AI governance

How I turn AI risk into release decisions

Governance works when a team can see the intended use, evidence, open question, accountable authority, release condition, and signal that reopens the decision.

The cases below come from systems I built. The operating model is the clearly labeled enterprise method I would bring to a larger review program. The distinction stays visible because a proposed program is useful only when it is not mistaken for biography.

Proposed operating model

Chapter 1 · Operating model

One record from intake through change review

Review depth changes with consequence and uncertainty. The decision record does not disappear at approval; monitoring, incidents, and material changes route back into it.

  1. Intake

    Define intended use, affected people, owner, data, model or vendor, autonomy, workflow, and decision consequence.

  2. Tier

    Set review depth from consequence, population, data sensitivity, reversibility, scale, and human authority.

  3. Review

    Bring required domain owners into one evidence record and separate expert judgment from unresolved questions.

  4. Decide

    Approve, condition, return for evidence, restrict, or stop. Record rationale, owner, conditions, expiry, and dissent.

  5. Release

    Verify controls, training, fallback, monitoring, escalation, and the accountable signoff before go-live.

  6. Monitor and change

    Connect bounded signals to action and reopen review when the model, data, vendor, workflow, use, law, or incident changes.

No accountable owner means no release decision.

An unresolved expert question stays unresolved in the record.

A condition without a test, owner, and expiry is not a condition.

Monitoring without a named action is observation, not governance.

A material model, data, vendor, workflow, use, or law change reopens review.

Chapter 2 · Case decisions

Three findings that changed the system

Consent and identity, a medical-function boundary, and agentic action control show three different kinds of stop decision.

Read the full cases

Chapter 3 · Evidence system

A reviewer can reconstruct the decision

Every artifact answers a different question. Together they connect the use, risk, authority, control, disposition, and post-release action.

Intended-use record

Who uses the system, for what, in which workflow, and with what consequence?

Risk and impact record

Who may be affected, what can fail, and where is uncertainty still material?

Decision-rights map

Who advises, who owns each expert judgment, and who may approve or stop release?

Rule-to-control map

What implements each requirement, what proves it operates, and how is an exception governed?

Decision record

What was decided, why, under which conditions, until when, and what would reopen it?

Monitoring and incident plan

Which signal has which owner, bound, first action, escalation, closure evidence, and re-review trigger?

Controls lab

Four controls you can run in this browser

Consent, validation, secret scanning, and retention behavior run on fictional data in your tab. Nothing is sent, stored, or measured.

Most demos show the happy path. This one defaults to the refusal, because what a system does when it is not allowed to proceed is the only part worth trusting.

Demo — sample data only. No client or customer data. Runs entirely in your browser; nothing you interact with is sent anywhere.

Refused — the session does not run

  1. Consent record present and current — blocked

    No record found for this participant. The gate stops here — it does not fall through to a default.

  2. Teach-back completed — not evaluated

    Not evaluated. Once a gate blocks, later checks do not run and cannot overturn it.

  3. Scope matches the requested action — not evaluated

    Not evaluated.

  4. Refuse — blocked

    Session refused and the refusal is logged with the rule that caused it. A human is notified; the system does not retry.

The obvious failures get caught before any model is even asked

A missing disclosure, a promised outcome, numbers that disagree — no AI is needed to catch these, and none is used. Three plain rules run in this tab; edit the text and watch them fire.

Demo — sample data only. No client or customer data. Runs entirely in your browser; nothing you interact with is sent anywhere.

Blocked by 1 deterministic rule — no model was consulted

  • Required disclosure present — passed

    Care-sector output must carry its disclosure. A missing one is a compliance defect, not a style note.

  • No absolute-outcome language — failed

    A model will happily promise an outcome. A regex will not let it.

  • Numeric claim is internally consistent — passed

    "Five of the four" is the kind of thing fluent text hides and arithmetic catches instantly.

An LLM judge can run after this, and it is useful for the things rules cannot see. It runs second, and it cannot overturn a deterministic failure.

A dangerous change is stopped before it ships — and the gate names why

A simplified version of the fence that runs on every change. Pick a diff — three of the four are meant to be stopped, and the gate names which check stopped them.

Demo — sample data only. No client or customer data. Runs entirely in your browser; nothing you interact with is sent anywhere.

+ const client = new Client({
+   apiKey: 'sk-live-9f2c4a7e11b8', // committed by mistake
+ });

Release blocked by: Secret scan

  • Secret scan — blocked

    A live-format API key appears in the diff. Blocked before it can reach a remote.

  • Destructive-action classifier — passed

    No irreversible operations.

  • Claim-of-done requires evidence — passed

    Change is covered by the existing suite.

What is kept when the session ends

Retention off is the production default. Toggle it and watch the record change shape — with retention off the verbatim fields are absent from the page, not merely hidden.

Demo — sample data only. No client or customer data. Runs entirely in your browser; nothing you interact with is sent anywhere.

Structured summary only — there is no transcript to leak

Session id
ssn_8f21c4 (synthetic)
Duration
14 min
Topics covered
scheduling · medication reminders · follow-up
Action items
3 created, 1 assigned to a human reviewer
Sentiment band
neutral-positive

The three fields that appear when you toggle retention on are not on this page right now. That is the difference between minimisation and redaction.

Runnable observability evidence

A live model run has to show its work after it ships

Run deployed-model telemetry, automated output checks, evaluator calibration, and agent action monitoring in one evidence chain. The new control room makes missing instrumentation a blocking result instead of an empty chart.

Run the observability control room

Chapter 4 · Current framework alignment

Frameworks organize the evidence; authority still has an owner

This map was reviewed on 21 August 2026. It distinguishes voluntary frameworks, standards, certification references, and legal applicability questions instead of presenting them as interchangeable badges.

Open the source map

Voluntary risk-management framework

NIST AI RMF 1.0 + GenAI Profile

Govern, Map, Measure, and Manage evidence, with generative and agentic risk practices. Mapping reviewed while NIST revises the RMF in 2026.

Open the primary source (opens in a new tab)

Healthcare governance guidance

CHAI governance playbooks

Policy, structures, resources, lifecycle use, risk and impact, data, third parties, and education, training, and feedback.

Open the primary source (opens in a new tab)

Management-system and impact-assessment standards

ISO/IEC 42001 and 42005

Organization-wide responsibility, objectives, operation, evaluation, continual improvement, and AI system impact assessment. No certification claim is made.

Open the primary source (opens in a new tab)

Voluntary organization-level certification reference

Joint Commission responsible AI

A health-organization operating reference for responsible AI use, not a product badge or a personal credential.

Open the primary source (opens in a new tab)

Authority-specific applicability review

Healthcare legal triggers

HIPAA, FDA software-function boundaries, ONC HTI-1, and current state law are scoped by use, actor, workflow, data, geography, and effective date, then routed to the proper authority owner.

Open the primary source (opens in a new tab)

Next step

The work is public. The application strategy is not.

Open the cases, search the full evidence index, read the résumé, or start a direct conversation.