Do we have legitimate authority and a bounded purpose?
Confirm authority limits, intended human benefit, affected people, accountable ownership, intended uses, exclusions, and prohibited practices.
From principle to practice
Start with one bounded workflow, name the accountable people, compare alternatives, exercise failure, and expand only when the evidence supports it.
Decision protocol
These checkpoints are decisions, not implementation phases. They determine whether work may proceed before procurement, development, pilot, live use, material change, renewed conformance, or resuming after a serious incident.
Confirm authority limits, intended human benefit, affected people, accountable ownership, intended uses, exclusions, and prohibited practices.
Assign the risk tier and compare no action, delay, non-AI, narrower, less intrusive, and more reversible paths.
Separate facts from inference, establish data authority and limits, inventory tools and dependencies, and confirm fallback and correction.
Test normal, edge, adversarial, accessibility, recovery, appeal, rollback, emergency-stop, and incident conditions.
Record residual risk, controls, thresholds, rollback, notice, appeal, evidence locations, accountable approval, and required independent approval.
Monitor outcomes and change, investigate thresholds, contain harm, correct downstream effects, and decide whether to resume, revise, or retire.
Implementation guide
These are phases of workânot approval gates. They describe what a team builds, tests, limits, monitors, changes, and eventually retires.
One workflow, owner, affected population, decision boundary, authority, and fallback.
Document inputs, decisions, handoffs, existing burden, errors, appeals, workarounds, and baseline performance.
Give each hazard an owner, retained evidence, metric, thresholds, and failure response.
Test conflicting evidence, overload, hostile input, tool overreach, rollback, incident repair, and change.
Compare AI-assisted output with the baseline without allowing it to influence live decisions.
Begin live use only after gates pass, keep scope bounded, review controls, and retire when benefit or safety fails.
Eight-week pilot
The pilot uses reversible decisions, named owners, predefined gates, and stop conditions that override schedule pressure.
Readiness, scope, roles, authority, risk tier, fallback, incident, and appeal paths.
Baseline the current non-AI workflow, burden, errors, accessibility, appeals, and data practices.
Complete controls and run tabletop exercises. Correct and retest failures.
Shadow mode without operational reliance. Compare quality, burden, uncertainty, and disagreement.
Limited live use only after approval, with bounded population, volume, duration, data, tools, and actions.
Compare against baseline and choose adopt within scope, revise and retest, or stop and repair.
Measurement
Important tradeoffs remain visible. Every target metric is paired with counter-metrics that expose displaced harm, burden, or gaming.
Human benefit, harm, near misses, missed risk, recurrence, and excluded needs.
Notice, alternatives, correction, appeal, repair time, unresolved effects, and retaliation.
False results, unsupported claims, uncertainty, abstention, escalation, disagreement, and downstream error.
Human-review coverage, audit completeness, workload, changes, deletion, rollback, and drift.
Detection, containment, closure, repeat failure, corrective action, feedback, and public-safe summaries.