Business Core · Technology · Module
AI and automation
Where AI and automation are used, who remains accountable for what they do, how well they are shown to work, and what risk each use carries.
The idea
How it works
AI differs from earlier automation in one respect that shapes the rest: its output is probabilistic. A rules engine does the same thing each time; a language model may not, and it can be fluent and wrong in the same sentence. That moves the work from specifying behaviour to measuring it, and each use needs an answer to how good is good enough, and who notices when it falls short.
The sequence the main frameworks converge on — the NIST AI Risk Management Framework and ISO/IEC 42001 — is to know what is in use, decide the level of human involvement for each use, evaluate before and after deployment, and classify by risk. The EU AI Act adds a regulatory reading of that classification. Which of its obligations apply is established in Compliance under regulatory mapping, the data the systems draw on is governed in Data Core, and the redesign of a process around automation belongs to Operational Systems.
Working with it
In practice
- 01
Start from the task, not the model
Name the decision or piece of work being changed and what a good outcome looks like. The choice of model follows from that.
- 02
Register every use, including informal ones
Staff using a public assistant on company material is a use. A register that lists only sanctioned projects describes a minority of what is happening.
- 03
Set human involvement deliberately
Whether a person decides, approves, monitors or is simply informed — chosen for each use by what an error would cost.
- 04
Evaluate against a fixed test set
Real cases with agreed good answers, run before launch and again after every change of model, prompt or provider.
One level in
The components of ai and automation
A component is something that exists afterwards which did not exist before — a deliverable or a mechanism, not an intention.
AI use-case register
Every place AI or automation is used, with its task, owner, provider, autonomy and risk classification.
LearnAI acceptable-use policy
What staff may and may not do with AI tools, which tools are sanctioned, and what material may be given to them.
LearnHuman oversight design
For each use, where a person reviews, approves or can stop the system, and what they need to do so meaningfully.
LearnAI evaluation record
The test set, the measured quality, the thresholds accepted, and how performance is watched once the system is live.
Learn
An AI system nobody has measured has an unknown error rate, which is not the same as a low one. Build the test set before choosing the model.
The other modules in technology
The technology estate
What systems the organisation runs, how they connect, and the few principles that decide what may be added to them.
LearnBuild, buy or subscribe
Deciding, for each capability, whether to build it, license it or rent it as a service — and recording why, so the reasoning can be revisited.
LearnSecurity
Protecting the estate as a capability: knowing what is worth attacking, holding a baseline of controls, managing who can get in, and being able to recover.
LearnTechnical debt and renewal
What the estate owes to decisions made earlier, which of those debts are worth repaying, and how ageing systems are replaced without stopping the business.
Learn