Skip to main contentSkip to contact

Senior operators only. No agency structure. No junior layer.

AI authority and operating control

When AI can act, decide where it must stop.

An AI system does not need to be failing to deserve examination. Once it can read business information, recommend a decision or take an action, leadership needs a clear view of its authority, evidence and boundaries.

A simple authority map
Business evidence
AI system

Recommends

Human decides

Acts

Approval boundary

Customer, money, reputation or operations

The important change is authority, not the label

Terms such as assistant, copilot and agent are used inconsistently. The useful question is what the system can actually do in your environment.

01

Answer

It produces a response from the information provided. A person still decides what happens next.

02

Access

It can read connected files, records, messages or systems. Read-only access can still expose information or influence a decision.

03

Recommend

It interprets evidence and proposes a next action. The quality of the recommendation still depends on the evidence, instructions and operating context.

04

Act

It can create, change, publish, send, buy, move or delete something. The consequence can now reach customers, money, reputation or operations.

Five questions before more authority is handed over

Use one real workflow. Do not answer in generalities and do not paste confidential, financial or customer information into a public tool.

  1. Where does AI enter the workflow?

    Name the exact task, trigger and intended outcome.

  2. What can it access?

    List the files, records, messages, customer information and connected systems it can read.

  3. What can it create, change or send?

    Separate suggestions from actions that produce a real operational consequence.

  4. Where must a person approve?

    Name the responsible person, the evidence they see and what they are authorised to stop.

  5. Can the result be checked, stopped and reversed?

    Confirm that actions are logged, independently checked where needed and recoverable when something goes wrong.

Prompt injection

A document can contain an instruction as well as information

Imagine a forged note placed inside a genuine customer file. A person may recognise that it did not come from the account owner. An AI system reading the file may treat that note as an instruction. This is one form of prompt injection. The potential consequence depends on what the system can access and what authority it has been given.

Controls that match the consequence

Scope

Define the task and the systems that are genuinely required.

Permission

Give the smallest access and action rights needed for that task.

Approval

Put an authorised person in front of expensive, sensitive or difficult-to-reverse actions.

Evidence

Record what the system used, recommended and did so the result can be reconstructed.

Stop and reverse

Make interruption and recovery part of the workflow, not an emergency improvisation.

The answer does not have to be “stop using AI”

A sound review can support any of these decisions:

Continue

  • continue as configured
  • continue with better evidence

Change the conditions

  • restrict access or authority
  • add an approval or verification step
  • test the workflow further

Stop or stand still

  • change or stop the use
  • take no further action

One workflow. One consequential decision.

AI Authority Snapshot

A fixed-scope examination for a leadership team that needs a decision on one named AI-enabled workflow, without commissioning an organisation-wide programme.

€2,500 fixed fee

plus applicable VAT

Decision record delivered within 7 to 10 working days, subject to access and availability.

Check whether the Snapshot fits

Up to three workflows across two functions.

Cross-functional AI Authority Review

For a leadership team whose authority question crosses systems, owners or more than one business function.

From €7,500

plus applicable VAT

Decision record delivered within 10 to 15 working days, subject to access and availability.

Check which review fits

What it includes

  • the decision, claimed value and operating context
  • the workflow, access and authority boundary
  • the human approval and ownership points
  • the evidence available and what remains unknown
  • a written decision record and senior walkthrough

What it does not include

  • an organisation-wide inventory of every AI use
  • penetration testing or security certification
  • legal, regulatory or data-protection advice
  • a guaranteed saving, return or compliance outcome
  • implementation outside the agreed workflow

When the question is wider than three workflows or two functions

If AI is only one part of a wider problem involving marketing, sales, ecommerce, customer operations, measurement or ownership, the work moves into the full Marketing MRI. Neither smaller review quietly expands into a discounted MRI.

If your immediate question is whether AI mentions, citations or referrals support a commercial decision, use the visibility evidence check first.

Sources and boundaries

These sources support the control principles. They do not establish that every AI use is high risk or that your current system is unsafe.

Bring the decision, not sensitive data

Tell us which workflow is involved, what decision you need to make and why the consequence matters. We will tell you whether the Snapshot, cross-functional review, Marketing MRI or no paid examination is the right route.

  • One named workflow to start
  • No confidential data
  • A personal scope decision
Step 1 of 2

Check which review fits

Start with the most consequential workflow. Choose the closest answers and do not include confidential, financial or customer information.

Which decision do you need to make?
What can the system currently do?

Choose all that apply.