Use of AI and LLMs
Artificial intelligence tools can be useful for writing code, researching solutions, diagnosing problems, producing documentation, reviewing work and reducing repetitive effort. The Technology Team is encouraged to use these tools where they help us work more effectively.
AI should be treated as a tool which assists people, not as a substitute for human judgement or responsibility.
Core principle
Our approach can be summarised simply:
Use AI where it helps. Give it good instructions. Keep a human responsible. Verify important work. Protect our data. Be transparent about significant AI-generated material.
AI should increase the capability of the Technology Team without reducing the care, judgement and accountability with which we operate St Mary’s systems.
Human responsibility
There must always be a human in the loop.
Anything produced or recommended by an AI system must ultimately be reviewed and accepted by a person who is competent to make that decision. The person using AI remains responsible for the resulting work.
This is particularly important where work affects security, personal data, finances, safeguarding, health and safety, or the reliability of important systems.
AI output can be confidently wrong. Code may contain subtle bugs or security problems; documentation may invent facts; and suggested commands or configuration changes may have unintended consequences. Treat AI output in the same way as work produced by an enthusiastic but fallible colleague: useful, but requiring review.
Using AI effectively
We should use AI deliberately rather than simply asking it to produce an answer as quickly as possible.
For substantial technical work, prefer tools and workflows which allow the AI to understand the problem and plan before making changes. Give it clear requirements, constraints and relevant context, and ask it to identify uncertainties rather than guessing.
Where appropriate:
- Use planning or reasoning modes before implementation.
- Give clear, specific prompts and acceptance criteria.
- Break large tasks into understandable stages.
- Ask the AI to explain significant decisions and assumptions.
- Review diffs rather than accepting large changes blindly.
- Run tests, linters and other automated checks after AI-assisted changes.
- Verify factual claims against authoritative sources where they matter.
A few extra minutes spent giving an AI good context will often save substantially more time later.
Project instructions and AGENTS.md
Repositories should use an AGENTS.md file, or an equivalent mechanism supported by the tools in use, to give AI coding agents persistent project-specific guidance.
This should document things such as:
- Coding and formatting standards.
- Project architecture and important conventions.
- Expected development and testing workflows.
- Commands for building, testing and linting.
- Security and privacy requirements.
- Areas of the repository which require particular care.
- Things an agent should not change without explicit instruction.
These instructions should be maintained alongside the project. They are part of our technical documentation, not merely prompts for a particular AI product.
Data and confidentiality
Do not provide an AI service with information which it is not appropriate for that service to process.
Particular care must be taken with personal data, safeguarding information, credentials, API keys, private keys and other confidential or security-sensitive information.
Before using an AI service with non-public information, consider what information is being sent, where it is processed, how it may be retained, and whether the service is appropriate for that information.
Secrets should never be included in prompts merely for convenience.
AI-generated code
AI-generated code is permitted and encouraged where it is useful.
It is not exempt from our normal engineering standards. Before it is deployed, somebody must understand sufficiently what the code does, review it, and test it appropriately.
Where an AI agent is capable of directly changing repositories, infrastructure or other systems, its permissions should be proportionate to the task. Human approval should remain part of consequential or difficult-to-reverse changes.
Transparency
We should be open about significant use of AI.
We do not need to label every autocomplete suggestion or trivial AI-assisted edit. However, where AI has generated a substantial piece of code, documentation, imagery, analysis or other material, this should be apparent where reasonably useful to future maintainers or users.
In particular, we should avoid presenting substantially AI-generated material as though a named person independently authored or verified every part of it.
Transparency does not remove responsibility: “AI generated this” is never an excuse for incorrect work.
Environmental impact
AI systems consume computational resources and energy. Their environmental impact should form part of our general approach to responsible technology use.
This does not mean avoiding AI where it is useful. It means using it purposefully: avoid unnecessary repeated generations, provide enough context to reduce wasted iterations, and do not use large or computationally expensive models for tasks which can reasonably be handled by simpler tools.
As with other technology choices, the resources consumed should be proportionate to the benefit gained.