Comparisons

COMPARISON

Locke vs Staff Training and Policy Alone

Most organisations start the same way: a memo telling staff not to paste client data into AI tools, plus an annual training module. Training matters — it shapes culture and creates legal defensibility — but it doesn't stop the next paste at 4:55 p.m. on a Friday. Technical and human controls complement each other; training alone leaves the data path unprotected.

When Staff training and policy alone fits

  • You're at an early stage and need to set baseline expectations before adding tooling.
  • Your AI usage is so limited that the residual risk after training is acceptable.
  • You need training and policy regardless — they are foundational.

When Locke fits

  • Training has been delivered and you still see incident reports involving AI tools.
  • You operate in a regulated industry where 'we trained them' is not by itself a sufficient control.
  • You want a runtime backstop that catches the cases policy doesn't.

Side-by-side

DimensionLockeStaff training alone
When it actsAt the moment of submission.At the moment of training, weeks or months earlier.
Failure modeDetection gap (rare with multi-layer matching).Human forgets, hurries, or rationalises.
Evidence in an auditLocal logs and exportable hashed reports of detections.Training completion certificates.
Cost to scalePer-user license; central rollout.Recurring time investment per cohort, per year.

Bottom line

Training is necessary but not sufficient. Locke catches what training misses — the late-night paste, the rushed handoff, the new hire who hasn't taken the module yet.