Free · No account required · Free to use with attribution (CC BY 4.0) · Context, not legal advice.
The free starter kit for applying the FairByDesign Sovereign AI Control Framework to one real AI use case. You do not need our courses to begin — they go deeper, but this is enough to start today.
⬇ Download the PDF — framework + starter toolkit in one document — free, CC BY 4.0.
How to use it
Pick one AI use case. Work it through the seven control domains using the quick-checks below, and record the calls. Keep what you produce — it becomes your first control baseline.
A. Control baseline (start here)
For each of the seven domains, write down: the control you have today, its owner, and how you would know it is working (a measurement).
- Data & privacy (M-A): control today / owner / measurement
- Identity & access (M-B): control today / owner / measurement
- Change control (M-C): control today / owner / measurement
- Agent actions (M-D): control today / owner / measurement
- Human oversight (M-E): control today / owner / measurement
- Evidence (M-F): control today / owner / measurement
- Exit (M-G): control today / owner / measurement
B. Data boundary quick-check (M-A)
- What is the most-sensitive field in this workflow?
- Where does data enter, move, and could it leak? (list every hop)
- Is retrieval limited to what the requesting user is actually allowed to see?
- What is the minimum data each step needs — and is that all it gets?
C. Identity & access quick-check (M-B)
- Does every human, service account and agent have only the access its job needs?
- Can every action be traced to exactly one identity (no shared accounts)?
- How fast can you actually revoke access — and have you tested it?
D. Agent-action quick-check (M-D / M-E)
- List every action the AI can take. Mark the high-impact ones (irreversible, financial, external-facing, sensitive-data).
- Is each high-impact action behind a real human gate — not a rubber-stamp?
- Can you roll an action back? Can you stop a runaway, and how fast?
E. Evidence quick-check (M-F)
- Pick one real action. Can you reconstruct it end to end from your own records: who or what triggered it, what the AI saw, what it decided (with model and version), who approved it, what it did, and what changed?
- Is that trail retained for the committed window, tamper-evident, and producible in the time an inquiry or incident would allow?
F. Exit quick-check (M-G)
- Could you export your data, prompts, configuration and evidence and run elsewhere?
- Have you tested a fallback provider or model — and did it actually work?
- When did you last prove you could leave?
What next
- Read the full public framework: Sovereign AI Control Framework.
- Go deeper with the courses: Sovereign AI courses.
- For a facilitated review or an evidence-based assessment, book a briefing call.
Licence & attribution
This Sovereign AI Starter Toolkit and the FairByDesign Sovereign AI Control Framework are released under Creative Commons Attribution 4.0 International (CC BY 4.0). You are free to use, share and adapt them, including commercially, with attribution:
"Based on the FairByDesign Sovereign AI Control Framework — fairbydesign.org."
The FairByDesign name and logo are trademarks and are not licensed for implying endorsement. This toolkit is context, not legal advice, and does not certify any person or organisation.
FairByDesign — framework, education, assessment and assurance. Questions: info@fairbydesign.org.