A short governance framework for teams deciding where AI belongs, what should remain under human control and how performance will be monitored.
1. What decision or task is AI supporting?
Describe the task precisely. A broad ambition to use AI is not enough to define acceptable performance, required data or the consequence of an incorrect output.
2. What happens when the output is wrong?
The impact of error should determine the level of review, testing and human control. Low-consequence drafting assistance and high-consequence operational decisions should not use the same governance model.
3. What information can the system access?
Data permissions, confidentiality and retention need to be explicit. Teams should understand what information enters the model or service and whether that use is appropriate for the context.
4. Who is accountable for the final action?
Users should know whether AI is providing information, making a recommendation or triggering an action. Responsibility for consequential decisions should remain clearly assigned.
5. How will we know it is still working?
Performance can change as data, users and operating conditions change. Monitoring, feedback, incident review and periodic reassessment should continue after deployment.