AI Governance that helps people decide.

A practical operating model for evaluating, approving, deploying, and overseeing AI.

Most organisations do not need another policy document. They need a clear way to decide which AI initiatives can proceed, what evidence is required, who owns the decision, and how the organisation will know whether the capability is safe and useful.

Discuss an AI governance diagnostic

Questions leaders need answered

  • What AI tools and use cases are already in use?
  • Who approved them?
  • What data do they use?
  • Which initiatives are experimental and which are operational?
  • What decisions can an AI system influence or make?
  • What remains human-owned?
  • What evidence is required before scaling?
  • How will changes, failures, and retirement be managed?

Framework components

AI pathways

Proportional routes from exploration through proof, pilot, governed adoption, and enterprise operation.

Decision rights

Clear ownership and escalation for business, architecture, risk, security, privacy, legal, and executive decisions.

Tool and use-case evaluation

Assessment across strategic fit, data sensitivity, integration, vendor risk, regulatory exposure, architecture fit, build or buy, and benefit measurability.

Maturity assessment

A practical view of current governance capability and the next level of improvement.

Agentic architecture oversight

Authority boundaries, permissions, human approval, auditability, observability, rollback, and shutdown.

The AI pathway model

Not every AI initiative needs the same route to production. A short evaluation determines which of six pathways a use case should follow, and whether it needs to pass through a protected engineering gate before it can be deployed.

  1. Use case identified
  2. Explore and evaluate
  3. AI evaluation framework
  4. Architecture governance gate

AI evaluation framework — four routing questions at the governance gate

Autonomy

Is a human-in-the-loop required?

Data

Do you have the data, and can you use it?

Risk

What is the cost of an AI error in this function?

Integration

What systems and workflows does it connect to?

These four answers determine which pathway a use case follows.

Six pathways

1Publish agents

LLM-native agent publishing — the fastest path to a contracted outcome.

Content, customer service, catalogue

2RFx / niche AI

Buy the specialist solution, and govern selection and integration.

Demand forecasting, pricing intelligence

3Automation / low-code

Workflow automation on the platform already in place.

Order processing, ERP triggers

4Local LM / SLM

On-premise models for data-sensitive or latency-critical work.

Customer data, internal knowledge

Protected engineering pathway
5Existing stack / add-ons

Activate AI capability already built into tools the organisation owns.

ERP AI, CRM AI, commerce AI

6Custom build

Rapid prototyping through to full engineering discipline, where a genuine advantage is being built.

Proprietary models, data ownership

Protected engineering pathway

Pathways 4 and 6 pass through a protected engineering gate — security scanning, architecture sign-off, and time-limited governance — before reaching production.

Production — governed AI deployment

Figure: The AI pathway model — from a use case to a governed production deployment.
View the AI pathway model as text

A use case moves from identification through an explore-and-evaluate step, into the AI evaluation framework, and reaches an architecture governance gate.

The evaluation framework asks four routing questions:

  • Autonomy: Is a human-in-the-loop required?
  • Data: Do you have the data, and can you use it?
  • Risk: What is the cost of an AI error in this function?
  • Integration: What systems and workflows does it connect to?

Depending on the answers, the use case follows one of six pathways:

  1. Publish agentsLLM-native agent publishing — the fastest path to a contracted outcome. (Content, customer service, catalogue)
  2. RFx / niche AIBuy the specialist solution, and govern selection and integration. (Demand forecasting, pricing intelligence)
  3. Automation / low-codeWorkflow automation on the platform already in place. (Order processing, ERP triggers)
  4. Local LM / SLMOn-premise models for data-sensitive or latency-critical work. (Customer data, internal knowledge) — protected engineering pathway.
  5. Existing stack / add-onsActivate AI capability already built into tools the organisation owns. (ERP AI, CRM AI, commerce AI)
  6. Custom buildRapid prototyping through to full engineering discipline, where a genuine advantage is being built. (Proprietary models, data ownership) — protected engineering pathway.

Pathways 4 and 6 pass through a protected engineering gate — security scanning, architecture sign-off, and time-limited governance — before reaching production. All pathways conclude in a governed production deployment.

Relationship to OCTA and The Hunting Ground

AI Governance controls the pathway and decision rights. OCTA structures the architecture and execution. The Hunting Ground helps identify where AI opportunity may exist.

Make AI decisions with the right oversight.

Book a discovery call