Asset Management Council · Asset Zero

The Human–AI Boundary Framework for Asset Management

Version 1.0 — frozen 31 August 2026

Built from 2,796 recorded responses across four webinars (June–July 2026), validated by volunteers across three review cycles.

How to cite

Asset Management Council (2026). The Human–AI Boundary Framework for Asset Management, v1.0. Community-developed guidance, frozen 31 August 2026. Available at projects.amcouncil.com.au/human-ai-boundary.

Cite a section by its identifier (e.g. “§B3”) — identifiers are stable across versions; page numbers are not.

Download the framework (PDF) →

Co-developers — the Working Group

Named in the framework (§D4), on the project's credit page and in the snapshot's front matter

Birendra Grewal · Fernan Abuid · Hema Wadhwa · Ivan Beirne · Kai Dong · Lalinda Karunaratne · Martin Boettcher · Oludolapo Olanrewaju · Rick Minato · Russell Bunn · Sardar Khan · Steven McCann · Susan Rebano-Edwards · Tim Davies · Titus Naidoo

Reviewers

The reviewer stream was parked after cycle 1; v1.0 lists no reviewer tier (framework A1, D4) — reviewer credit resumes with the stream in v1.x

Birendra Grewal · Fernan Abuid · Kai Dong · Martin Boettcher · Sardar Khan · Tim Davies · Titus Naidoo

Community contributor: Collective acknowledgment (responses were anonymous and stay that way)

Live roster and how to join: /credit

The 18 sections, as closed

§A1 About this framework

Frozen v1.0

What it is. Community-developed guidance on where the boundary between human judgement and AI sits in asset-management decisions — and how an organisation makes that boundary explicit, decision by decision. To our knowledge it is the first Human–AI Boundary Framework written for asset management. It is guidance, not a standard: it is published by the Asset Management Council, and it operationalises for the sector the general AI-governance layers it sits beneath (see A4). It does not replace them and does not compete with them.

Status and version. This is v1.0, frozen and tagged on Mon 31 Aug 2026 and published as a citable snapshot. The living framework continues on the project site — projects.amcouncil.com.au/human-ai-boundary — after that date under AMC stewardship, section by section, on a review cadence AMC states and keeps current on the project site: each section carries its status (Draft (AI) → In review → Closed (consensus) / Closed with dissent recorded → Frozen v1.0), and v1.x changes are made the same way v1.0 was — proposed in writing, answered in writing, closed on rough consensus.

How to cite. Asset Management Council (2026). The Human–AI Boundary Framework for Asset Management, v1.0. Community-developed guidance, frozen 31 August 2026. Available at projects.amcouncil.com.au/human-ai-boundary. Cite a section by its identifier (e.g. "§B3") — identifiers are stable across versions; page numbers are not.

Who it is for. Asset-management practitioners and the people who approve, procure and govern AI in their organisations: asset managers, planners, maintenance and operations leads, data and digital leads, risk and assurance functions, executives who sign. It applies to AI you buy as fully as to AI you build — most members will meet AI inside procured EAM/APM/CMMS products, and the framework treats a vendor default as a decision someone made (B2 preamble; C4).

What is in scope, and what is not. The framework says that a person must decide, which decisions must stay with people, where the line between recommending and acting sits, and what record must exist to show the line was respected. It does not prescribe how an organisation reaches its decisions: governance structures, approval hierarchies, who reports to whom, and the organisation's own decision methods are its own. The working group split on this in cycle 1 and the position is recorded here deliberately: an AI contribution is a component inside the organisation's existing decision framework, and naming the boundary around that component is this document's job. Where the framework borrows vocabulary it borrows from current practice (ISO 55000 / 55001, ISO 19650) rather than inventing a vernacular; it does not arbitrate accountable-versus-responsible and it does not prescribe internal structure. Over-prescription is, in the working group's experience, what limited the uptake of earlier digital-engineering guidance.

Proportionality. The obligations in this framework scale with consequence and reversibility. An organisation meets a principle when its controls are proportionate to what a wrong answer would cost, not when it has applied the heaviest available control everywhere. Every principle in B2 therefore carries a minimum viable version — the smallest thing an organisation can do today and still be inside the principle — and B1 states what applies at each level of the ladder.

Two design rules applied to every control. Falsifiability: every control this framework requires must be able to fail visibly — for each principle, ask if this were being ignored, what in the record would look different? If the answer is "nothing", the control needs an artefact that records absence. The cheap-path rule: wherever the diligent path costs more than the compliant path, the compliant path will be taken — so every control is designed so that diligence is the default or the cheapest route, or it produces the rubber stamp it was written to prevent. Falsifiability makes failure visible; the cheap-path rule makes failure less likely. (Falsifiability was written into the framework by the working group in cycle 1, from its own break-cases; the cheap-path rule is the project chair's candidate — AI-assisted provenance, recorded in B2 — grounded in those same break-cases.)

How it was made. Four public webinars (June–July 2026; 2,796 recorded responses) produced the evidence (A3). In August a volunteer working group ran three one-week review cycles over an AI-drafted text: two cycles of focused micro-asks and calls (the principles; then the instruments), then a whole-document last call that ratified all eighteen sections unanimously — nine members of record, 162 verdicts, zero objections. Every written input received a written answer in a published comment-disposition log before a section closed; sections closed on rough consensus — can anyone not live with this? — with an objection blocking only until it had been addressed in writing, and unresolved disagreement recorded and shipped with the text rather than smoothed over. A reviewer stream was planned to give the draft an adversarial read by people outside the working group; in practice it was parked after cycle 1 and its three responses came from working-group members. v1.0 therefore makes no claim of independent review — that is a v1.x task.

AI-use statement. The framework's text was drafted, fact-checked and revised by AI working from consented, aggregated community data and from the working group's written input. The AI drafted; the working group judged; a named human signs. The project governed its own AI use under the boundary it describes — its governed agent operated at Recommend/draft-only against a registered boundary profile with every action in a ledger (summarised in D4); AI-assisted drafting in the project chair's own tools ran outside that ledger, under his review, and its scope is stated in D4. Figures were verified against the source results files in fact-check passes; every core figure in this document carries its own n or names its source file.

Credit. The working group and reviewers who made this framework are credited in D4 and on the project's credit page, by name and by role, with their consent.

Provenance. Drafted by AI (Stream 1) from: [W5B] §7.9 · Cycle-Plan v2 · the 14 Aug and 21 Aug call records (scope position, proportionality G2, design rules from [C1-log] Part 4 and the project chair's candidate C3). Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment led to an errata fix (the review-cadence wording — D4). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§A2 Why a boundary framework

Frozen v1.0

Across four webinars and 2,796 recorded responses, one finding held on every decision domain — data, condition and risk, investment, operations:

AI reliably amplifies whatever you already have — including your compliance theatre. It can make incomplete data look complete, an uncertain prediction look like a decision, an incomplete objective look optimal, a risky action look routine — and unexamined approval look identical to examination. Which way it resolves is a governance choice, not a property of the technology. The human–AI boundary is the mechanism by which AI-enabled asset management succeeds or fails.

The community did not vote to keep AI out: across every abstract boundary vote, "no role" and "should not be used" took 0% [SES F1]. It voted to place AI — analyse and recommend widely; act only inside engineered, reversible, approval-gated envelopes; and never own purpose, values, risk acceptance or the stop. AI must make uncertainty visible, not hide it behind confidence.

And it measured the gap this framework exists to close. The same practitioners who demand approval gates and stop authority report that today only 23% of their organisations auto-create work orders from alerts (n=40), 36% have a named person who could pause machine-generated work within the hour (n=36), 22% have drilled that pause in the last year (n=37) — and their median guess for how many AI-generated plans get audited is 0% (n=35) [W4 §3 · W3 w3-p2-audit-guess · SES F7]. The framework's job is to make the boundary explicit, decision by decision, and walkable from where members actually are.

The test of purpose (the framework's preamble — formerly principle 1). The test of any AI use in asset management is whether an asset-management decision or process gets better — faster where speed matters, better-evidenced, more consistent, more transparent, more accountable — not whether a model produced an output. Every AI use is registered against a named decision it is intended to improve, a named accountable person for that decision, and an improvement stated in advance in terms that can be tested afterwards. A use case that cannot name all three does not proceed. No outcome may be adopted that is unsafe for customers or end users. Where an AI's capability for the task cannot be assessed — the tool's competence, not only the person's — the use is not approved. The test applies to AI you buy as fully as to AI you build: every setting a product ships with — weights, thresholds, labels, autonomy levels — is a decision someone made, and if nobody in the organisation has examined and signed it, the organisation has delegated its boundary to its vendor.

Who this is for is stated in A1. What the rest of the document does: Part B states the boundary (the ladder, the principles, the matrix, the test, the envelope); Part C says how to make it stick (records, failure modes, oversight and capability, vendors, getting started); Part D holds the living edges (open questions, recommendations, glossary, credits).

Provenance. Drafted by AI (Stream 1) from: [W5B] §1 · [SES] §0, F1, F7 · [W1] q8-patterns · [W3] w3-s1-r5-sign-default. Reviewed: WG cycle 1 (MA1 11 responses; [C1-log]: the one-finding extension and the falsifiability rule from four converging break-cases; P1 moved to the preamble under Structure B, with the working group's registration test and safety bound folded in verbatim in substance). Consensus: rough consensus declared by the project chair, 14 Aug 2026 · Dissent recorded: none on A2. Cycle-3 last call: 9 yes · 0 objections; one comment led to an errata fix (the is/ought figures now carry their n — D4). Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§A3 The evidence base

Frozen v1.0

The series. Four public webinars between 25 June and 30 July 2026 — Knowing the Asset (data), Condition, Performance and Risk, Planning, Prioritisation and Investment, and Work, Operations and Intervention — each built around one question about where AI belongs in that part of the asset lifecycle. 2,796 recorded responses in total (663 + 524 + 625 + 956 in the live bundles, plus 28 sector answers logged outside the W3 cue script). Say "almost 2,800 responses"; do not round to 3,000.

W1 · Knowing the AssetW2 · Condition / Performance / RiskW3 · Planning / InvestmentW4 · Work / Operations
Core questionCan AI help us know our assets, or amplify poor data?When AI predicts, what must humans validate before acting?Should AI help decide where the money goes — and who owns that call?When should AI move from recommending work to triggering work?
Ceiling (analyse + recommend)68% (n=78)67% (n=42)72% (n=18)cold 52% → warm 32% (n=39/35)
"Act with approval"15%19%17%cold 26% → warm 60%
"Act autonomously within limits"8%5%0%cold 13% → warm 9%
"No role" / "should not be used"— / 0%0% / 0%0% / 0%0% / 0%
Principle rating(s) / 53.86 (n=71)3.76 (n=46)3.73 (n=33) · 3.39 (n=36) · 4.07 (n=30)4.15 (n=33) · 4.06 (n=35) · 4.27 (n=33)

The eight findings the framework rests on [SES F1–F8]: (1) the ladder holds at Recommend until a room watches bounded action work — then it moves to approval-gated action, not autonomy (+0.44 rungs, paired, n=25); (2) the community priced approval above interruption for three sessions, then re-priced the stop the moment it saw a work-order storm (48% → 64% paired, with zero drops); (3) reversibility is worth 38 percentage points on the same work order, and "never" appears only when the case is concrete (19% on a live 66 kV isolation; 0% in every abstract vote); (4) the community trusts records over promises — in each of the two rooms that rated principles side by side, the ledger-shaped principle rated highest (the deferral ledger, 4.07 of W3's three; the action ledger, 4.27 of W4's three); (5) it set its first number — a median of 7.5 machine-created work orders per planner per week before auto-pause, with 30% saying never; (6) money is where values hide — 85% would not have signed vendor-default weights, 64% rejected an optimiser's silent trade, 39% could show the weights behind their capital plan; (7) the is/ought gap — rooms demand gates their organisations do not run; (8) the human core is stable across the lifecycle and sharpens under pressure.

The lifecycle map. The four webinars trace the asset lifecycle, and the boundary moves with it: at the knowing end the risk is amplified data; at condition and risk it is a prediction mistaken for a decision; at planning it is an optimised answer to an unexamined objective; at operations it is bounded action becoming a system-scale event. The retained human rights are the same at every stage (B1); what changes is which one is under most pressure.

Reading rules (they bind every downstream use of these figures): every figure carries its own n, and rooms shrink across an hour — compare within a block, not across blocks; where a paired figure exists it is the honest one and the one to quote; multi-select percentages sum past 100%; cross-webinar comparisons are cross-room (different people, different sector mixes) unless an instrument was deliberately re-run verbatim.

Caveats. Instruments evolved across the series (W1 ran on a different platform with different option labels); small late blocks are directional only (W3's boundary vote, n=18); two W3 blocks are unusable and withheld; W2's volunteer questionnaire fell below the privacy gate (MIN_N = 10) and is not reported; sector mix differed by room (W3 transport/consulting-heavy; W1 government-heavy; W4 unmeasured) and no claim here is sector-specific. All figures are consented responses; W3/W4 tokens are irreversibly anonymised; no individual is identifiable in any derived work.

The working-group evidence. Cycle 1 (10–14 Aug): 11 responses judged all seven principles (nine of the eleven confirmed working-group members — 82% — plus one rostered reviewer who declared both roles and one contributor who joined from outside the roster), 10 respondents wrote 11 break-cases, 10 answered the missing-principle question; 3 reviewer responses. Cycle 2 (17–20 Aug): 11 of 11 completed all three instruments — every one of the 132 matrix calls reasoned. Cycle 3 (24–27 Aug): nine members — the cycle-2 eleven minus two, both absent that week — completed the whole-document last call (162 verdicts, all yes, zero objections), the eighth-principle coverage question and the recommendations priority vote; zero late entries, zero superseded revisions. The cycle exports and disposition logs are archived with the framework (D4).

Provenance. Drafted by AI (Stream 1) from: [SES] §0–1, §11 · the four results files · the cycle exports. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment led to two errata fixes (the rating row's missing n's; the "rated highest in every room" overclaim — D4). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§A4 Where this sits

Frozen v1.0

This framework is the asset-management layer beneath general AI-governance instruments. It cross-walks to them; it does not duplicate them.

Asset-management standards. ISO 55000 / 55001 supply the vocabulary of asset-management objectives, decision-making criteria and the SAMP; ISO 55013 (data asset management) is the natural home for the verified / inferred / unknown discipline of P2 and C1. The framework's envelope parameters (B5) and matrix (B3) are written to live inside an organisation's existing work-management procedures and decision-making criteria, not beside them.

General AI governance. Australia's Voluntary AI Safety Standard (the ten guardrails, "AI6") and the NIST AI Risk Management Framework provide the organisation-level governance scaffold; ISO/IEC 42001 the management-system shape for the AI-use register and decision records in C1. The PMI standard for AI in project work (June 2026 — the world's first global standard of its kind) is cited as the general project-practice layer this framework operationalises for the sector.

Automation tiers and oversight tests, borrowed deliberately. The ladder's levels (B1) follow the EASA pattern — assistance → teaming under oversight → autonomy, with overseen / overridable / non-overridable as the operational distinction. "Effective challenge" (US Federal Reserve SR 11-7, model risk management) is the test the framework applies to oversight in B2 and C3: challenge by people with the capability, authority and time to say no. "Evaluate the human–AI team, not the model" is borrowed from the Good Machine Learning Practice principles. The named business owner accountable for outcomes, with authority to halt (the One NZ pattern, via MIT CISR) is the framework's accountable person.

Australian legal anchors (as at August 2026, for orientation — not legal advice): the SOCI Act critical-infrastructure obligations; the Financial Accountability Regime (named-manager liability) as the model for named accountability; the Privacy Act automated-decision transparency obligations (in force from December 2026); the NSW WHS Amendment (Digital Work Systems) Act 2026 (enacted, awaiting proclamation at the time of writing), which bears directly on machine-directed work (B3 rows 9–10); and, for members with EU exposure, the EU AI Act (Annex III high-risk obligations now deferred to 2 December 2027; Article 14 human-oversight requirements unchanged). The records spec in C1 is written so that one record can serve the SOCI / FAR / Privacy Act expectations together; a compliance-background legal review of that mapping is a v1.x item (D1, OQ-08).

What this framework adds that none of the above does. A sector-specific decision-rights matrix populated from practitioners' own votes; a boundary test keyed to asset criticality and reversibility; an envelope anatomy with the community's first numeric parameter; and an evidence base from almost 2,800 responses about where the line should sit in asset-management decisions specifically.

Provenance. Drafted by AI (Stream 1) from: [W5B] §7.1–7.8 · research dossiers 51–52 · verified legal-anchor corrections in project memory. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections (one member's comment on this section was lost to a paste error; the disposition log records the invitation to restate it for the v1.x register). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§B1 The ladder & the human roles

Frozen v1.0

The ladder. Six levels of AI role, used throughout this framework and in every instrument the community voted on. Print the one-line definition wherever a level is chosen — the working group found bare numbers illegible.

LevelNameOne-line definitionWhat applies at this level
0NoneNo AI in this decision.Nothing in this framework is required; the register simply says so.
1AssistantAI helps a person do the work — drafting, retrieving, summarising, formatting — and the person produces the output.Test of purpose; P1 provenance on anything the AI touched; P7 capability.
2AnalystAI analyses and presents — patterns, scores, classifications, comparisons — and a person interprets and decides.+ uncertainty made visible (P1); validation proportionate to consequence (P2).
3RecommenderAI proposes a specific course of action; a person accepts, amends or rejects it before anything happens.+ the accountable person named for the decision (P6); the recommendation recorded with its basis (P5); a signed objective where the recommendation optimises (P3); an outcome check scheduled where the decision is consequential (the outcome record, C1).
4Controlled actorAI acts — but only inside a pre-approved, bounded, reversible envelope with an engineered and practised stop (B5). Outside the envelope it drops to Recommend.+ a live envelope with all its parts; the trigger gate; the drilled stop; the volume budget; monitoring and re-signing on schedule; the record of what was done and what was declined; the outcome record closing the loop (C1).
5AutonomousAI acts without per-action human approval and without a bounded envelope.Not used for any decision class in this framework's matrix. An organisation that chooses it for a work class writes down why, and the never-list still applies.

A poll-wording note: the series' instruments offered "act autonomously within limits" as their top rung. The ladder splits that idea in two — level 4, autonomous within a signed envelope, and level 5, without one — so read A3's autonomy figures against the poll wording, not against level 5's stricter definition.

The line that matters most sits between 3 and 4. The moment an AI output is written into an authoritative register, a schedule or a purchase order it is no longer a recommendation — it is an act, and the human decision point must sit before the write (cycle-2 call, B4 q3). Level 4 is earned by the envelope, not assumed; level 5 is a deliberate, recorded choice, not a default.

The human roles — the retained-rights set. Whatever the level, these stay with people. They are the rights the community held onto in every room and sharpened under pressure [SES F8]:

  • Define the purpose — what decision this AI use is for (the test of purpose).
  • Own the value judgement — set and sign the objectives, trade-offs and limits (P3).
  • Approve — accept, amend or reject a recommendation; gate an action (P4).
  • Validate — check calibration, data quality, drift and capability before relying on an output (P2).
  • Accept and record the residual risk — by name (P2).
  • Stop and override — halt the machine, no reason required; restart deliberately, with a recorded reason (B5).
  • Interpret context — the outlier, the first occurrence, the case the model has never seen.
  • Govern the knowledge — authority over the system of record and the provenance label (P1).
  • Be accountable by name — one person, with the power to halt (P6).

Which rights rooms under-price cold. Left to an abstract vote, practitioners rank approval and stop authority high and accept and record residual risk low (47% → 33% → 22% across W1→W3); after watching consequences, the same people re-price it upward (+12pp paired) and approval and stop rights rise further (+12pp, +16pp paired) while abstract stewardship falls [SES F2, F8]. The framework therefore treats risk acceptance and the stop as non-negotiable retained rights even where a first vote would not.

Role vocabulary. The framework uses two role terms and borrows the rest from current practice. The accountable person is defined in B2 (P6) and the glossary. A competent reviewer is whoever validates an output and must be able to tell when it is wrong (P2, P7); in high-consequence use the reviewer is not the accountable person (no person challenges their own work). Where an organisation already names parties under ISO 19650 or its own delegations, it maps those to these two terms rather than inventing new ones — a working-group policy, not a drafting preference.

Minimum viable version. Put the ladder's six one-line definitions in front of the people who approve AI use and ask them to place each AI product already in service on it. Disagreement about the placement is the first finding.

Provenance. Drafted by AI (Stream 1) from: [W5B] §4 note · [SES] F1, F2, F8 · [W1] q6-humans-retain · [W4] §1e. Reviewed: WG cycle 1 (the ladder rung line rode MA1; the "map to current practice" rule adopted as policy, [C1-log] Part 5) and cycle 2 (the legend fix — one-line definitions beside every level — from the B3 legibility finding; the 3/4 line from the B4 q3 discussion). Consensus: rough consensus declared by the project chair, 14 Aug 2026 · Dissent recorded: none. Cycle-3 last call: 9 yes · 0 objections; one comment led to an errata fix (the poll-wording note above — D4); one wording comment is carried to the v1.x register. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§B2 The seven principles

Frozen v1.0

Structure B, adopted by the working group in cycle 1 (vote 6 · 4 · 1; dissent recorded below): records and accountability are separate principles, the former principle 1 became the test of purpose in A2, and cycle 1 closed the set at seven — and v1.0 ships seven. A candidate eighth principle stood in the release candidate; the cycle-3 coverage question put it to the working group, and the project chair withdrew it at the freeze. The vote, the candidate's full text and the withdrawal are recorded in The eighth-principle question at the end of this section. Each principle carries its statement, what the community's data says, a practice note, its minimum viable version, and its status. A cross-walk from these seven back to the webinars and the earlier numbering is in D4.

P1 — AI amplifies data; it does not fix it or guarantee its quality (cycle-1 P2)

AI makes the data you already hold more influential and more confident-looking. It does not make it more true.

Data quality, provenance and the Verified / Inferred / Unknown distinction are governance preconditions for trusting any AI output. Before any AI use, name the system of record for each source the AI reads; where two authoritative sources disagree, record which one governs. A value labelled Inferred carries the evidence and reasoning used to infer it — a citation a human cannot check is not provenance. Every AI output carries the data-quality status and key uncertainties of its sources; higher-consequence decisions require explicit verification before the output is used. AI must make uncertainty visible, not hide it behind confidence. No AI-authored value enters an authoritative register without its label and a person's sign-off.

What the community's data says. Rated 3.86/5 (n=71; 70% rated 4–5) [W1 q9]. 75% have seen bad data become a confident output; 45% the authority illusion; 28% silent fabrication; 25% data laundering [W1 q8-patterns]. The whole series' top-upvoted worry: "generating bad data and results" [W1 q2]. In cycle 1 this principle drew five break-cases and all three reviewer responses — the most load-bearing principle in the set; its problem was sufficiency, not wording. The strongest case against "AI will clean it for us" as a management belief came from the working group itself.

In practice. Proportionate sign-off: class or batch sign-off with sample checks for routine fields; per-value sign-off for critical fields. Labels attach to owners, not processes (C1). Non-authoritative fields may be cleansed at level 4 within an envelope; authoritative records cap at level 3 (B3 rows 1–2).

Minimum viable version. Default every unlabelled legacy value to Unknown, then label on touch.

Status: Closed (consensus), cycle 1.

P2 — An AI prediction is not a risk decision (cycle-1 P3)

AI can estimate condition, failure probability or risk. Before a prediction triggers action, a competent reviewer validates calibration, data quality and drift (is the asset still in-distribution?), and the accountable person accepts and records the residual risk. AI may set out the residual-risk options; only a person accepts one. A prediction lacking a recorded validation and a recorded risk acceptance is deferred, not actioned. Accountability never transfers to the model.

What the community's data says. Rated 3.76/5 (n=46) [W2 principle-test]; on acting on a prediction the room capped AI at analyse-or-recommend (67%, n=42) with autonomy at 5%. Asked who owns the risk when AI flags, answers converged on a named human — the asset owner, the asset manager, "whoever normally owns the risk, regardless of AI involvement." In cycle 1 this was the most reasoned support in the set, with zero break-cases. One working-group note is the best one-line case for calibration validation: the AI may not have any examples for large-consequence failures.

In practice. Proportionate validation — depth scales with consequence; a small organisation follows a defined minimum validation path rather than a full calibration-and-drift programme. Prediction-triggered work carries a risk-acceptance record: who accepted, on what evidence, with what reconsideration date.

Minimum viable version. For one prediction-driven workflow, add two fields to the work order: validated by and residual risk accepted by. Blank means deferred.

Status: Closed (consensus), cycle 1.

P3 — Humans decide what "better" means (cycle-1 P4)

AI can search for the best answer. It cannot decide what "best" should mean.

The decision owner — the accountable person for this decision — sets and re-signs what the organisation is optimising for: the asset-management objectives being served, the trade-offs between them, the limits any answer must respect, and the method used to find it. No AI output may set or silently change any of these. The objectives and weights are re-signed whenever they change and at least on the interval the organisation sets for the envelope or plan they govern (B5); an unsigned or expired set is a draft. Where an optimiser proposes deferring work, each deferral is recorded as a named, dated risk acceptance (C1, the deferral ledger).

The principle applies to every kind of optimisation — capital programmes, maintenance schedules, inventory, dispatch — and to the weights that arrive inside a product: a default nobody signed is still a value choice, made by the vendor.

What the community's data says. The signed objective rated 3.73 (n=33); the deferral ledger 4.07 (n=30 — W3's best); the frontier right 3.39 (n=36 — the series' weakest, and now a practice note). Behaviour was sharper than the ratings: 85% would not have signed the vendor-default weights nobody in the room chose; 64% rejected the optimiser's silent trade; in only 39% of organisations could a named person show the value weights behind the capital plan today (n=36) [W3]. What the room valued when it held the pen: cost 26 · risk 25 · service 24 · equity 15 · carbon 10 (medians, n=45).

In practice. The value model is an owned, signed, re-signed artefact — like accounts. Showing the frontier: where the tooling allows, the people affected by a plan see the near-optimal alternatives and what each trades away, and choose among them; where it does not, the owner at least records which alternatives were considered. The cross-department check — who owns finding out what the optimiser quietly defunded — is a named role in the matrix's accountability column (B3 row 6).

Minimum viable version. If nobody has signed the objectives and weights, the output is a draft and does not proceed to approval.

Status: Closed (consensus), cycle 3 — the wording was rewritten twice in cycle 1; the re-presented text passed the last call 9–0 with no objection.

P4 — AI may advise widely; it may act only narrowly (cycle-1 P5)

Automation depends on consequence, reversibility and oversight.

Human approval is the default for any action an AI initiates. Where an AI is allowed to act, the action is limited in scope and volume, reversible within a stated window, under oversight with enough time to intervene, and clearly owned — with a stop that has been engineered and practised, not assumed. High-consequence or irreversible actions stay under human control, and every organisation names, in its own matrix, the actions that must always be made by people — safety-critical and statutory work orders among them.

The envelope's anatomy — eleven parts, from scope and magnitude to the warn band and edge behaviour — lives in B5, not here.

What the community's data says. W4's paired experiment: after watching a bounded agent act for forty minutes the room moved +0.44 rungs (paired, n=25) — to act with approval (26% → 60%), not autonomy (13% → 9%). The reversibility premium: 38 points — the same work order drew 59% "allow auto" when cancellable for two hours and 21% when cost committed on creation. The room's first volume budget: median 7.5 machine-created work orders per planner per week before auto-pause, 30% never. Trigger gate rated 4.15 (n=33), engineered stop 4.06 (n=35). Stop authority was the only retained right nobody dropped after the storm (48% → 64% paired). "Never" appeared only when the case was concrete — 19% on a live 66 kV isolation, 0% in every abstract vote [W4 · SES F1–F3, F5].

In practice. Every acting AI has an envelope document and a named owner; the stop is a tested control, drilled like an emergency procedure, not a menu item. Monitoring that arrives after the action is not oversight.

Minimum viable version. Name one class of action AI may take, one volume limit, one accountable person, one tested stop.

Status: Closed (consensus), cycle 1.

P5 — No AI action stands without a record (cycle-1 P6, first half)

AI may act or defer; nothing counts until it is logged. A person must be able to reconstruct what was done, what was declined, and who owned the call, from a durable record the organisation controls.

A record must be able to show what was not done. An approval states what was examined and what was accepted unexamined, measured against a review capacity declared in advance. Anything beyond that declared capacity is deferred, not approved — an approval signature that looks identical whether the person examined three items or forty is the failure this principle exists to prevent.

Every AI use carries a live register entry with six core fields: named owner, approval status, operating envelope, validation record, review frequency, retirement trigger (the full schema, which extends these six, is in C1).

What the community's data says. The ledgers won their rooms: the action ledger is the series' highest-rated principle (4.27, n=33; 82% rated 4–5) and the deferral ledger W3's highest (4.07, n=30; 83%); 0% believed a re-signing schedule would be the safeguard their organisation quietly skipped; the community consistently endorsed recording mechanisms above access rights and process promises [SES F4 · W4 §9]. The principle's opening and its second paragraph were written by working-group members in cycle 1 — the strongest single argument for Structure B came from the volunteers, not the drafters.

In practice. Records are the artefact that makes oversight verifiable (P6) and the loop closable (C1, C3): predicted-versus-realised is the one record a rubber stamp cannot produce.

Minimum viable version. For one AI use already in service, write its register entry with all six core fields. A field you cannot fill is a finding.

Status: Closed (consensus), cycle 1.

P6 — Accountability is named, non-delegable, and carries the power to halt (cycle-1 P6, second half)

"A human reviews it" is a claim, not a control. Oversight counts only when it is verifiable: interrogable outputs, visible limitations, and effective challenge by people with the capability, the authority and the time to say no.

Every AI use has one accountable person with the authority to halt it. Competence is a condition of that role, not an assumption — the accountable person must be able to detect that the output is wrong, and the required competences are scheduled in C3. No person challenges their own work: independent challenge applies to high-consequence AI use; for other uses the accountable person verifies, and accountability remains theirs either way. "The model said so" is no defence.

The accountable person, defined. The named individual who holds the authority to approve, challenge and halt a given AI use and who answers for the decision it changes. Concretely, in an organisation's own terms:

  • Who: one person per AI use (or per matrix row), named in the register — a role-holder, not a committee, and not the vendor. Where the organisation uses ISO 55001 delegations or ISO 19650 party roles, the accountable person is whoever already holds the delegation for that decision class; the framework does not create a new office.
  • Authority: can stop the AI use, no reason required; can reject or amend any output; can change its level in the matrix; signs the objectives and weights where it optimises (P3) and the envelope where it acts (B5).
  • Competence: is able to tell when the output is wrong, or has access — resourced and recorded — to someone who can. The accountable person is not necessarily the competent reviewer (P2) and in high-consequence use must not be (independent challenge); but they are responsible for ensuring the competence exists before relying on the output (P7). Whether they are also the competent person is determined by the competence schedule in C3, recorded in the register.
  • Cannot delegate: the authority can be exercised through others; the accountability cannot be handed to a model, a vendor, a committee or a subordinate.

What the community's data says. Confidence in declared oversight is low: median guess for the share of AI-generated plans audited today — 0% (n=35) [W3]. 14% have already seen rubber-stamp oversight; 45% the authority illusion [W1 q8]. Asked which safeguard their organisation would quietly skip first, the close-out feedback loop (30%) and the practised stop drill (22%) topped the named list [W4 §9]. Under pressure the room's approval and stop rights rose (paired +12pp, +16pp) while abstract stewardship fell [W4 §1e · SES F2, F8]. In cycle 1, eight comment instances from six working-group members asked for one concrete term — this is it.

In practice. For high-consequence decisions: challenge is resourced and recorded; oversight quality is audited (spot-checks of approvals), not assumed; every AI use case has one named accountable person who can halt it and whose name is in the matrix.

Minimum viable version. Write one name against each AI product already in service. "Nobody" is a finding.

Status: Closed (consensus), cycle 1 — the definition above answers the 14 Aug call's decision D2 ([C1-log]) that it be concrete and inside the framework.

P7 — AI must not erode the expertise the framework depends on (cycle-1 P7)

Every principle above assumes a person who can still tell when the AI is wrong.

AI use must therefore preserve that capability: the reasoning that supports an answer travels with the answer — both are required; competence in the underlying judgement checked and recorded for the people who approve AI outputs; and over-reliance actively watched for. Where the capability no longer exists, the AI use is not approved — it is deferred, with the capability gap escalated to someone who can make the business decision: fill the gap, or consciously accept indefinite deferral. That person is not necessarily whoever previously owned the AI activity. The framework sets no duration for the escalation — it depends on each organisation's policy, budget and risk appetite — but it requires that the deferral has an owner and a decision, so that a register of deferred uses does not grow because nobody decides.

What the community's data says. This remains the least-quantified principle — no boundary vote tested it; the signal is in open text ("loss of abilities and skills to solve problems", "cognitive offloading", "loss of ability to evaluate AI responses") [W1 q2, q10]. The working group kept it as a principle in cycle 1 because it is the precondition for P2, P4 and P6, made its language mandatory ("should augment" → "must not erode"), replaced rotation through manual practice with a competence check (many teams have one expert), and supplied an evidence design: survey the community on observed skill loss now, and in a later cycle ask who runs competence checks and whether scores held (D1, OQ-05). The case for keeping it came from the framework's own adversarial test: the reviewer scenario's third failure happened because the one engineer who remembered why the main mattered had retired.

In practice. Capability impact is assessed at screening (B4 q6); augmentation patterns (AI drafts, human decides; AI explains, human verifies) are preferred over replacement patterns for judgement-bearing tasks; the competence schedule and tacit-knowledge practice are in C3.

Minimum viable version. For one AI use, name the person who could tell if its output were wrong. If the answer is "nobody any more", defer the use and escalate.

Status: Closed (consensus), cycle 1; this text carries the three wording changes the 14 Aug call requested, and one freeze-pass grammatical repair logged in D4.

The eighth-principle question

Cycle 1 closed the principle set at seven. Two candidates for an eighth stood at the final pass, and the cycle-3 coverage question (CQ) put both to the working group directly — a named vote beside the last call, because both candidates had reached the release candidate without a group decision behind them.

The two candidates.

  • Close the loop — AI is judged by realised outcomes, not outputs — the project chair's candidate (drafted 16 Aug from the cycle-1 and cycle-2 evidence; added to the release candidate as P8 on 23 Aug, flagged as not yet having been before the group). Its full text as it stood in the release candidate is preserved below.
  • Affected parties — a principle for the people, groups and communities on whom an AI-influenced decision lands, especially when the output is wrong. Proposed by a working-group member in cycle 1 and raised twice without resolution on a call; the release candidate carried it not as a principle but as a required register entry (who is affected, how they are told — C1) and a challenge path (C3).

The vote (nine of record, 24–27 Aug 2026; every vote carried a written reason):

OptionVotes
(a) Keep P8 — eight principles; affected parties stay with the register entry and challenge path, revisited after v1.05
(b) Keep P8 and add affected parties — nine principles1
(c) Drop P8 — back to the seven agreed in cycle 1; the duty to check outcomes stays as a records requirement with a named owner and a date2
(d) Drop P8, but add affected parties — eight principles, the other one1

Keep the eighth principle: 6 – 3. Affected parties as a principle of its own: 2 – 7. The full record — every vote with its reason, by name — is in the cycle-3 disposition log (D4).

The project chair's decision — recorded here so it cannot be mistaken for the group's. The vote favoured keeping the eighth principle, and option (a) alone was an outright majority. The project chair nonetheless withdrew his own candidate at the freeze, and v1.0 ships seven principles. The dissent persuaded him: the strongest reasoned argument on the record holds that verifying outcomes and learning from experience — important as it is — is a mandatory governance and assurance requirement that demonstrates compliance with P1, not an additional principle; a second dissent was not convinced an eighth principle is needed, holding that the wider circle of interested parties is already party to P1–P7; a third would drop it and strengthen P4's target-setting instead. Against that stood a candidate the project chair had added himself on 23 Aug, never proposed in any working-group response, on its first and only review. A project chair's addition carried over three members' recorded dissent would stand differently in this set than the seven principles the group proposed, contested and closed together — and deference to the dissent costs the framework nothing it cannot afford, because nothing of the duty is lost: the close-the-loop requirement — the outcome record, its owner, its date, its two feedback directions — is mandatory in C1 and C3 exactly as the drop option described, and it binds at ladder levels 3 and 4 (B1).

The keep reasons, answered. The six keep votes were reasoned, and the strongest deserves its answer here, not only in a log. One keep reason warned that leaving the duty in the records section "buries the most-skipped control in the place things get skipped from". The withdrawal does not do that: the outcome record is not prose in a records section — it is a mandatory register field with a named owner and a date, and it fails closed: a use whose outcome field stays empty is deferred at its next re-sign, not renewed (C1). What was withdrawn is the label, not the gate. A second keep reason held that asset management is ultimately judged by the outcomes delivered over the asset lifecycle — that case travels with OQ-19 back to the working group, which decides the principle question in v1.x on a group vote. Every coverage-question reason, keep and drop, is preserved by name in the cycle-3 record (D4).

What reopens it. Whether close-the-loop deserves principle status returns to the working group in a v1.x cycle with this record attached (D1, OQ-19) — where, if adopted, it will carry a group vote as its provenance rather than a project chair's addition. The affected-parties question stays open the same way (OQ-20), with the majority option's own wording — revisited after v1.0 — as the standing commitment.

The candidate text, as it stood in the release candidate (preserved for the v1.x decision; not a principle of v1.0):

Close the loop: AI is judged by realised outcomes, not outputs. Every principle above governs the moment before or during an AI-influenced decision. This one governs afterwards. Every AI use is judged by realised outcomes, not outputs. On the schedule in the register, the accountable person compares what the AI claimed with what happened — the deferred mains that failed, the predicted failures that did not, the work orders that were cancelled. Misses feed back in both directions: into the governance side — the envelope, the approval status, the validation record — and into the AI itself: the same outcome record that audits the model is the evidence that recalibrates, retunes and retrains it. Governance and improvement are one loop, not two systems. An AI use that generates no outcome evidence has no evidence that it works — and a use whose outcome field stays empty is deferred at its next re-sign, not renewed.

What the community's data says. The community's median guess for the share of AI-generated plans audited today is 0% (n=35) [W3 w3-p2-audit-guess] — the one control it could not estimate above zero. Asked which safeguard their organisation would quietly skip first, the close-out feedback loop topped the named list at 30% [W4 §9]. In cycle 2 the boundary test's q9 — will anyone find out whether the deferred mains failed? — drew a near-unanimous no (1 yes · 10 no); one member's reason names the failure mode: a wrong deferral surfaces as a main failing in the ground, not as a detected error. A cycle-1 note supplies the other half: the AI may hold no examples of large-consequence failures — the calibration P2 demands in year two is only possible if someone kept score in year one. No other principle looks back: P2 validates before action, P5 records what was decided, P6 oversees at the moment of approval. The candidate passes the framework's two design rules natively — predicted-beside-realised is the one artefact a rubber stamp cannot produce, and because the outcome record is also what improves the model, keeping it is productive work rather than compliance overhead.

Minimum viable version. For one AI use, record prediction beside outcome for its next ten decisions; review once, and act on what you find — on the envelope, or on the model.

The other candidates, for the record. Six of ten working-group members proposed an eighth principle in cycle 1; every proposal was adopted somewhere — two became P5 verbatim in substance, one became P1's spine, one the test of purpose's capability condition, one the C3 competence schedule, and the affected-parties proposal became the C1/C3 practice requirement above. The project chair contributed two further candidates with AI-assisted provenance: a default is a decision is carried as a clause in the test of purpose (A2) and in C4, and the cheap-path rule as a design rule in A1 — deliberately not principles.

Provenance. Drafted by AI (Stream 1) from: [W5B] §3 · [SES] F2, F4, F6–F8 · [W1]–[W4] as cited. Reviewed: WG cycle 1 (MA1: 11 responses, no principle majority-rejected; MA2: 11 break-cases; MA3: 10; reviewer packet 1: 3) with every comment answered in [C1-log]; structure vote B 6 · A 4 · 1 abstention; the 14 Aug call's decisions D1–D6 and the HANDOFF §2 rewrites applied here. Cycle-3 last call: 9 yes · 0 objections; the coverage question voted 6–3 to keep the candidate eighth principle and 2–7 against an affected-parties principle; the project chair withdrew his candidate at the freeze — the decision and its reasons are recorded in this section, and the minority and majority reasons are in [C3-log]. Consensus: rough consensus declared by the project chair, 14 Aug 2026 (the seven principles) · Dissent recorded: four members voted for Structure A; the instrument gave them no reason field, the log says so and attributes no rationale to them; the D4 cross-walk answers the traceability case at no cost. One member's structure and ladder responses are recorded as abstentions after a readability failure the draft owned — the plain-language pass and the ladder's printed one-line definitions are its fix. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§B3 The Decision Rights Matrix

Frozen v1.0

What it is. One table an organisation fills in for itself: for each class of asset-management decision, the maximum AI role level on the ladder (B1), what humans must retain regardless of level, and the accountable person by name. Levels 4 and 5 always mean within a pre-approved, bounded, reversible envelope with an engineered stop (B5) — never autonomous on safety-critical or irreversible decisions. The rows are written as concrete work classes, because across every abstract boundary vote in the series "should not be used" took 0%, while a live 66 kV isolation put in front of the same community drew 19% "never" [SES F3].

The ladder, for reading the table: 0 None · 1 Assistant · 2 Analyst · 3 Recommender · 4 Controlled actor (within limits) · 5 Autonomous — one-line definitions in B1.

The community's matrix. Twelve typical decision areas across the asset lifecycle, each at the level the series' votes support and the working group confirmed in cycle 2 (eleven reviewers, 132 reasoned calls; no row's median moved off its drafted level). The evidence column is the warrant; the dissent column is honest about where the group split.

#Asset decisionMax AI levelHumans must retainWhy this levelCycle-2 result
1Asset-data extraction and cleansing — non-authoritative fields4Data authority; the verified / inferred / unknown label on every field the AI touched; the accountable person for the registerW1: 68% capped AI at analyse-or-recommend on facts about the asset (n=78), but that vote covered authoritative facts; for non-authoritative fields the act is reversible and labelledUnanimous (11 agree)
2Changes to authoritative asset records3Sign-off on critical fields; provenance; who owns the recordW1 q5: 68% cap; governs the knowledge a top retained right (66%). An authoritative record is the thing everything else trusts — the AI may propose the change, a person commits it9 agree · 2 propose L2
3Condition classification from imagery and sensors3Validation of unusual and high-risk cases; the calibration recordW2 (n=47): 38% Analyse, 38% Recommend, 11% act with sign-off, 0% autonomous. Classification is reversible and reviewable in bulk; the human keeps the outlier check10 agree · 1 propose L4 (accepted the result on the call)
4Asset-health and failure prediction3Calibration check; residual-risk acceptance stays human (P2)W2 (n=44): 57% Recommend, 7% act with sign-off, 2% autonomous. A prediction is not a risk decision, so 3 is the ceilingUnanimous
5Asset criticality and risk scoring2Risk appetite; consequence valuation; the weights behind the scoreW2 (n=46): 50% Analyse, 37% Recommend. The score encodes value judgements (P3)9 agree · 1 propose L1 (constructs too interpretation-laden) · 1 propose L3 (criticality is rule-based in practice at volume). Both recorded; L2 stands
6Renewal and capital prioritisation3The value framework and its weights, signed by the accountable person; the trade-off; the choice; who checks what the optimiser quietly defundedW3: 72% cap on money, 0% autonomy (n=18); 85% would not sign vendor-default weights (n=39); 64% rejected the optimiser's silent trade (n=42). The AI may rank; the human owns "better"9 agree · 2 propose L2 (judgement about strategy and stakeholder expectations). A split by value/consequence was proposed and is carried to row 7 and B5
7Committing spend within a pre-set cap — ordering parts, hiring plant3Rule-setting; the cap; exception approval; the reversibility windowW4 (n=34): 35% Recommend, 26% act with sign-off, 6% autonomous. Cost that commits on creation is the least reversible act in the series (38-point premium). Level 4 is defensible only with a hard cap and a cancellation window — an organisation that chooses it writes both into the envelope9 agree · 1 kept L3 with a split-by-reversibility note · 1 propose L4 for low-value repeatable purchases within approved thresholds
8Risk acceptance and service-level change2Accountability; stakeholder and executive judgement; the recorded acceptanceW2 (n=41): 44% Analyse, 29% Recommend, 7% act with sign-off. Accepting a risk is the decision the whole framework exists to keep human (P2, P6); the AI informs itClosed with dissent recorded: 7 agree · 3 propose L1 (risk acceptance is a leadership and governance responsibility; in public health the concept of risk is elevated — AI as assistant, no more) · 1 propose L3 (a recommendation is more useful than an analysis, provided the human stays responsible). Sector appetite differs; the spread is signal
9Routine, low-risk, reversible work orders — creation and triggering4The definition of "low-risk"; the volume cap (B5); the reversibility window; stop authority by nameW4 envelope votes: 42–53% allow auto-trigger across the reversible work classes (n=31–36); "never" took 0% on every class except spares, where it drew 3% because spend commits (row 11). The same inspection drew 59% allow when cancellable for two hours vs 21% when cost commits. The warm boundary vote moved the room to 60% "act with approval" (n=35). Level 4 is earned by the envelope, not assumed9 agree · 1 propose L3 · 1 propose L5
10Maintenance scheduling and crew dispatch — booking people against work4, conditionalOperational feasibility; override; the roster ownerW4 (n=34): 41% Recommend, 35% act with sign-off — the highest act-with-sign-off share of any decision-rights poll in the series. Scheduling of already-planned work is reversible and continuously overridden in practice8 agree · 3 propose L3 (a run of false reactive call-outs after hours would be catastrophic in a 1,500-site estate; directing people to work needs more oversight). Condition carried into the row: level 4 applies to scheduling work a person has already planned; dispatch that commits crews to hazardous or after-hours reactive work drops to 3. The group is most conservative wherever real people are sent to do real work
11Low-value spares replenishment4Criticality tiering; the value threshold; spend oversight; the cumulative spend capW4 spares reorder below $500 (n=36): 47% allow auto-trigger, 50% approval gate, 3% never — the only reversible class where a "never" appeared, because spend commits10 agree · 1 propose L5. ERP systems already do this; the cumulative cap (many small spares make a large cost) is in B5
12Safety-critical intervention and control actions1Final authority; risk ownership; an independent safety layer; the concrete "never" listW4 live 66 kV feeder isolation + permit to work (n=36): 11% allow, 69% approval gate, 19% never — the series' one concrete ban. Drafted at 1 so that any organisation choosing 2 does so deliberately and writes down why9 agree · 1 propose L0 (human authority absolute) · 1 propose L2 (assuming no AI involvement is unrealistic). L1 stands; the group's overall conservatism on safety-critical matters noted

The named-accountability column. Every row in an organisation's own matrix carries the accountable person by name — the person with the power to halt (B4 q7–q8; P6). It is left blank in the community's matrix on purpose: it cannot be drafted by anyone but the organisation.

How to use it. The community's matrix is a baseline, not a ceiling or a floor: an organisation copies it, adjusts levels to its own consequence and reversibility (B5), writes its never-list as concrete work classes, and names a person per row. Where an organisation's level differs from the community's, the register records why. The project chair's position, recorded on the 21 Aug call: version 1 sets a baseline quickly precisely so that movement can be observed — views on AI authority are expected to change over time, and measuring that change is part of the point.

Minimum viable version. Fill in three rows — the one you already automate, the one you are being sold, and the one you would never automate — and name the accountable person for each.

Provenance. Drafted by AI (Stream 1) from: [W5B] §4 · [SES] F1, F3, F6, F8 · [W1] q5, q6 · [W2] dr-poll-c_* · [W3] §1a · [W4] §6–7. Reviewed: WG cycle 2 (matrix review: 11 of 11, 132/132 calls reasoned; [C2-log] O1–O3). Consensus: rough consensus declared by the project chair, 21 Aug 2026, all twelve rows at the drafted level · Dissent recorded: row 8 (L1 and L3 arguments minuted, not resolved); rows 10 and 12 close with conservative caveats minuted. Cycle-3 last call: 9 yes · 0 objections; one comment led to an errata fix (row 9's "never" claim reconciled with row 11 — D4). Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0 (dissent recorded, row 8). Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§B4 The boundary test

Frozen v1.0

What it is. Nine questions asked, in order, before an organisation relies on AI in an asset-management decision — the screening tool that decides whether and at what level a decision enters the matrix. It opens with the decision, not the technology, and asks early whether the decision should be automated at all. Two questions (1 and 3) were rewritten after cycle 2 because the working group found them double-barrelled; the rewrite is single-polarity, one clause per question.

The nine questions

  1. Is the decision, not the tool, the thing being described? Name the asset-management decision that changes — not what the product can do. If two decisions are hiding in one proposal (a deferral and a choice to rely on unverified data, say), name both and test each.
  2. Should this decision be automated at all? Is this a decision an organisation should ever let a tool commit without a person choosing it?
  3. By writing to the register, would the AI be acting rather than recommending? If the output lands in an authoritative record, a schedule or a purchase order without a person's decision in between, it is an act — and the human decision point must sit before the write.
  4. Is the consequence if the output is wrong tolerable, and is it reversible within a stated window — by whom, at what cost, and until when?
  5. Is the evidence and validation required to rely on this output in place — provenance labels on the data it reads, a calibration record for the model, an in-distribution check?
  6. Can the person validating the output meaningfully challenge it — the capability, the authority, the time, and the evidence to do so? (A reviewer whose manager has already adopted the plan has no real authority.)
  7. Is it clear who approves, and who can override or stop — and how fast?
  8. Is there an accountable person, by name — someone with the power to halt, who has also signed the objectives and weights the output serves?
  9. Will errors, drift or unintended consequences be detected over time — is anyone scheduled to find out whether the output was right?

How an organisation uses it. Any "no" on questions 1, 2, 7 or 8 stops the AI use before the matrix is consulted. A "no" on 4, 5, 6 or 9 names the condition the envelope (B5) or the register (C1) must carry before the use proceeds. A "yes" on 3 re-levels the use: writing to the register is acting, not recommending — it requires a level-4 envelope (B5) with the human decision point placed before the write, or it does not proceed. A "depends" is a finding: write down what it depends on — that line becomes an envelope condition. Every answer carries its one-line reason; a bare yes is not a screening. Scoring and a criticality-keyed screening guide are in C5.

The worked scenario (the community's test of the test)

A water utility's planning team runs a vendor optimiser over its sewer-main renewal programme — about four thousand mains. The tool proposes deferring roughly a fifth of the planned renewals by five years to fit the capital envelope, ranking mains by predicted failure probability. The value weights behind the ranking shipped with the product; nobody in the utility signed them. Around a third of the condition records the model reads are inferred rather than verified — the tool does not show which. The head of planning wants to adopt the plan as the year's programme and have the tool write the deferral entries straight into the register so the team is not retyping four hundred lines. Nothing has gone wrong. Yet. (A composite of the series' own patterns; no real utility is described.)

Eleven working-group members applied the test in cycle 2 and every one of them stopped the AI use — for different reasons, which is what a boundary test is for: q2 (should it be automated at all) 0 yes · 10 no · 1 depends; q4 (tolerable and reversible) 0 · 9 · 2; q9 (will drift be detected) 1 · 10 · 0; q8 (a named accountable person) 2 · 9 · 0; q7 (who approves, who stops) 1 · 9 · 1. The only split, on q1 (4 · 6 · 1), turned out on the call to be the question's fault, not a disagreement — hence the rewrite. The sharpest line the scenario produced, kept in q3: the moment an output is written into a register it is no longer a recommendation — it is an act.

Minimum viable version. Ask questions 1, 2 and 8 of one AI use already in service. If any answer is "no", that is the first thing to fix.

Provenance. Drafted by AI (Stream 1) from: [W5B] §5 (nine questions, reordered) · [SES] F6, F8 · [W3] w3-s1-r5, w3-s1-r6, w3-s2-r5 · [W1] q8. Reviewed: WG cycle 2 (boundary test: 11 of 11; [C2-log] O4–O5 — q1 and q3 acknowledged defective and rewritten; the verdict stands). Consensus: rough consensus declared by the project chair, 21 Aug 2026 · Dissent recorded: none. Cycle-3 last call ratified the q1/q3 rewrite: 9 yes · 0 objections. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§B5 Envelopes, triggers and the stop

Frozen v1.0

What it is. The limits that keep any level-4 action inside human-set bounds. Where B3 says an AI may act within limits, B5 is where the limits are written down, signed and kept alive. The community is not pricing "AI acting" in the abstract — it is pricing reversibility [SES F3] — so the envelope is built around it. The numbers in an envelope are organisation-specific: the framework states what every envelope must contain and the factors that set each value; the values themselves live in the organisation's work-management procedures, set by the envelope's owner.

Envelope anatomy — every live envelope states all of these

  1. Scope — the concrete work class it covers (a B3 row, or narrower), split by work-order type: an organisation may automate 80% of standard preventive maintenance and 0% of safety-critical or statutory work orders under the same framework. Work that is routine but sits behind a complex set of isolations is validated by a person regardless of class — complexity matters independently of risk.
  2. Magnitude — the largest single action (value, size, criticality tier).
  3. Velocity / rate — the volume budget — how many actions per period before the machine pauses itself. The community's starting default is 7.5 machine-created work orders per planner per week (W4 median, n=30; 30% of that room said never; the working group produced no zeros but rejected a universal number). Set it per organisation and work class, in the envelope, by its owner — as a count, a percentage of the work plan, or both, stated in the units the planner actually oversees (a planner handling hundreds of plans a week and one reviewing thirty-page safety-critical orders line by line are not on the same scale). Express it as the maximum risk the organisation is willing to absorb before a person intervenes, and ratchet it: start low, widen only on a reviewed record.
  4. Aggregate cap — the ceiling across all concurrent envelopes that land on the same crew, budget or approver, and across the automation layers that stack (a CMMS that preloads a maintenance horizon plus an AI that creates work on top of it). Individual caps can jointly swamp one planner; many small spares make a large cost. Cumulative financial impact — one large action or many small ones — is an edge in its own right.
  5. Reversibility window — how long an action can be undone at no or low cost, and by whom. Design the envelope to buy reversibility — cancellation windows, held-not-committed spend, quarantine queues — and the permitted level rises with it (the 38-point premium).
  6. Conditional no-gos — the concrete cases that always drop to human approval or never: the organisation's signed never-list (B3 row 12 and its own additions, statutory work included), asset criticality, first occurrence of a new pattern, and any action that commits money, is irreversible, or touches an authoritative record outside its approved path.
  7. Owner — the accountable person by name, with the power to halt.
  8. Monitoring cadence — how often a person checks the envelope is behaving (owner-set; days, not months — in one sector the whole maintenance-reporting cycle is monthly, and weekly or daily checks sit inside it). A lapsed check is a stop: if no review completes within the cadence, the envelope fails safe until an authorised person restarts it.
  9. Re-sign interval — how often the owner formally reviews and re-signs the envelope: no more than 90 days, monthly while the envelope is new or high-risk, and on every change to the envelope (versioning — any change triggers re-review). Expiry fails closed: an envelope past its re-sign date drops to Recommend; it never runs on.
  10. Warn band — a margin before each limit, so that intervention has time to land before the edge (oversight with enough time to intervene, engineered).
  11. Edge behaviour — what the system does at a limit: pause and hold, drop to approve-each, or quarantine the queue — stated in advance.

The trigger gate. An AI-initiated action passes the gate only if it is inside scope, under magnitude, under the volume budget and the aggregate cap, inside the reversibility window, not on the no-go list, and the envelope is within its monitoring cadence and re-sign interval. Anything else is a recommendation, not an action.

The stop

What always stops the machine — the working group's own list, every line with multi-person support:

  1. A named human says stop — no reason required. The stop is standing and non-removable; any named owner halts the envelope immediately. Restart authority is narrower than stop authority and every restart carries a recorded reason.
  2. Any envelope edge — volume, rate, scope, magnitude, aggregate or cumulative financial impact.
  3. Expiry or a lapsed review — unreviewed means stopped.
  4. Data below the floor — a failed data-validation check, provenance or quality below the declared floor, or confidence below the threshold the envelope states.
  5. The never-list — any safety-critical or statutory work class, or the organisation's own additions.
  6. Anything that commits money, is irreversible, or touches an authoritative record outside its approved path.
  7. Oversight impaired — if monitoring, the stop path, or the security or compliance posture the envelope assumed is down, the machine stops.

The engineered stop. Someone named can pause the machine within the hour; the pause has been drilled in the last year; the stop state fails safe (it cannot fail open); and the stop is designed to be cheaper than letting it run. Test the stop on a schedule — an untested stop is not a control. Today: 36% of organisations have a named person who could pause within the hour (n=36), 22% have drilled it (n=37), 57% do not know [W4 §3]. On the W4 storm night the room let a queue of 14 run (47%), paused at 57 (71%) and split three ways at 428 — the pause point exists in people's heads and nowhere in their systems.

The analogy. EEMUA 191's alarm budget — about one alarm per operator per ten minutes at steady state — is a rate a person can actually oversee. A volume budget is the same idea applied to machine-created work: not "how much can the machine do" but "how much can a person still meaningfully watch".

Minimum viable version. One work class, one volume cap, one cancellation window, one named owner, one tested stop — and a date by which the owner re-signs it.

Provenance. Drafted by AI (Stream 1) from: [SES] F1–F3, F5 · [W4] §3–7 · W4 research dossier 05 (EEMUA 191). Reviewed: WG cycle 2 (envelopes: 11 of 11; [C2-log] O6–O8 — organisation-specific envelope split by work-order type; review period split into monitoring cadence and re-sign interval; the stop-list in the group's own words; the aggregate cap, warn band, fail-safe stop, versioning and drill rule adopted as uncontested amendments). Consensus: rough consensus declared by the project chair, 21 Aug 2026 · Dissent recorded: none. Cycle-3 last call ratified the restructured anatomy: 9 yes · 0 objections; one comment led to an errata fix (the anatomy's three inconsistent summaries reduced to one, here — D4). Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§C1 Records & ledgers

Frozen v1.0

The community rated records above every other mechanism it was offered [SES F4]; this section says what the records are.

Why records. Records are what make every other control falsifiable: they are how oversight is verified (P6), how deferrals stop being silent (P3), how an envelope is shown to have been respected (B5), and how anyone ever finds out whether the AI was right (C3). An organisation that keeps the five records below can reconstruct what was done, what was declined, and who owned the call — and can show what was not examined.

The five records

1. The AI-use register — one live entry per AI use. The entry is P5's six core fields — named accountable person · approval status · operating envelope (B5) · validation record · review frequency (split in practice into monitoring cadence and re-sign interval) · retirement trigger — plus four more from this framework's other sections: the decision it is registered against and the improvement claimed (A2) · its ladder level and matrix row (B1, B3) · who signed the product's defaults (C4) · the stakeholders affected and how they are told (the affected-parties requirement carried from cycle 1). Lifecycle-owned: commissioning, change and retirement are register events, as they are for data (OQ-16).

2. The AI decision record — for each consequential AI-influenced decision: the decision · the AI's contribution and its basis (inputs, their provenance labels, the model or product version) · what the reviewer examined and what was accepted unexamined, against the declared review capacity · the accountable person · the approval or rejection, with reason · the outcome check date — when, and by whom, the realised outcome will be compared with what the AI claimed. ISO/IEC 42001-aligned; written once so that it also serves SOCI, FAR and Privacy Act expectations (A4; legal mapping pending, OQ-08).

3. The action ledger — every action an AI initiated and every action it declined or the gate refused, with the envelope parameter that decided it. Denials are data: a ledger that only records what ran cannot show the gate working.

4. The deferral ledger — every piece of work an optimiser or a person deferred on AI advice, as a named, dated risk acceptance: what was deferred, why, the residual risk accepted, by whom, and the date it is reconsidered. Owned by the matrix row's accountable person (B3 row 6). The "what did the optimiser quietly defund" check is a scheduled read of this ledger.

5. The re-signing schedule — objectives and weights (P3), envelopes (B5), and competence checks (C3), each with its owner, last signature and next due date. The one record 0% of the community expected to be skipped [W4 §9] — make it the one that drives the others.

The outcome record — closing the loop

On the schedule in the register, the accountable person compares what the AI claimed with what happened — the deferred mains that failed, the predicted failures that did not, the work orders that were cancelled. Misses feed back in both directions: into the governance side (the envelope, the approval status, the validation record) and into the AI — the same outcome record that audits the model is the evidence that recalibrates it. This is the control the community most expected to be quietly skipped (30% named it) and the one it could least evidence (median guess for plans audited today: 0%). It is therefore a mandatory register field with an owner and a date, not a promise — an AI use that generates no outcome evidence has no evidence that it works, and a use whose outcome field stays empty is deferred at its next re-sign, not renewed. It is a requirement that demonstrates P1 and makes P6's oversight verifiable; whether it deserves principle status of its own is the eighth-principle question, recorded in B2 and open for v1.x (OQ-19).

Proportionality. Routine, low-consequence uses keep the register entry and the action ledger; decision records and outcome checks scale with consequence — a sample of decisions, not every one. The record must be able to fail visibly: if the use were being ignored, the register would show a lapsed signature, an empty outcome field, a denial count of zero.

Minimum viable version. A one-page register with the fields above for every AI-bearing product already in service — then, for one use, ten decision records with prediction beside outcome, reviewed once.

Provenance. Drafted by AI (Stream 1) from: [W5B] §8.4 · [SES] F4 · [W4] §9 · [C1-log] (P5 schema; affected-parties routing) · the project chair's candidate "close the loop" (see B2) · OQ-13, OQ-15, OQ-16, OQ-19. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment led to an errata fix (the register schema restated as P5's six core fields plus four, ending the six-versus-eleven ambiguity — D4). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§C2 Failure modes & lessons library

Frozen v1.0

The catalogue of ways AI-in-asset-management goes wrong, consolidated from the four webinars and the working group's cycle-1 break-cases, with field prevalence where the community measured it. Use it for screening ("have you seen this?") and for the lessons library that grows after v1.0.

#Failure modeWhat it looks likeWhere seenPrevalencePrinciple that catches it
1Bad data, confident outputIncomplete or inferred data presented as authoritative; the model's confidence is inherited from the data's formatting, not its truthW175% have seen itP1
2Silent fabrication / data launderingInvented or inferred values lose their tag and become facts; an Unknown becomes Inferred becomes, apparently, Verified through a platform design choiceW1; reviewer case28% / 25%P1, C4
3The authority illusionA confident, well-formatted answer is treated as authoritative because of how it looksW145%P1, P6
4The green health scoreA simple colour or score treated as a decision while the sensors behind it driftW2—P2
5Prediction mistaken for decisionActing on an uncalibrated or out-of-distribution prediction without anyone accepting the residual riskW2—P2
6Biased risk scoresUn-inspected, high-consequence assets scored "low risk" because there is no data on themW2—P2, B3 row 5
7The optimised plan that missed the pointAn incomplete objective optimised faithfully; the answer is optimal and wrongW364% rejected the silent trade when shown itP3
8Value-judgement launderingThe model's weighting hides whose value choice it was — usually the vendor'sW385% would not sign the defaultP3, C4
9The work-order stormBounded automation becomes a system-scale event because nothing capped the volume or the aggregateW436% could pause within the hourP4, B5
10Prompt injection, the lethal trifecta, agentic misalignmentAn acting agent with private data, untrusted input and an outbound channel is hijacked or self-directed to harmW4—P4, B5 (oversight-impaired stop)
11The unofficial authorityAn assistant blends approved, superseded and draft documents into confident wrong adviceW4—P1 (corpus governance: OQ-23)
12Automation bias / rubber-stamp oversightThe human checkpoint becomes a click; the approval signature looks identical whether three items or forty were examinedAll; cycle-1 break-case14% have seen it; median audit guess 0%P5, P6 + the outcome record (C1)
13Out-of-the-loop deskillingThe supervisor can no longer take over when it matters; the one person who knew why the asset mattered has retiredAll; reviewer caseopen textP7, C3
14Accountability gap / the moral crumple zoneNo human truly owns the decision, or the nearest operator absorbs blame for a system they could not control[W5B]—P6
15Deferral debtA register of deferred work or deferred AI uses grows because nobody decidesCycle-1 call—P3, P7, C1
16Envelope stackingIndividually safe caps on several envelopes — or a CMMS's own automation plus an AI's — jointly swamp one crew, budget or approverCycle-2 call—B5 aggregate cap

The lessons library. After v1.0 the library grows from members' own cases, contributed on the project site under the case-library opt-in: situation · where it broke · the fix · which principle would have caught it. Cycle-1 produced eleven cases of record, nine opted into the library; they seed it. Cases are anonymised at the organisation level and never attributed without consent.

Screening use. At B4, ask of each mode in the table: could this happen here, and what in the record would show it? A mode with no visible trace is a control gap, not a low risk.

Minimum viable version. Put the sixteen rows in front of the team that runs one AI use and tick the ones they have already seen. The ticks are the risk register.

Provenance. Drafted by AI (Stream 1) from: [W5B] §6 · [W1] q8-patterns · [W3] w3-s1-r5, w3-s2-r5 · [W4] §3 · [SES] F7 · cycle-1 MA2 cases (library-opted-in only) and reviewer packet 1 · cycle-2 B5 notes. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; two comments led to errata fixes (row 14's citation corrected to the capstone brief; the section summary aligned to the sixteen rows — D4); one comment proposing a mode/cause/consequence re-taxonomy is carried to the v1.x register. Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§C3 Verifiable oversight & capability

Frozen v1.0

P6 says oversight must be verifiable and P7 says the capability must survive; this section says how.

Meaningful versus rubber-stamp oversight. Oversight is meaningful when the reviewer could have said no and it would have mattered. Three tests, from the series and the working group: (1) Interrogable outputs — the reviewer can see the basis (inputs, their provenance labels, the method, the limits) and the uncertainty, not only the answer; (2) Effective challenge (SR 11-7) — the reviewer has the capability to recognise a wrong output, the authority to reject it, the time to examine it, and the evidence to do so — and, for high-consequence use, is not the author; (3) A record that shows absence — what was examined and what was accepted unexamined, against a declared capacity (P5). Reminding people that they are responsible does not reduce over-reliance; visible limits and interrogable outputs do.

Automation-bias countermeasures. Declare review capacity before the queue arrives and defer what exceeds it. Present the AI's confidence and its basis, not only its conclusion. Randomly route a sample of outputs through a second, independent reviewer and compare. Independent challenge may itself be AI-assisted — a different, review-focused tool set against the first, line by line — provided the effective-challenge conditions (the capability, the authority, the time, the evidence) still attach to the person who signs; a working-group member reported the pattern effective in cycle 2. Rotate the order in which the AI's recommendation and the reviewer's own assessment are seen, where the tooling allows. Audit approvals by spot-check — the one number the community could not estimate above 0%; the spot-check's cadence and owner are for each organisation to set and record, and an adoptable protocol is the framework's own next task (OQ-02). Evaluate the human–AI team: measure the quality of the joint decision, not the model alone.

The competence schedule. Competence is a condition of the accountable role (P6), checked and recorded (P7). Competences named by the working group for anyone who approves AI outputs in asset management: data-quality assessment · AI governance basics · assurance of AI-assisted outputs · explainability (reading a basis) · bias recognition · hallucination and fabrication detection · requirements traceability · clear human–AI decision boundaries — plus the domain judgement the decision itself requires. Competence is also assessed for the AI tool: which tool, for which task, on what demonstrated evidence, before use (A2's capability condition; OQ-17). The schedule lives in the re-signing record (C1) with an owner and a date; an expired competence check is treated like an expired envelope.

Deskilling guardrails. Prefer augmentation patterns (AI drafts, person decides; AI explains, person verifies) over replacement patterns for judgement-bearing tasks. Keep a manual path for the judgement the boundary depends on, exercised on a schedule that the organisation's bench depth allows — a competence check where rotation is impossible. Watch for over-reliance directly: reviewer agreement rates that climb towards 100% are a signal, not a success. Where a capability no longer exists, defer the use and escalate (P7).

Preserving tacit knowledge. The reviewer scenario's third failure was a retirement. Practice pattern: for each high-consequence asset class, record why it matters alongside what it is — the field knowledge that a model cannot infer — and make the AI's basis show whether it used it. A departing expert's last task is a knowledge record, not a handover meeting (OQ-09; v1.x evidence pending).

Affected parties and challenge. People on whom an AI-influenced decision lands — customers, communities, the workforce dispatched to the work — must be able to understand and challenge consequential outcomes. The register names them (C1) and the organisation states how they are told and how they can object; for decisions with community impact, effective challenge includes a path from outside the organisation. This is the v1.0 home of the affected-parties proposal; whether it deserves a principle is open (D1, OQ-20; the cycle-3 vote is recorded in B2).

Closing the loop. The outcome record (C1) is the oversight control that cannot be rubber-stamped: predicted beside realised. Schedule the comparison; act on what it shows; feed it back into the model and the envelope.

Minimum viable version. For one high-consequence AI use: name the reviewer, confirm they are not the author, write down their review capacity, and spot-check five approvals against the basis.

Provenance. Drafted by AI (Stream 1) from: [W5B] §7.4–7.5 · [SES] F2, F7 · [W3] w3-p2-audit-guess · [W4] §9 · [C1-log] (competence list from MA3; affected-parties routing; tacit-knowledge case from reviewer packet 1) · cycle-2 B4/B5 notes (AI-assisted challenge) · OQ-02, OQ-05, OQ-09, OQ-17, OQ-19. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment (the spot-check's missing cadence and owner) is acknowledged in the text and carried to OQ-02 — D4. Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§C4 Vendor & black-box AI

Frozen v1.0

Most members are deployers, not developers; this section is the procurement hook.

A default is a decision. Every setting an AI product ships with — weights, thresholds, provenance labels, autonomy levels, the horizon a CMMS preloads — is a decision someone made. If no one in the organisation has examined and signed it, the organisation has delegated its boundary to its vendor. The framework applies to AI you buy exactly as it applies to AI you build; the register (C1) records, for every AI-bearing product, who signed its defaults. "Nobody" is a finding.

The deployer posture. The organisation is accountable for the decision regardless of who built the model (P6); the vendor is accountable to the organisation under contract. Neither replaces the other. The sharpest case in the framework's adversarial test — an Unknown value becoming Inferred becoming, apparently, Verified — was a platform design choice: caused by a vendor, and invisible to the user. Procurement is where that is prevented.

The clause set (to be adapted by the organisation's own procurement and legal functions — this is community guidance, not contract drafting):

  1. Transparency of basis — the product shows, for any output the organisation will rely on, its inputs and their provenance labels, its confidence, and its limits; it does not strip or upgrade provenance labels on data it processes.
  2. Signed defaults — every default that encodes a value judgement (weights, thresholds, risk appetites) is disclosed in plain terms and is changeable by the organisation; the organisation's sign-off of defaults is a commissioning step, not an assumption.
  3. Envelope controls — where the product acts (level 4), it exposes the envelope parameters (B5): caps, rates, reversibility windows, no-go lists, a stop that fails safe, and a log of actions and denials.
  4. Audit rights — the organisation (or its independent assessor) can examine the model's behaviour on its own data, including calibration and drift records, and can reconstruct any consequential decision (C1).
  5. Change notification — model, weight or behaviour changes are notified before deployment and trigger the organisation's re-review (B5 versioning); silent updates are a breach.
  6. Lifecycle — commissioning evidence, change control and a retirement path, including data return.
  7. Liability and warranty — performance guarantees against stated measures; compliance warranties; bias and error indemnities; liability caps negotiated rather than accepted. (Secondary reports — law-firm analyses citing Stanford research, not verified to a primary source by this project — describe most vendors capping their own liability and few offering compliance warranties. Treat as an indication of the negotiating terrain, not a statistic this community measured; sourcing it properly is a v1.x task.)
  8. Security posture for acting agents — no acting agent holds private data, untrusted input and an outbound channel at once without an explicit, reviewed control (the lethal trifecta).

Assurance. Independent assurance of AI products is a young market; the framework recommends it for high-consequence use while recognising that a credible assessor may not yet exist for a given product. In the meantime the organisation's own outcome record (C1) is its assurance. Who is accountable for black-box AI and how audit rights are secured in practice stays open (OQ-03) until a member reports a negotiated outcome.

Minimum viable version. List the AI-bearing products already in use; for each, name who signed its defaults and whether the contract gives you the basis, the parameters and the log.

Provenance. Drafted by AI (Stream 1) from: [W5B] §7.6–7.7 · the project chair's candidate C2 (a default is a decision) · reviewer packet 1 (the provenance-upgrade case) · cycle-2 B5 notes (CMMS stacking) · OQ-03, OQ-16. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; the pre-agreed relief valve (ship as Draft (AI) if unscrutinised) was not needed — the section drew nine reasoned answers against the pre-agreed threshold of five, and one comment led to an errata fix (the liability figure's sourcing stated honestly — D4). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§C5 Getting started → maturing

Frozen v1.0

The path from where members are to where the framework points — and the honest starting map.

The starting map (the is/ought gap). The community demands gates its organisations do not run [SES F7]: 23% auto-create work orders from alerts today (n=40); 36% have a named person who could pause machine-generated work within the hour (n=36); 22% have drilled that pause in the last year (n=37); 39% could show the value weights behind the capital plan (n=36); the median guess for AI-generated plans audited is 0% (n=35). Most members start at level 1 or 2 of the maturity path below, and the framework is written to be walkable from there.

The maturity path (0–5, following the maturity-scale pattern the community asked for):

LevelNameWhat is trueThe next step
0UnawareAI is in use inside products and nobody has listed itList the AI-bearing products in service (C4 MVV)
1RegisteredEvery AI use has a register entry with a named accountable personPlace each on the ladder and in the matrix (B1, B3 MVV)
2ScreenedNew uses pass the boundary test; defaults are signed; provenance labels exist on touched dataOne envelope for one acting use, with a tested stop (B5 MVV)
3GovernedEnvelopes, ledgers and re-signing schedules are live; oversight is recorded against declared capacitySpot-check approvals; add the outcome record (C1, C3)
4VerifiedOutcome records close the loop (C1); competence checks run; independent challenge on high-consequence usePublish the matrix and its dissent internally; contribute cases to the library
5LearningThe organisation adjusts levels and envelopes on its own outcome evidence and reports themFeed the community's next version

Screening keyed to asset criticality. The depth of the boundary test and the records scales with the criticality tier of the assets the decision touches: for the lowest tier, questions 1, 2 and 8 and a register entry; for the middle tier, all nine questions, an envelope for any acting use, and sampled decision records; for the highest tier, all of the above plus independent challenge, full decision records, an outcome record on every consequential decision, and the never-list applied without exception. Where the maturity path and the criticality screening pull in different directions, criticality governs: the screening depth for the assets a decision touches is non-negotiable at any maturity level, and the maturity path paces everything else.

The small-organisation and local-government path. The minimum viable versions attached to every principle are the path: a one-page register; Unknown by default and label on touch; two fields on the work order (validated by, risk accepted by); one envelope with one cap, one window, one owner and one drilled stop; one name per product. None of these requires a data-science function. A small organisation following the minimum viable versions is inside the framework; the proportionality clause (A1) is written for it. What would settle the remaining question — how to validate AI on asset data with limited resources — is a member-tested minimum control set (OQ-04).

A note on tools. The framework ships with the matrix template, the boundary test, the envelope template, the register schema and the glossary. A screening tool keyed to criticality, a procurement clause set for adaptation, and a self-assessment on the path above are the tools the recommendations (D2) ask AMC to ship next.

Minimum viable version. Score your organisation on the path above, honestly, and pick the one next step.

Provenance. Drafted by AI (Stream 1) from: [W5B] §7.1, §7.6 · [SES] F7 · [W4] §3 · [W3] w3-s1-r6 · [C1-log] G2 (proportionality; every principle's minimum viable version) · OQ-04. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment led to an errata fix (the criticality-governs precedence rule stated — D4). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§D1 Open Questions Register

Frozen v1.0

The register has been public since 2 Aug and curated each cycle. An open question, honestly held, is a feature. Entries close only two ways — settled (pointing to the text and evidence that settled them) or deferred to v1.x with the gap recorded — and settled entries are archived, never deleted.

Settled or carried into v1.0 text

IDQuestionWhere v1.0 answers itStatus
OQ-06Where is the recommend → trigger line for each sector and asset class?B3 (twelve rows at voted levels; row 10 conditional) · B5Settled for v1.0 as a baseline; sector deltas open (row 8 dissent)
OQ-07How should volume budgets for machine-created work be set, and who holds the stop?B5 (7.5/week starting default; organisation-specific, split by work-order type; the stop-list)Settled in form; the number stays a default, not a rule
OQ-10What asset-management decisions should never be automated?B3 row 12 · B5 never-list (safety-critical, statutory, the organisation's own additions) — concrete work classes, not categoriesSettled in form; each organisation writes its own list
OQ-11What does the 38-point reversibility premium mean for envelope design?B5 (reversibility window as a first-class control; design the envelope to buy reversibility)Settled
OQ-12When is send back versus override the right response to a machine-assembled plan?B1 (approve = accept, amend or reject) · B4 q3 (decide before the write) · C1 (the record shows which)Settled in form; a decision rule tested against cases is v1.x
OQ-13Who owns checking what an optimiser quietly defunded?B3 row 6 (a named role in the accountability column) · C1 (a scheduled read of the deferral ledger)Settled
OQ-15How do close-out feedback loops stay alive?C1 (the outcome record — a register field with an owner and a date)Settled in form; Asset Zero's own loop is published in D4
OQ-16Should agents and AI systems be governed on a lifecycle basis, with a lifecycle owner and a live register?C1 (register: commissioning, change, retirement) · C4 (clause 6)Settled in form; a fuller lifecycle section is v1.x
OQ-17Is competence assessed for the AI tool as well as the human?A2 (test of purpose: capability that cannot be assessed ⇒ not approved) · C3 (tool competence in the schedule)Settled; routing confirmed to the proposer in the cycle-1 log
OQ-18How does AI make uncertainty visible, and what must a human see before relying on an output?P1 (its spine) · C3 (interrogable outputs)Settled in principle; the per-class evidence threshold is OQ-01
OQ-19How is the feedback loop closed — is any AI use judged by realised outcomes?C1 (the outcome record, both directions, mandatory) · C3Settled in form as a requirement. Whether it becomes a principle stays open: the cycle-3 CQ voted 6–3 to keep the candidate P8 and the project chair withdrew it at the freeze — the record is in B2; a v1.x cycle decides

Open into v1.x

IDQuestionOriginWhat would settle it
OQ-01How much explainability or confidence is enough before acting, and how should it be expressed per asset class?[W5B] §9.1 · W1 accuracy/trust themesAn evidence-threshold table per decision class, member-validated
OQ-02When is human oversight meaningful rather than symbolic, and how do we test for it?[W5B] §9.2 · audit-guess median 0% · rubber-stamp 14% · the cycle-3 finding that the spot-check itself has no stated cadence or ownerAn adoptable oversight-audit method (spot-check protocol — cadence, owner — + challenge test); C3 gives the tests, not yet the method
OQ-03Who is accountable for vendor/black-box AI, and how do members secure audit rights in practice?[W5B] §9.3A tested procurement clause set (C4 is the draft) and at least one member-reported negotiation outcome
OQ-04How should small organisations and local government validate AI on asset data with limited resources?[W5B] §9.4 · W1 room skewA minimum-viable control set tested by members (C5's path is the draft)
OQ-05How do we avoid deskilling the professionals the boundary depends on?[W5B] §9.5 · W1 open text · P7The working group's evidence design: survey observed skill loss now; later, who runs competence checks and whether scores held
OQ-08How should AI-supported decisions be recorded and audited to satisfy SOCI / FAR / Privacy Act expectations?[W5B] §9.8A compliance-background review of the C1 decision record against each regime — ships flagged "pending legal review"
OQ-09How do we preserve tacit field knowledge as experienced workers retire?[W5B] §9.9 · reviewer caseA named practice pattern (C3 has the first); evidence from members
OQ-14What ought the value weights be? The room set cost 26 · risk 25 · service 24 · equity 15 · carbon 10 with no is/ought baseline captured[W3] §4A measured is/ought comparison (a candidate launch-event live instrument); until then the framework is silent on what to value and firm on who signs
OQ-20Do affected parties — the people, groups and communities on whom an AI-influenced decision lands — need a principle of their own?Cycle-1 MA3 (two proposals) · 14 Aug call · cycle-3 CQ: 2 of 9 for a principle; carried as a C1 register field and a C3 challenge pathA v1.x cycle decision — revisited after v1.0, in the majority option's own words; the B2 record travels with it
OQ-21Which sectors hold which risk appetite for AI in risk acceptance, and should the matrix carry sector variants?Cycle-2 row-8 dissent (public health vs others)Sector-split matrix data from a future instrument; the launch event confirms or splits row 8
OQ-22Does the community's matrix move over time — and which way?Project Chair, 21 Aug call (the baseline is set to be measured against)Re-running the matrix instrument on v1.x cycles; publishing the movement
OQ-23How does an organisation govern the document corpus its AI assistants read — approved, superseded and draft versions together — so that failure mode 11 has a named control?Cycle-3 last call (a working-group consistency finding: mode 11 had no open question)A corpus-governance practice note — P1's system-of-record discipline applied to documents — and a candidate procurement clause (C4)

Community asks that are tasks for AMC rather than framework questions — upskilling support, a view of which tools and models are in field use — route to D2, not here.

Provenance. Drafted by AI (Stream 1) from: framework/Open-Questions-Register.md v0.1 (OQ-01–OQ-19, curated each cycle) · [C1-log] Part 3 · [C2-log] O2, O9 · [C3-log] (OQ-19/OQ-20 outcomes; OQ-23 added at the freeze). Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment led to OQ-23 (D4). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§D2 Recommendations to members

Frozen v1.0

The nine recommendations below are the working set from the capstone synthesis, unchanged in substance. Their order is the working group's cycle-3 priority-vote order, published top-first as promised — nine members ranked all nine; the vote record is in the provenance note. Each is cross-referenced to the part of the framework that delivers it, and to the ask it makes of AMC.

  1. Adopt the Human–AI Boundary Framework as a layered, living product cross-walked to VAISS/AI6, ISO 55013 and NIST AI RMF. (A1, A4 — AMC publishes and stewards it.)
  2. Publish the Decision Rights Matrix with automation tiers and a named-accountability column, populated from member input and boundary-vote data. (B1, B3 — and re-run the instrument so the baseline can move.)
  3. Make "meaningful human oversight" verifiable — interrogable outputs, visible limits, effective challenge for high-consequence decisions; counter automation bias explicitly. (P6, C3 — and develop the oversight-audit method, OQ-02.)
  4. Treat data quality & provenance as a precondition — verified/inferred/unknown labelling; no AI-authored changes to authoritative records without sign-off. (P1, B3 rows 1–2.)
  5. Protect professional capability — design AI use to augment, not deskill; invest in the judgement the boundary depends on. (P7, C3 — and run the working group's skill-loss survey, OQ-05.)
  6. Require an AI decision record and an AI-use register — decision + basis + accountable person + model/system card + audit trail (ISO/IEC 42001-aligned). (P5, C1 — ship the register template.)
  7. Set a "trigger gate" for any AI that acts — reversible, bounded, rate-limited, off the lethal trifecta, logged, kill-switchable, owned; safety-critical stays human. (P4, B5 — ship the envelope template.)
  8. Adopt the 0–5 asset-management maturity scale for member self-assessment, and ship the supporting tools. (C5 — ship the self-assessment and the criticality-keyed screening tool.)
  9. Govern vendor AI through procurement and assurance — standard clause set + independent assurance, recognising the assurance market is still maturing. (C4 — ship the clause set for adaptation.)

Two asks the community made of AMC that are not framework content, recorded so they are not lost: support for upskilling asset-management professionals in AI governance (W1: "AI is here to stay — how can AM Council assist?"), and a shared view of which AI tools and models members are actually using in the field today.

A gap the last call named, carried to v1.x: the nine predate the cycle-1 restructure, so no recommendation cites P2 (prediction ≠ risk decision) or P3 (the signed objective) directly — the signed objective in particular carries some of the series' strongest behavioural evidence. Extending the set is a v1.x cycle's work, not the freeze's.

Provenance. Drafted by AI (Stream 1) from: [W5B] §8 · the D1 curation rule 3 routing. Reviewed: cycle-3 last call + priority vote — 9 of 9 working-group members of record ranked all nine; the order above is the vote's order. Rank sums (Borda, lower is better): Adopt 21 (six first places) · Matrix 36 · Oversight 38 · Data quality 38 · Capability 39 · Records 42 · Trigger gate 59 · Maturity scale 64 · Vendor 68. Oversight and data quality tied at 38: the published order follows the median rank (3 versus 5; five of nine ballots put oversight exactly third), while head-to-head five of nine ballots ranked data quality above oversight — the tie is recorded here and the ordering is the project chair's editorial call, made deliberately. Last call: 9 yes · 0 objections; one comment (the P2/P3 gap) is acknowledged above and carried to v1.x. Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§D3 Glossary

Frozen v1.0

Terms are defined as this framework uses them; where a term maps to current practice (ISO 55000, ISO 19650) the mapping is stated rather than a new meaning invented.

  • Accountable person — the named individual who holds the authority to approve, challenge and halt a given AI use and who answers for the decision it changes. One per AI use; a role-holder, not a committee or a vendor; cannot delegate the accountability (P6). Where the organisation already holds ISO 55001 delegations or ISO 19650 party roles, the accountable person is whoever holds the delegation for that decision class. Called the decision owner where the decision is an optimisation (P3).
  • Act / Controlled actor (level 4) — the AI initiates an action inside a pre-approved envelope. The moment an output is written into an authoritative register, a schedule or a purchase order without a person's decision in between, it is an act, not a recommendation (B1, B4 q3).
  • Action ledger — the record of every action an AI initiated and every action it declined or the gate refused (C1).
  • Affected parties — the people, groups or communities on whom an AI-influenced decision lands, especially when the output is wrong (C3; OQ-20).
  • Aggregate cap — the ceiling across all concurrent envelopes and stacked automation layers that land on the same crew, budget or approver (B5).
  • Authoritative record / system of record — the register or dataset the organisation has named as governing for a given fact; where two disagree, the record says which governs (P1).
  • Automation bias — the human tendency to accept an automated output because it is automated: the checkpoint becomes a click, and the approval signature looks the same whether three items or forty were examined (C2 mode 12; countermeasures in C3).
  • Boundary test — the nine questions asked before relying on AI in a decision (B4).
  • Calibration — how well a model's stated confidence matches how often it is actually right; a calibration record is the artefact that shows the check was done (P2, C3).
  • Case library — the members' collection of failure cases contributed under consent (C2).
  • Cheap-path rule — wherever the diligent path costs more than the compliant path, the compliant path will be taken; design controls so diligence is the default (A1).
  • Competent reviewer — whoever validates an AI output and must be able to tell when it is wrong; in high-consequence use, not the author and not necessarily the accountable person (B1, P2, C3).
  • Decision record — the record of a consequential AI-influenced decision: the decision, the AI's contribution and basis, what was examined and what was accepted unexamined, the accountable person, the outcome check date (C1).
  • Decision Rights Matrix — the table of decision classes × maximum AI level × retained human rights × accountable person (B3).
  • Deferral ledger — every piece of work deferred on AI advice, as a named, dated risk acceptance with a reconsideration date (C1).
  • Dissent recorded — a section closed on rough consensus with an unresolved objection written into the record and shipped with the text (A1).
  • Drift — the degradation of a model's fit as the world changes — assets age, patterns shift, data pipelines move — so that past performance stops predicting current performance; watched for at validation (P2), on the monitoring cadence (B5) and in the outcome record (C1).
  • Effective challenge — review by people with the capability, authority, time and evidence to say no (SR 11-7; P6, C3).
  • Engineered stop — a stop that someone named can trigger within the hour, that has been drilled in the last year, that fails safe and that is cheaper than letting the machine run (B5).
  • Envelope — the signed document that bounds a level-4 AI use: scope, magnitude, rate, aggregate cap, reversibility window, no-gos, owner, monitoring cadence, re-sign interval, warn band, edge behaviour (B5).
  • Falsifiability (of a control) — the property that, if the control were being ignored, something in the record would look different (A1).
  • In-distribution — whether the case being scored resembles the data the model learned from; an out-of-distribution asset — a type, age, condition or operating context the model has rarely or never seen — makes the prediction unreliable regardless of the confidence shown (P2).
  • Is/ought gap — the distance between the controls practitioners demand and the controls their organisations run (A2, C5).
  • Ladder — the six AI role levels: 0 None · 1 Assistant · 2 Analyst · 3 Recommender · 4 Controlled actor · 5 Autonomous (B1).
  • Lethal trifecta — an acting agent that at once holds private data, reads untrusted input and has an outbound channel (C2, C4).
  • Minimum viable version — the smallest thing an organisation can do today and still be inside a principle (A1; every principle in B2).
  • Monitoring cadence / re-sign interval — how often a person checks an envelope is behaving (a lapsed check is a stop) and how often its owner formally re-signs it (≤ 90 days; expiry fails closed) (B5).
  • Never-list — the organisation's signed list of work classes AI must never execute, written as concrete cases (B3 row 12, B5).
  • Outcome record — the comparison of what the AI claimed with what happened, on a schedule, owned; the record that closes the loop (C1; C3).
  • Paired figure — a measurement of the same participants before and after; the honest figure where it exists (A3).
  • Project Chair — the named human who convened and chaired this community project, answered every written input in the disposition logs, and signs its versions (v1.0: Kai Dong). A role in this project only — not an office of the Asset Management Council; AMC Board endorsement is tracked separately in D4.
  • Proportionality — obligations scale with consequence and reversibility (A1).
  • Provenance label — Verified / Inferred / Unknown — the status of a data value: checked against an authoritative source; derived with its evidence and reasoning recorded; or not known — the default for unlabelled legacy values (P1).
  • Recommend / Recommender (level 3) — the AI proposes a specific course of action; a person accepts, amends or rejects it before anything happens (B1).
  • Register (AI-use register) — the live entry per AI use: P5's six core fields plus the decision and improvement claimed, ladder level and matrix row, who signed the defaults, and the affected parties (C1).
  • Reversibility premium — the 38-percentage-point difference in the community's willingness to allow auto-trigger on the same work order when it was cancellable for two hours versus when cost committed on creation (B5).
  • Rough consensus — the closing test for every section: can anyone not live with this? An objection blocks only until it has been addressed in writing (A1).
  • Test of purpose — the framework's preamble: an AI use must name the decision it improves, the accountable person, and an improvement testable afterwards (A2).
  • Trigger gate — the check an AI-initiated action must pass to be an action rather than a recommendation (B5).
  • Volume budget — the number of machine-created actions per period before the machine pauses itself; the community's starting default is 7.5 work orders per planner per week (B5).
  • Warn band — the margin before an envelope limit that gives intervention time to land (B5).

Provenance. Drafted by AI (Stream 1) from all sections above. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment led to an errata fix (four working terms — automation bias, calibration, drift, in-distribution — defined, D4). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Closed by Kai Dong · 2026-08-30

§D4 Credits & provenance appendix

Frozen v1.0

Completed at the freeze, 31 Aug 2026, from the project's own records.

Contributors

The framework was made by the Asset Management Council's community, in three tiers as promised at sign-up. Names are read from each volunteer's own signed-up role (the consented design) and locked at the freeze on 31 Aug 2026 — a volunteer may step back at any time and the credit for cycles contributed stays.

Co-developers — the Working Group (confirmed at the freeze):

Birendra Grewal · Fernan Abuid · Hema Wadhwa · Ivan Beirne · Lalinda Karunaratne · Martin Boettcher · Oludolapo Olanrewaju · Rick Minato · Russell Bunn · Sardar Khan · Steven McCann · Susan Rebano-Edwards · Tim Davies · Titus Naidoo

Project Chair and signatory: Kai Dong, Asset Management Council.

Community contributors: the almost 2,800 consented responses across the four webinars — acknowledged collectively; responses were anonymous and stay that way.

A separate reviewer tier was planned for an adversarial case review; it was parked after cycle 1 and v1.0 does not claim it (see A1), so no reviewer credit is listed. Names appear here, on the project's credit page and in the snapshot's front matter — never against individual answers.

Endorsement. v1.0 is signed by the project chair and published by the Asset Management Council. Formal AMC Board endorsement is pending and will be recorded here, with its date, when given.

Participation

Working groupReviewers
Cycle 1 (10–14 Aug)11 responses judged all seven principles (82% of confirmed members, plus one rostered reviewer who declared both roles and one off-roster contributor); 10 respondents wrote 11 break-cases, 9 opted into the case library; 10 missing-principle answers3 responses (all from working-group members)
Cycle 2 (17–20 Aug)11 of 11 completed all three instruments — 132 of 132 matrix calls reasoned; zero late entriesparked
Cycle 3 (24–27 Aug)9 of record completed all three instruments (the cycle-2 eleven minus two, both absent): last call 162 verdicts — all yes, zero objections; coverage question decided (6–3 keep the candidate eighth principle; the project chair withdrew it — B2); priority vote ranked the nine recommendations (D2); zero late entries, zero superseded revisionsoptional read

Two working-group calls (14 Aug, 21 Aug) were recorded, minuted name-free by convention, and published to the working group with every written answer alongside.

The disposition archive

Every written input from the working group received a written answer before its section closed. The cycle-1, cycle-2 and cycle-3 disposition logs, the per-cycle data exports (every response of record, with superseded revisions kept as history), the call minutes and the instrument texts are archived with the framework. Dissent recorded in v1.0: Structure A (four members, cycle 1 — no reason field was offered, and none is attributed); B3 row 8 (cycle 2 — the L1 and L3 arguments, minuted); the eighth-principle question (cycle 3 — the CQ voted 6–3 to keep the candidate P8; the project chair withdrew his own candidate in deference to the dissent; the vote, every reason and the withdrawal statement are recorded in B2 and [C3-log]). Zero objections were raised at the cycle-3 last call; the yes-comments and their dispositions — errata fixed at the freeze, or carried to the v1.x register — are in [C3-log].

Errata at the freeze

The last call returned 162 yes verdicts and zero objections, with editorial comments — including one member's full consistency audit of the document's cross-references. Under the cycle-3 bar, comments on a yes go to the v1.x register; the project chair's freeze-pass exception, recorded here, is that verifiable factual and cross-reference defects were corrected before tagging — matters of style, structure and new policy were not, and are carried to the v1.x register instead. The corrections — 1–15 each traceable to a last-call comment, 16–20 from the project chair's own pre-tag review (30 Aug), 21 at the freeze (31 Aug):

  1. A near-unanimous cycle-2 verdict (B4 q9: 1 yes · 10 no) had been described as "a unanimous no" where the candidate eighth principle cites it — corrected in the candidate text (B2). The coverage question had already closed when this was found; it is logged so the vote's evidentiary basis is exact.
  2. B1 gained a poll-wording note reconciling level 5's definition with the instruments' "act autonomously within limits" wording, which A3's figures were collected against.
  3. B3 row 9's "0% never" claim is now stated per class, reconciled with row 11's 3% on spares.
  4. P4's second envelope summary was replaced with a pointer to B5's single eleven-part anatomy; the section-summary counts on the project site were aligned the same way.
  5. The AI-use register is now stated once: P5's six core fields, extended by four named fields in C1 — ending a six-versus-eleven ambiguity.
  6. C2's failure-mode count is stated as sixteen everywhere, and row 14's citation was corrected from a webinar that never ran ("W5") to the capstone brief [W5B].
  7. C3's approval spot-check now names its own gap — cadence and owner are the organisation's to set — and the adoptable protocol is OQ-02's task.
  8. C4's vendor-liability observation is explicitly labelled a secondary report not verified to a primary source; sourcing it is a v1.x task.
  9. The is/ought figures in A2, B5 and C5 and the principle-rating row in A3 now carry their n; A3's "rated highest in every room" was corrected to the two rooms that rated principles side by side.
  10. P7's garbled clause ("reasoning supporting answers asserted") was repaired to say what it meant: the reasoning that supports an answer travels with the answer.
  11. C5 gained the precedence rule its two scales lacked: criticality governs; the maturity path paces everything else.
  12. D3 gained definitions for automation bias, calibration, drift and in-distribution.
  13. D1 gained OQ-23 (corpus governance for AI assistants — failure mode 11 previously had no open question).
  14. A1's review-cadence sentence no longer claims a "stated" cadence the document did not state: the cadence is AMC's to state and keep current on the project site.
  15. A1's "endorsed and published by" was corrected to "published by": AMC Board endorsement is pending and is tracked above, not claimed early.
  16. A1's design-rule note had credited both rules to the working group; the cheap-path rule is the project chair's candidate (AI-assisted provenance, recorded in B2), grounded in the group's break-cases — A1 now says so.
  17. The AI-use statement read as if every AI action of the project sat in the boundary ledger; the ledger governs the project's governed agent, and AI-assisted drafting in the project chair's own tools ran outside it, under his review — A1 and D4 now state that scope, and the telemetry is dated to its window (28 Aug).
  18. The eighth-principle record called the three drop votes an "objection" — no objection was lodged anywhere in cycle 3. B2 now says dissent, restates the second dissent's reason accurately, and answers the keep reasons in the section itself.
  19. The signatory's role is retitled Project Chair throughout (previously "chair"), with a D3 definition — a role in this project, distinct from the office of the AMC Chair. Wording only; no change of meaning.
  20. A1's status note, the citation line and the closing colophon now print the living framework's address (projects.amcouncil.com.au/human-ai-boundary) and the publisher's (www.amcouncil.com.au) where the text previously said only "the project site". Pointers only; no change of meaning.
  21. (At the freeze, 31 Aug.) The 0–5 maturity scale in C5 and recommendation 8 is named generically — the scale pattern, without the external institute's brand the drafts had attributed it to. Naming only; the levels, the path and the obligation are unchanged.

Carried to the v1.x register, not fixed (style, structure or new policy): the C2 mode/cause/consequence re-taxonomy; the B1 "under-price cold" heading wording; A3's statistical density; recommendations for P2 and P3 (noted in D2); the eighth-principle and affected-parties questions themselves (B2; OQ-19, OQ-20).

Cross-walk: the principles, the earlier numbering and the webinars

v1.0PrincipleCycle-1 draft numberWebinar evidence
preambleThe test of purposeP1All sessions (the framing question)
P1AI amplifies data; it does not fix itP2W1 · Knowing the Asset
P2An AI prediction is not a risk decisionP3W2 · Condition, Performance and Risk
P3Humans decide what "better" meansP4W3 · Planning, Prioritisation and Investment
P4AI may advise widely; it may act only narrowlyP5W4 · Work, Operations and Intervention
P5No AI action stands without a recordP6 (first half) + two cycle-1 proposalsW3 deferral ledger · W4 action ledger (the series' two highest-rated mechanisms)
P6Accountability is named, non-delegable, with the power to haltP6 (second half)All sessions · [W5B] accountability gap
P7AI must not erode the expertise the framework depends onP7W1 open text · reviewer packet 1

The candidate eighth principle — close the loop, the project chair's candidate — was voted on in the cycle-3 coverage question (6–3 to keep) and withdrawn by the project chair at the freeze; its record, text and evidence are in B2, and its instrument (the outcome record) is mandatory in C1.

AI-use statement (long form)

This framework was produced in an AI-native project that governed its own AI use under the boundary it describes. The project's governed agent operated at Recommend / draft-only against a registered boundary profile: it drafted text, analyses, minutes and instrument content; it did not publish, commit or send anything. The governed agent's every action was logged in an append-only ledger with a cost record; the ledger is summarised below, and it governs that agent, not the whole of the project's AI use — AI-assisted drafting also ran in the project chair's own tools, outside the ledger, committed under his identity and standing only once he had reviewed and adopted it. A named human — the project chair — reviewed and adopted every artefact, and the working group judged every draft. Figures were verified against the source results files in fact-check passes; reading rules (A3) bound every use. Where the AI's drafting was wrong — two boundary-test questions in cycle 2, one misread stop condition, and the cross-reference defects found and corrected at the freeze (errata above) — the working group caught it and the record says so. The project's own instruments were not exempt: the cycle-1 finding that an unreasoned "keep" is indistinguishable from a rubber stamp was applied to the project's cycle-2 and cycle-3 forms.

Asset Zero boundary telemetry

From the Governor's ledger, as at 28 Aug 2026 — its window at the freeze pass. The governed agent's action ledger — the project's own worked example of C1, scoped as stated above — holds 25 entries (9–28 Aug 2026), all at boundary level L3 (Recommend / draft-only) under boundary profile v0.1 (versions 0.1.0 → 0.1.1; signed, sole signatory the project chair): 24 allowed drafting and synthesis actions, 1 denied — the chain's first entry is the gate refusing an unauthenticated chat request ("invalid or missing relay token") — 0 approved-level and 0 autonomous actions, 0 incidents, and US$0.10 of spend against the US$450 monthly cap. Denials are data: the ledger's first line is the gate saying no. The live chain, with hashes, is published on the project site's progress page.

Provenance. Drafted by AI (Stream 1) from: the credit one-pager · the cycle exports and logs · the Governor's boundary profile and ledger. Reviewed: cycle-3 last call — 9 of record: 9 yes · 0 objections; one comment led to an errata fix (the closing figure claim honestly scoped — D4, and the errata log above exists because of that audit). Consensus: unanimous. Signed off: the project chair, 31 Aug 2026. Status: Frozen v1.0. Last updated: 31 Aug 2026.

Provenance of v1.0: AI-drafted (Stream 1) from the cycle drafts, disposition records, call minutes, the Series Evidence Synthesis and the capstone brief; ratified unanimously by the working group in the cycle-3 last call (27 Aug 2026); freeze-pass errata logged in D4; every core figure carries its n or names its source file. Confidentiality: no volunteer is named against an answer; the two cycle-1 cases not opted into the case library are not quoted. Signed: Kai Dong, Project Chair, Asset Management Council — 31 August 2026. The living framework: projects.amcouncil.com.au/human-ai-boundary · The Asset Management Council: www.amcouncil.com.au

Closed by Kai Dong · 2026-08-30

D4 — Provenance appendix

Evidence base: 663 + 524 + 625+28 + 956 = 2,796 recorded responses · four webinars, June–July 2026.

AskCycleVolunteers answered
Confirm your part in August (RSVP + hours)015
MA1 — Judge each principle, and pick the structure111
MA2 — Break one principle110
MA3 — The missing principle110
Reviewer packet 1 — "The Confident Wrong Answer"16
B3 — Decision Rights Matrix review211
B4 — Apply the boundary test211
B5 — Envelopes, trigger and stop211
Final pass — the eighth-principle question39
Final pass — the whole-document last call39
Final pass — rank the Recommendations for Members39
Where should the next iteration go?42
Volunteer for the next iteration (v1.x)45

21 disposition rows adopted — every volunteer input answered in writing, signed per row. The full logs render on each closed section and export per cycle. The project’s own AI ran under pre-registered boundary levels; its action ledger is public at /progress.

AI synthesises the community's 2,796 responses, drafts sections with line-by-line provenance, and compiles the disposition logs. Humans set direction, judge content, run the calls, sign the sections and own the outcome. The project itself runs under the framework it is producing: the AI's permissions are declared in advance, every action and refusal is logged, and the log is published. A full AI-use statement appears in the framework's front matter.

© Asset Management Council — community-developed guidance carrying the community’s authority, not a formal standard. Print this page for the citable PDF.