A framework for using AI responsibly has to live in three layers at once. The failures happen in the layer almost nobody is managing.
Last post I argued the two easy answers — "the vendor handles safety" and "we'll train our people" — both fail because each assumes the framework lives somewhere else. Here's a structure that doesn't.
Picture three layers.
The systems layer: what the model's makers build and constrain. This is where the universal, non-negotiable limits belong — the ones no user should be able to switch off. It's necessary, and it's not yours to control.
The local layer: the judgment of the person at the keyboard in a specific moment. This is where genuine context lives — the tone for this client, the nuance of this situation. No central rule could anticipate it. Also necessary, also not something you can fully systematize.
And the organizational layer — the middle. This is the layer your business actually owns, and it's the one most companies are skipping entirely.
The middle layer is where the decisions you can actually make live. What is this tool allowed to touch? What output needs a human check before it goes anywhere? Where does "the AI suggested it" stop being an acceptable answer? You can't rewrite the model. You can't make every employee a saint on a Tuesday afternoon. But you can decide these things — deliberately, in advance, in writing.
If you have an engineering background, this is just defense in depth. You never put every safeguard in one place. Some lives in the hardware, some in the procedures, some in the operator's training and discretion. A plant that relied solely on foolproof equipment — or solely on an operator who never errs — would be badly designed. Same logic here. The skill isn't picking a layer. It's knowing which decisions belong at which one.
I'll be honest about the limits here — this series has been about not pretending to more certainty than I have. How much to enforce at the model layer versus leave to the people deploying it is genuinely unsettled, tangled up with liability, regulation, and competitive pressure none of us have clean answers to yet. So I'm not offering you the correct allocation. I'm offering a way to see the layers, so you stop hoping someone else is handling the part that's actually yours.
Which brings me back to where I started this series. Is it too late?
No. Asimov saw the danger before the machines existed, and used fiction to show that no clean set of rules survives contact with the real world. He was right about both. The danger is here, the framework is unfinished, and the honest truth is that finishing it isn't something we get to outsource — not to the vendors, not to the technology, not to the person at the next desk.
It lives at every layer. Including yours.
Where does your operation actually stand?
The AI Operational Readiness Assessment asks about the foundation underneath the tools: how work is documented, who the operation depends on, and what happens when something goes wrong. Roughly 30 questions, free, and you get the analysis.
Take the assessment