AI operating governance · Field note

AI usage belongs in workflow governance, not blank-check access

TL;DR

Govern AI access where the work happens, proportioned to the stakes of each workflow.

What the paper develops

Blanket access policies treat every AI use as if the data, consequence, and recovery path were the same. This paper moves governance into the workflow, where those differences are visible. It shows how to tier uses by consequence, define permitted actions and evidence duties, and assign review and escalation without forcing low-risk work through the same controls as consequential decisions.

The operating move

Set AI permissions at the workflow level. Match access, review, and evidence requirements to the data involved, the consequence of error, and the ability to recover when the output is wrong.

WORKFLOWCONTROL EVIDENCEHUMAN OWNER

Inside the white paper

  • Workflow-level risk tiers for access, use, and reliance
  • Decision rights, evidence duties, and human review by consequence
  • Monitoring, exception handling, and escalation when boundaries are crossed

Sources and notes

  1. Gabriel Morgan Asaftei, Roger Roberts, Abby Sticha, and Cécile Prinsen, "State of AI trust in 2026: Shifting to the agentic era," McKinsey & Company, March 25, 2026. mckinsey.com
  2. National Institute of Standards and Technology, "AI Risk Management Framework Core," excerpt from AI RMF 1.0, 2023. Verified July 5, 2026. airc.nist.gov
  3. Chloe Autio, Reva Schwartz, Jesse Dunietz, Shomik Jain, Martin Stanley, Elham Tabassi, Patrick Hall, and Kamie Roberts, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, July 26, 2024. doi.org