows the size of the exposure, not the recipe for reducing it. The recipe, where regulation states one, has an old name. The EU AI Act carries an explicit requirement in Article 14: in high-risk biometric identification systems, no decision may be taken on the basis of the system's output unless at least two people with the necessary competence, training and authority separately verify and confirm the identification. It is the "four eyes" principle — segregation of duties — carried from accounting into AI.

Accountants have known the idea for a long time. Segregation of duties is an internal control in which responsibilities are split across more than one person, so that nobody alone can initiate, authorize, record and review the same transaction. Whoever enters the supplier invoice is not the one who releases the payment. Whoever writes the reimbursement policy does not approve it. It is intentional redundancy. The Sarbanes-Oxley Act of 2002 gave that framework the force of law, requiring public companies to maintain, assess and report on effective internal controls over financial reporting — with an independent auditor's attestation. In AI, the same logic is still a novelty for most.

The problem segregation solves

When AI generates a critical document — an updated policy, a contract template, a pricing table — that document carries an embedded risk: it may be correct in form and outdated in content. A pricing table generated from a 2024 document, in a company that repriced in June, is formally perfect and factually wrong. A governance policy built on an old director's comment may be five months out of date. Without a validation step, the error travels invisibly until someone discovers it — and by then it has become a liability, a customer complaint, an investigation.

This is not about distrusting AI. It is about recognizing that an AI model has a knowledge horizon, and that horizon is always earlier than the company's present. What the model cannot know is what changed yesterday in the board meeting, what was renegotiated with the supplier last week, which clause legal asked to remove. A person knows that — and the process has to give that person a formal place to intervene.

The common answer — "let's forbid AI from touching critical documents" — fails for the same reason AI bans in general fail. If the tool is useful, someone will use it; and if it is forbidden, they will use it outside IT's line of sight, where there is no review, no record and no retention. What works is designing a place where the governed path is easier than the ungoverned one and, by construction, more controlled.

What has to be in place

What has to be in place

Whoever writes does not approve. When someone generates a critical document with AI — a policy, a contract, a pricing table — it cannot be the same person who approves it. The document goes to someone with different authority, under a legal or contractual obligation to validate it first. In a governed system, approval power belongs to a defined group, not to "anyone with access."

Approval by risk, not for everything. Not every AI response needs four eyes. An analysis the team discards in ten minutes if it is wrong is low risk. A contract to be signed with a customer is the highest risk. The system should let the manager define: documents in the "Corporate Policy" category require approval; quick queries do not. It is configurable because what is critical in one department may not be in another. Note that the AI Act itself recognizes proportionality: the Article 14 dual-confirmation requirement may be waived for law enforcement, migration and border control uses where the law considers it disproportionate. Absolute rigor everywhere is not governance — it is paralysis.

Clear audit trail. Who wrote the document, when, with which AI version? Who approved it, when, with what comment? All on record. In case of an incident, it is the difference between reconstructing in minutes and never reconstructing. The ISO/IEC 42001 standard for AI management systems organizes 38 controls across nine objectives, and one of them deals specifically with recording system event logs, alongside technical documentation and data provenance. It is the reference gaining the most traction: the 2026 AI Index reports that 36% of surveyed organizations already cite it as a standard shaping their AI governance, ahead of other frameworks.

Exceptions audited, not silent. Sometimes an approval has to be skipped — an emergency, an unavailable person, an acceptable risk. That can happen. But the skip is recorded, annotated with a reason, and reviewed afterwards. Constant exceptions become the rule; audited exceptions become an alert.

This is how Skyller was built: critical documents can require review and approval in two stages, with whoever writes separated from whoever approves, segregation of duties in the corporate identity, and a searchable trail of every step.

From individual risk to shared control

The gain from segregation of duties is not only security. It is also reputation. When a document goes out wrong because "nobody checked first," the liability belongs to the company, not to the person who used AI. When there is a documented approval step, that action is a corporate decision — and responsibility is distributed, clear, recorded.

There is also the effect on knowledge. An approved critical document becomes official corporate knowledge: it can be stored so the AI uses it in future conversations, with the confidence that it went through validation. If it were informal, personal, undocumented, it would be speculation. Approved is an institutional reference — and a wrong answer stops multiplying across a hundred conversations.

The path is not only technical. The same 2026 AI Index points out that the biggest barrier to responsible AI is neither budget nor regulation, but missing know-how: 59% of organizations cite knowledge gaps as an obstacle, against 48% citing budget and 41% citing regulatory uncertainty. At the same time, the share of companies with no responsible-AI policy at all fell from 24% to 11%. Most have already written the rule; what is often missing is the mechanism that makes it hold day to day — and an approval step built into the tool is exactly that mechanism.

Five questions for the next meeting

Five questions for the next meeting

Before writing one more policy — or letting AI write without control — answer these with IT:

  1. When someone generates a contract with AI, who sees it before it becomes official? If the answer is "it depends," there is no process — there is improvisation.

  2. Which document or category of document is critical enough to require four eyes? If "everything," the process stalls. If "nothing," it is as before: visible lack of control.

  3. When someone leaves the company, does their earlier approval of a document still stand? If it stands forever, there is a gap. If there is no tracking, you are operating blind.

  4. Was there a documented exception in the last audit of critical documents? If there are many, that is an alert — the rule is either not accepted or not working.

  5. If an incident involved an approved document with no tracking, could we reconstruct who did what? If not, it is worth going back and drawing the trail.

Discover Skyller