Comparisons
COMPARISON
Locke vs Staff Training and Policy Alone
Most organisations start the same way: a memo telling staff not to paste client data into AI tools, plus an annual training module. Training matters — it shapes culture and creates legal defensibility — but it doesn't stop the next paste at 4:55 p.m. on a Friday. Technical and human controls complement each other; training alone leaves the data path unprotected.
When Staff training and policy alone fits
- You're at an early stage and need to set baseline expectations before adding tooling.
- Your AI usage is so limited that the residual risk after training is acceptable.
- You need training and policy regardless — they are foundational.
When Locke fits
- Training has been delivered and you still see incident reports involving AI tools.
- You operate in a regulated industry where 'we trained them' is not by itself a sufficient control.
- You want a runtime backstop that catches the cases policy doesn't.
Side-by-side
| Dimension | Locke | Staff training alone |
|---|---|---|
| When it acts | At the moment of submission. | At the moment of training, weeks or months earlier. |
| Failure mode | Detection gap (rare with multi-layer matching). | Human forgets, hurries, or rationalises. |
| Evidence in an audit | Local logs and exportable hashed reports of detections. | Training completion certificates. |
| Cost to scale | Per-user license; central rollout. | Recurring time investment per cohort, per year. |
Bottom line
Training is necessary but not sufficient. Locke catches what training misses — the late-night paste, the rushed handoff, the new hire who hasn't taken the module yet.