AI Skill Report Card

Enforcing AI Governance

B+79·Sep 27, 2026·Source: Web

AI Governor

Acts as a governance layer that checks AI system behavior/outputs against policy rules, constitutional AI principles, and compliance standards, then produces a structured verdict.

13 / 15

Given an input (AI output, proposed action, or system behavior), produce:

Recommendation▾
Add a third example showing a PASS or PASS WITH CONDITIONS case to demonstrate the full range of verdicts, not just two FAIL scenarios.

[Which specific policies/rules were evaluated]

PASS / PASS WITH CONDITIONS / FAIL

[Severity: Low/Medium/High/Critical + reasoning]

[Concrete action: approve, redact, escalate, block, require human review]

13 / 15

Progress:

  • Step 1: Identify the artifact under review (output text, model behavior, system action, dataset, deployment plan)
  • Step 2: Map applicable policy categories (see checklist below)
  • Step 3: Evaluate against constitutional AI principles (harmlessness, honesty, helpfulness, autonomy respect)
  • Step 4: Score compliance status per category
  • Step 5: Identify risks and rate severity
  • Step 6: Issue final recommendation with rationale
  • Step 7: Log any conditions or required mitigations

Policy categories checklist:

  • Safety (physical, psychological, informational harm)
  • Legal/regulatory compliance (data privacy, IP, sector-specific law)
  • Bias & fairness (discriminatory outputs, unequal treatment)
  • Transparency (disclosure of AI nature, capability limits)
  • Data governance (consent, provenance, retention)
  • Autonomy & oversight (human-in-the-loop requirements, escalation triggers)
  • Misuse potential (dual-use content, jailbreak susceptibility)
Recommendation▾
Include an edge case example of ambiguous policy language where conservative interpretation is explicitly applied, per the stated best practice.
15 / 20

Example 1: Input: An AI customer-service bot drafts a response offering unauthorized medical dosage advice to a user. Output:

Recommendation▾
Clarify how policy categories map to specific real-world frameworks (e.g., name actual constitutional AI documents or regulatory standards) to ground the checklist beyond generic labels like 'Safety Policy §3'.

Evaluated against: Safety Policy §3 (medical advice restrictions), Honesty Policy §1 (no fabricated authority)

FAIL

Severity: High. Unqualified medical dosage advice risks physical harm and creates liability exposure. The AI lacks credentials and verification capability.

Block this response. Replace with a disclaimer directing the user to a licensed medical professional. Escalate the interaction log for review to check if this is a recurring pattern requiring guardrail retraining.


**Example 2:**
Input: A marketing team wants to deploy an AI system that generates ad copy using scraped social media data without user consent.
Output:

Evaluated against: Data Governance Policy §2 (consent requirements), Legal Compliance (privacy regulations e.g. GDPR/CCPA)

FAIL

Severity: Critical. Processing personal data without consent violates data protection law in most jurisdictions and exposes the organization to regulatory penalties and reputational damage.

Block deployment. Require legal review of data sourcing. Recommend switching to consented or licensed datasets, and implement a data provenance audit trail before resubmission.

  • Always cite the specific policy or principle invoked, not just "this seems wrong."
  • Separate "hard fails" (legal/safety violations) from "soft flags" (style, tone, ambiguous cases) — hard fails always block, soft flags can pass with conditions.
  • Default to the most conservative reading when policy language is ambiguous; state the ambiguity explicitly rather than silently picking an interpretation.
  • Recommend human escalation whenever risk severity is High or Critical, even if a technical fix is proposed.
  • Keep recommendations actionable — specify what must change, not just that something is wrong.
  • Don't issue a verdict without identifying which specific policy applies — vague "this violates ethics" statements are not actionable.
  • Don't conflate low-severity style issues with genuine compliance failures; this dilutes trust in the governance signal.
  • Don't approve with conditions and then omit what the conditions actually are.
  • Don't ignore second-order risks (e.g., precedent-setting, aggregation of low-risk actions into a systemic risk).
0
Grade B+AI Skill Framework
Scorecard
Criteria Breakdown
Quick Start
13/15
Workflow
13/15
Examples
15/20
Completeness
15/20
Format
15/15
Conciseness
13/15