TL;DR
Govern AI access where the work happens, proportioned to the stakes of each workflow.
What the paper develops
Blanket access policies treat every AI use as if the data, consequence, and recovery path were the same. This paper moves governance into the workflow, where those differences are visible. It shows how to tier uses by consequence, define permitted actions and evidence duties, and assign review and escalation without forcing low-risk work through the same controls as consequential decisions.
The operating move
Set AI permissions at the workflow level. Match access, review, and evidence requirements to the data involved, the consequence of error, and the ability to recover when the output is wrong.
WORKFLOWCONTROL EVIDENCEHUMAN OWNER
Inside the white paper
- Workflow-level risk tiers for access, use, and reliance
- Decision rights, evidence duties, and human review by consequence
- Monitoring, exception handling, and escalation when boundaries are crossed
Sources and notes
- Gabriel Morgan Asaftei, Roger Roberts, Abby Sticha, and Cécile Prinsen, "State of AI trust in 2026: Shifting to the agentic era," McKinsey & Company, March 25, 2026. mckinsey.com
- National Institute of Standards and Technology, "AI Risk Management Framework Core," excerpt from AI RMF 1.0, 2023. Verified July 5, 2026. airc.nist.gov
- Chloe Autio, Reva Schwartz, Jesse Dunietz, Shomik Jain, Martin Stanley, Elham Tabassi, Patrick Hall, and Kamie Roberts, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, July 26, 2024. doi.org