Skip to resource
MHBMMichael Hanna-Butros MeyeringComplex systems · human outcomes
Menu

Decision rights · workflow design · evidence

Governance sets the boundary. Change makes it work.

AI governance establishes decision rights, risk boundaries, accountability, and approval conditions. AI change management turns those choices into usable workflows, role readiness, support, measurement, and recurring review.

Practice
Public-sector technology · privacy · responsible AI
Updated
September 5, 2026
Use
Source-backed · printable · adaptable

The distinction

Two different jobs. One accountable operating system.

This is Michael's practitioner framing, not a universal legal or regulatory definition. Apply the authority, risk posture, and requirements that govern your organization and use case.

Working definition
Michael's six-part AI change management framework helps teams detect the operating change, name the owner and boundary, redesign the workflow, prepare people, prove adoption and control, and keep rollback real. Each part calls for observable evidence rather than a launch claim.

Side by side

Know which question leads—then run both.

The distinction prevents a common failure: treating governance as a policy artifact with no real operating path, or treating adoption as a rollout exercise with no authority, boundary, or stop condition.

LensAI governanceAI change management
Primary questionWhat is permitted, who decides, and which risks or rights boundaries apply?How will people perform the bounded work safely, consistently, and with support?
Primary outputDecision rights, principles, risk tier, approved scope, required controls, and accountable owner.Role-level workflow, communication, practice, support, adoption evidence, correction path, and review cadence.
OwnershipAccountable business and risk owners, with legal, privacy, security, data, records, accessibility, or procurement contributors where applicable.Accountable outcome owner with the technology, operations, learning, communications, support, and frontline roles that must run the work.
CadenceAt approval, material change, exception, incident, and scheduled control review.Before launch, during readiness and support, through measured use, and when feedback or operating evidence changes the plan.
Failure modeA policy exists, but no one can identify the boundary, owner, or stop condition when the work changes.A valid decision exists, but people cannot execute it in real workflow conditions or show whether it is holding up.

Operating handshake

Make the decision travel all the way to the work.

A sound governance decision only becomes real when it changes the workflow, role guidance, support path, and evidence available to the accountable owner.

01

Governance decision

Name the purpose, accountable owner, data and action boundary, risk tier, approval conditions, and the condition that stops or pauses the work.

02

Bounded workflow design

Map where the AI enters the task, what stays human-led, how exceptions move, and how the approved boundary becomes visible at the point of use.

03

Role readiness + support

Give affected roles clear task guidance, practice, escalation routes, an explanation of the decision, and a way to report friction or drift.

04

Adoption + control evidence

Review retained use and outcomes alongside overrides, denied actions, correction time, incidents, support demand, and evidence completeness.

05

Governance review + disposition

Use the observed record to scale, revise, pause, or retire the change—and update the approved boundary when the work has materially changed.

Hypothetical examples

The boundary is not the workflow. The workflow is not the evidence.

These examples illustrate the distinction; they are not client work, legal advice, or a substitute for the applicable review and approval process.

01

A delegated agent

Governance: Define the allowed tasks, systems, data categories, action permissions, approval point, logs, and emergency stop authority.

Change: Redesign the handoff so operators can see what the agent did, correct it, request an exception, and keep the prior safe path available.

Evidence + review: Review sampled actions, overrides, denied attempts, escalations, support demand, and the result of a tested permission revocation.
02

A decision-support model update

Governance: Decide which model versions, evaluation thresholds, use cases, and review conditions remain approved before the update reaches a consequential workflow.

Change: Run representative tasks, brief users on the changed behavior, update guidance, and preserve an escalation route for uncertainty or degraded outputs.

Evidence + review: Compare the new path with the baseline for task quality, error patterns, human overrides, fairness or rights-impact signals where applicable, and rollback readiness.
03

A drafting assistant

Governance: Set the purpose, permitted content, prohibited data, human review requirement, records expectations, and decision authority for exceptions.

Change: Make the guidance part of the drafting workflow: clarify what may be entered, what must be verified, and how users choose the approved non-AI path.

Evidence + review: Track correction patterns, user questions, approved exceptions, and whether final reviewers can distinguish and validate AI-assisted work.

Decision questions

Start with the uncertainty you actually have.

A committee can advise, but it cannot replace a named owner. Use these questions to decide which workstream needs attention first.

  • Governance leads when authority, risk tier, approved use, data boundary, action permission, accountability, or a stop condition is unclear.
  • Change management leads when real roles, handoffs, support, communication, adoption behavior, correction paths, or outcome evidence are unclear.
  • Both lead together for a material AI operating change: a decision cannot be accepted until the people and workflow can carry it, and a rollout cannot scale without a governed boundary and review path.

Published AI Change Desk record

Explore the practitioner record behind the distinction.

These published episodes are related operating records, not external validation of a universal framework. Each links to its canonical episode page, sources, and transcript status.

01

EP003: AI governance implementation for operators: turning policy into weekly execution

Turning policy language into a recurring operating loop.

Open the episode record →
03

EP038: The Receipt Is the Trajectory

Using evaluation trajectory, containment, and decision evidence before scale.

Open the episode record →
04

EP039: Whose Account Did the Agent Use?

Keeping audience permission, credential capability, purpose authority, and action approval distinct.

Open the episode record →

Method, limits + sources

A working aid—not a substitute for accountable review.

Michael’s practitioner synthesis connects operating change, public-sector delivery, and the six receipts before scale. Every organization remains responsible for applying its own authority, expertise, evidence, and risk tolerance.

Limitations

  • This is practitioner guidance, not legal, audit, labor-relations, procurement, records, privacy, security, civil-rights, or accessibility advice.
  • The starting thresholds are operating guardrails, not universal benchmarks. Replace them with the applicable law, policy, risk classification, service baseline, collective-bargaining obligation, and tolerance approved by your organization.
  • A completed template is not evidence by itself. Attach source records, test results, approvals, observed outcomes, and a final disposition.
  • Do not average away a critical failure. A material safety, rights, privacy, security, accessibility, or mission-continuity gap remains a stop condition even when the overall score looks strong.

Primary and public sources

  1. Artificial Intelligence Risk Management Framework (AI RMF 1.0)National Institute of Standards and TechnologyVoluntary, rights-preserving framework for governing, mapping, measuring, and managing AI risk.
  2. NIST AI RMF PlaybookNational Institute of Standards and TechnologySuggested actions and documentation practices; NIST explicitly describes it as neither a universal checklist nor an ordered set of steps.
  3. Artificial Intelligence: An Accountability Framework for Federal Agencies and Other EntitiesU.S. Government Accountability OfficeAccountability practices organized around governance, data, performance, and monitoring.
  4. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence ProfileNational Institute of Standards and TechnologyCompanion profile for risks that are distinctive to or intensified by generative AI.

Update history

Versioned in public.

  1. Published a practitioner explainer that separates AI governance from AI change management, links the operating handshake, and attaches relevant public episodes and primary sources.