Responsible AI is not a committee that meets after the product is designed. It is a set of operating decisions that follow the workflow from idea through retirement.

1. Classify the consequence

Identify the decision the system influences and the harm created by a wrong, unavailable, manipulated, or over-trusted output. Use consequence tiers to scale validation, approval, oversight, and evidence.

2. Assign one accountable owner

A cross-functional team can contribute, but accountability cannot be a group noun. Name the executive or product owner responsible for the consequence and the technical owner responsible for the system’s operation.

3. Establish data boundaries

Document permitted inputs, prohibited data, retention, provider use, regional processing, and downstream exposure. Test whether the real workflow follows the diagram.

4. Define human authority

Specify when review is required, what evidence a reviewer receives, who can override, and who can suspend. Measure whether the review changes decisions instead of merely recording clicks.

5. Use a launch gate

Require evidence appropriate to the tier: performance across relevant populations, failure-mode tests, adversarial and abuse scenarios, privacy and security review, continuity, rollback, and user communication.

6. Monitor outcomes, not only model health

Track drift and latency, but also overrides, complaints, disparate outcomes, automation bias, data leakage, and business consequence. A technically healthy model can still create an unhealthy workflow.

7. Schedule review and retirement

Set a review date, material-change trigger, and retirement path. Models, providers, policies, and the environments around them change. Governance must be able to notice.