An enterprise AI agent can do more than generate an answer. It can select tools, retrieve information, retain state, delegate work, and change a business system. Responsible AI therefore has to govern the complete operating system and the consequences of its actions.
The central recommendation is to approve a bounded deployment configuration: a defined business mandate, accountable owner, permitted actions, controlled tools and memory, tested oversight, and independently observable outcomes. Approval should identify the configuration that was evaluated and specify the changes that invalidate its evidence.
- Establish authority before execution. A model's proposed action must pass an independent authorization check. Consequential approvals must bind the actual action, affected resources, permitted variation, and expiry.
- Verify outcomes after execution. Check the external business state before declaring completion. Reconcile partial, uncertain, and duplicated effects. An agent's explanation is supporting evidence, not independent outcome verification.
- Measure prevention and useful work together. Keep critical prohibited effects, business utility, review burden, customer outcomes, and recovery as separate acceptance conditions. A system that refuses every task has not demonstrated useful operation.
- Maintain assurance throughout operation. Changes to prompts, memory, models, tools, permissions, monitors, and delegation can change behavior. Incidents and material changes reopen the relevant control claims.
This handbook supplies the knowledge and artifacts needed to put that approach into practice: definitions and risk assessment, a control architecture, operating and assurance guidance, worked workflows, a 90-day implementation sequence, 45 baseline control practices, 12 detailed implementation specifications, and 36 proposed acceptance tests. The control practices and tests are original proposed enterprise designs. Their presence is not evidence of effectiveness in an enterprise.
Recent research reinforces the need to test complete configurations. Selected September interaction experiments reported 43 pairwise safety failures among components that passed separately. A proactive-monitoring benchmark reported a highest optimal-window interruption result of 40.74% among its evaluated models. These findings concern the specified experiments. They do not estimate an institution's production failure rate. [S11, S13]