AI Governance that helps people decide.
A practical operating model for evaluating, approving, deploying, and overseeing AI.
Most organisations do not need another policy document. They need a clear way to decide which AI initiatives can proceed, what evidence is required, who owns the decision, and how the organisation will know whether the capability is safe and useful.
Discuss an AI governance diagnosticQuestions leaders need answered
- What AI tools and use cases are already in use?
- Who approved them?
- What data do they use?
- Which initiatives are experimental and which are operational?
- What decisions can an AI system influence or make?
- What remains human-owned?
- What evidence is required before scaling?
- How will changes, failures, and retirement be managed?
Framework components
AI pathways
Proportional routes from exploration through proof, pilot, governed adoption, and enterprise operation.
Decision rights
Clear ownership and escalation for business, architecture, risk, security, privacy, legal, and executive decisions.
Tool and use-case evaluation
Assessment across strategic fit, data sensitivity, integration, vendor risk, regulatory exposure, architecture fit, build or buy, and benefit measurability.
Maturity assessment
A practical view of current governance capability and the next level of improvement.
Agentic architecture oversight
Authority boundaries, permissions, human approval, auditability, observability, rollback, and shutdown.
The AI pathway model
Not every AI initiative needs the same route to production. A short evaluation determines which of six pathways a use case should follow, and whether it needs to pass through a protected engineering gate before it can be deployed.
- Use case identified
- Explore and evaluate
- AI evaluation framework
- Architecture governance gate
AI evaluation framework — four routing questions at the governance gate
Autonomy
Is a human-in-the-loop required?
Data
Do you have the data, and can you use it?
Risk
What is the cost of an AI error in this function?
Integration
What systems and workflows does it connect to?
These four answers determine which pathway a use case follows.
Six pathways
LLM-native agent publishing — the fastest path to a contracted outcome.
Content, customer service, catalogue
Buy the specialist solution, and govern selection and integration.
Demand forecasting, pricing intelligence
Workflow automation on the platform already in place.
Order processing, ERP triggers
On-premise models for data-sensitive or latency-critical work.
Customer data, internal knowledge
Protected engineering pathwayActivate AI capability already built into tools the organisation owns.
ERP AI, CRM AI, commerce AI
Rapid prototyping through to full engineering discipline, where a genuine advantage is being built.
Proprietary models, data ownership
Protected engineering pathwayPathways 4 and 6 pass through a protected engineering gate — security scanning, architecture sign-off, and time-limited governance — before reaching production.
Production — governed AI deployment
View the AI pathway model as text
A use case moves from identification through an explore-and-evaluate step, into the AI evaluation framework, and reaches an architecture governance gate.
The evaluation framework asks four routing questions:
- Autonomy: Is a human-in-the-loop required?
- Data: Do you have the data, and can you use it?
- Risk: What is the cost of an AI error in this function?
- Integration: What systems and workflows does it connect to?
Depending on the answers, the use case follows one of six pathways:
- Publish agents — LLM-native agent publishing — the fastest path to a contracted outcome. (Content, customer service, catalogue)
- RFx / niche AI — Buy the specialist solution, and govern selection and integration. (Demand forecasting, pricing intelligence)
- Automation / low-code — Workflow automation on the platform already in place. (Order processing, ERP triggers)
- Local LM / SLM — On-premise models for data-sensitive or latency-critical work. (Customer data, internal knowledge) — protected engineering pathway.
- Existing stack / add-ons — Activate AI capability already built into tools the organisation owns. (ERP AI, CRM AI, commerce AI)
- Custom build — Rapid prototyping through to full engineering discipline, where a genuine advantage is being built. (Proprietary models, data ownership) — protected engineering pathway.
Pathways 4 and 6 pass through a protected engineering gate — security scanning, architecture sign-off, and time-limited governance — before reaching production. All pathways conclude in a governed production deployment.
Relationship to OCTA and The Hunting Ground
AI Governance controls the pathway and decision rights. OCTA structures the architecture and execution. The Hunting Ground helps identify where AI opportunity may exist.