Original practitioner framework
AI Control Envelope
Define the conditions within which an AI-enabled use remains acceptable and detectable.
Problem addressed
A model metric alone does not control data, prompts, retrieval, permissions, human reliance, or operational drift.
Limitation of existing practice
Point-in-time model testing cannot establish continued fitness across changing context.
Proposed method: inputs and steps
- Define approved users, decisions, inputs, and prohibited uses.
- Set data and performance boundaries.
- Specify deterministic guardrails and human authority.
- Define monitoring thresholds and response actions.
- Control model, prompt, retrieval, and tool changes.
Decision outputs
- Approved operating envelope
- Control and monitoring map
- Restriction and rollback criteria
Worked example
An AI complaint classifier may recommend a category but cannot set seriousness, submit the record, or operate below a subgroup recall threshold.
When to use—and when not to
Use when: Assuring probabilistic or AI-enabled functions.
Do not use as-is when: The function is entirely deterministic; use conventional boundary and control methods.
Limitations
Thresholds need representative data and ongoing review.
Inspection questions
- What use is prohibited?
- Which threshold triggers restriction?
- Can the human reviewer detect a plausible error?
Printable working aid
AI Control Envelope worksheet
A clean, browser-printable worksheet for workshop or assessment use.
Version and citation
| Version | 1.0 |
|---|---|
| Author | Sandip Thorat |
| Publication / review | September 4, 2026 |
| Revision history | 1.0 — Initial migration-preview publication |
| Suggested citation | Thorat, S. (2026). “AI Control Envelope.” CSV to CSA Knowledge Hub, version 1.0. |
| External adoption | No verified public evidence supplied; no adoption claim is made. |