The practical unit of AI risk is not the model in isolation. It is the decision a person or system makes because of the model’s output. That distinction is where useful governance begins.

Start with consequence

A low-consequence drafting assistant and a system that influences care, access, employment, money, or safety should not pass through the same generic approval process. Classify the workflow by what happens when it is wrong, unavailable, manipulated, or trusted too quickly.

The classification should change the controls. Higher-consequence systems need stronger validation, narrower data boundaries, explicit human authority, more durable evidence, and a tested way to stop or fall back.

Define the human authority before launch

“Human in the loop” is not a control unless the human has time, information, authority, and a usable interface. Name who can approve, override, suspend, and explain the workflow. Give that person evidence that reveals uncertainty instead of presenting every output with the same confidence.

If the operator cannot see why an output deserves scrutiny, the review step becomes ceremony. If the operator is punished for slowing the workflow, the review step becomes theater.

Govern the data path

Map what enters the system, where it is processed, what a provider retains, which jurisdictions or subcontractors are involved, and how data leaves. Sensitive-data controls should survive convenience. Production secrets, patient information, proprietary research, and regulated records do not become safe because a vendor labels a conversation private.

Keep evidence that can survive review

For consequential workflows, preserve the model or service version, material inputs, relevant policy, reviewer action, override, and final outcome. The goal is not infinite logging. It is enough trustworthy evidence to reconstruct why a decision occurred and whether the control worked.

Design the exit

Every launch plan should name a shutdown condition, rollback owner, manual continuity path, and review date. A system that cannot be stopped safely is not mature merely because its benchmark looks strong.

Responsible AI is not a policy document placed beside the product. It is an operating system for authority, evidence, data, and recovery.