AI operating governance · Field note

Choose AI limits before the model

TL;DR

Before comparing AI vendors, write down the permitted use, the data allowed, the strongest action the tool may take, who owns each part of the work, and what sends the decision back for review. Then choose a model that fits.

What the paper develops

A model can look impressive and still be wrong for the work, data, or actions an organization is ready to support. Before comparing vendors, state what the tool may do and what it may not do.

Start with five choices: the use, data, action limit, work split, and approval triggers. Name the owner for each. Then compare models that fit those choices.

Set the first limits before the shortlist. Before commitment, test the selected model, hosting, contract, supplier chain, and workflow against them. If the candidate needs broader data or more power, return that change for a visible decision.

This is not legal advice. It gives legal, security, data, procurement, and business owners a reliable set of facts before a vendor's defaults become the operating design.

Record the evidence, owner, date, and status for each choice. Mark it as a fact, judgment, or open question. Give every open question an owner and a due date.

New users, a new region, a different data class, an outside integration, or an automated action can all send the decision back for review.

Use one page for an AI request entering sourcing. Write the use, data, action limit, work split, and review triggers before comparing vendors.

What to do next

Take one AI request entering sourcing. Write its five limits on one page before comparing vendors.

WORKFLOWCONTROL EVIDENCEHUMAN OWNER

Inside the white paper

  • Five choices that define an AI deployment
  • How a two-pass review keeps vendor defaults visible
  • One record for owners, evidence, and review triggers

Sources and notes

  1. European Commission, AI Act, Shaping Europe’s digital future, updated August 3, 2026 — the Commission's current AI Act timing page explains the general milestone and earlier and later rules.
  2. European Parliament and Council of the European Union, Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, July 12, 2024 — the EU AI Act uses intended purpose, roles, and context when it assigns duties.
  3. European Parliament and Council of the European Union, Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), Official Journal of the European Union, July 24, 2026 — the 2026 Digital Omnibus changed dates for some high-risk and transparency requirements.
  4. Elham Tabassi, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, National Institute of Standards and Technology, January 26, 2023 — NIST's AI RMF calls for intended use, context, documented risk tolerance, roles, and third-party risks.
  5. Chloe Autio, Reva Schwartz, Jesse Dunietz, Shomik Jain, Martin Stanley, Elham Tabassi, Patrick Hall, and Kamie Roberts, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, National Institute of Standards and Technology, July 26, 2024 — NIST's GenAI Profile covers design, development, use, and evaluation across a system lifecycle.
  6. Cybersecurity and Infrastructure Security Agency, United States Digital Service, and Federal Risk and Authorization Management Program, Cloud Security Technical Reference Architecture, Version 2.0, June 2022 — U.S. government cloud guidance describes shared responsibility between customer and provider.
  7. National Institute of Standards and Technology, AI RMF Core, Artificial Intelligence Resource Center, excerpt from Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 — NIST's AI RMF Core addresses context, alternatives, and third-party risks.