A blueprint tells you what good looks like. A checklist tells you whether one system is ready. Neither helps with certify or defer, hire or distribute, or how much authority to give an agent. Those are judgement calls with no correct answer, and they are where most of the real difficulty lives. This framework does not make them for you. It names the criteria that should drive each one, supplies a default for the common case, and defines the trigger that should make you reopen the question, which is the part that matters most.
Seven of the ten can wait until the question arrives. These three cannot, because each one otherwise gets decided under pressure by whoever is nearest.
against demand
A named deal requiring it is decisive. Three or more qualified prospects asking in one quarter is high. Existing ISO/IEC 27001 is high, because marginal cost falls materially. Maturity is gating, since certifying below roughly 112 is expensive theatre. The default is defer, because 42001 attests that you run a management system rather than that any AI system is safe.
Five levels from advisory through read-only tools, bounded write, approved irreversible and autonomous irreversible. Bounded write is the default ceiling. The operative rule is that autonomy is granted at the tool scope rather than at the agent, because saying an agent is level two means nothing if one of its six tools can send email.
No lawful basis and none obtainable. A consequential decision about a person with no meaningful route to human review. Performance that cannot be measured against the outcome that matters. Or a use that depends on the user not realising AI is involved. Four, not fourteen: a long prohibited-use list reads as bureaucracy and gets ignored.
Reversible and low-stakes gets delegated. Irreversible or expensive to undo gets a written record, a named decider and the executive sponsor in the room.
Each decision compares the real options on what they get right and where they break. Where nothing in your situation argues against it, take the stated default and move on.
The most valuable field in the log. It is where the risk you accepted is actually stored, and the first thing worth rereading when the revisit trigger fires.
Calendar reviews get skipped and conditions fire. Write the specific change in circumstances that should reopen each decision, then let it sit until that happens.
Defer unless a named deal requires it, or three or more qualified prospects asked in a single quarter. It attests that you run a management system, not that any AI system is safe. Build the evidence pack first, because it wins more deals per dollar and is a prerequisite anyway. If you already hold ISO 27001 and score above 112, the calculation shifts.
Usually not. Fund half a full-time equivalent of a named senior person and protect it in planning. The failure mode of distribution is not that the work is done badly but that it is done in whatever time remains, which in a shipping quarter is none. Reduce their delivery commitments by the same amount in writing, or the allocation is fiction.
Two separate decisions that get collapsed into one. Prompts: permit, with provider training disabled and verified in the console, retention bounded and sensitive classes blocked at the application layer. Shared-model training: prohibit. You cannot remove a customer's contribution from a trained model on request, which makes deletion obligations very hard to satisfy honestly.
Bounded, reversible writes by default, with scoped credentials, ceilings and a tested rollback. Approved irreversible actions only with a named business owner and a tested emergency stop. Fully autonomous irreversible actions only with written executive sponsor approval and a stated loss tolerance. Grant autonomy at the tool scope, not at the agent.
Hybrid. External for the first three layers and the control library, where experience compresses months into weeks. Internal for evaluation, monitoring and incident response, which are specific to your architecture and must be built by people who will operate them. Contract the external part on a handover milestone rather than a document deliverable.
Four conditions. No lawful basis for the data use and none obtainable. A consequential decision about a person with no meaningful route to human review. Performance that cannot be measured against the outcome that matters. Or a use that depends on the user not realising AI is involved.
Drop your details and we'll send AI Governance Decision Framework straight to your inbox - no spam, unsubscribe anytime.
Work through the three that cannot wait with our engineering leads, against your own architecture and pipeline. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions
Talk to our engineers