You added a human. You didn't add a standard.
Every AI workflow has an approve button now. Almost none of them tell the person clicking it what they are checking against.
Somebody at your company approved an AI-drafted answer this week.
Ask them what they checked it against and you will get a pause. Not because they were careless. Because there was nothing to check against. They read it, it sounded right, it went to a buyer. That was the control.
Most companies live in the gap between the first number and the second. The licences got bought. The rollout was a login. Each function worked out its own relationship with the tool on its own time, and nobody wrote down what good looks like — so good became whatever the person in the seat thought it was that afternoon.
Then, sensibly, somebody added a human to the loop.
A seat is not a control
Human-in-the-loop is table stakes now. Every vendor has the checkpoint. It is the first slide in every AI-risk deck, and it is the cheapest thing in the building to install, because installing it means adding a button.
What almost nobody installed is the thing the button is supposed to enforce.
Approval without a standard is a signature, not a control.
There is evidence the seat can make things worse. In a 2026 Scientific Reports study (n = 295), participants who always used the AI guidance they were given scored 67%; those who ignored it scored 75%. The people most positively disposed toward AI did worst. That was a lab task, not a security questionnaire, and I am not going to stretch it into a business claim. But the direction is worth sitting with: a checkpoint is only ever worth what the checker brings to it, and enthusiasm is not it.
Five questions the reviewer usually cannot answer
Take the answer your team is about to send and put the reviewer’s actual job in front of them:
Which document did this come from, and is that the one we stand behind?
Not who sent it. Who owns this domain and put their name on this position?
If a buyer’s auditor asks in fourteen months, what do we show them?
When was the underlying fact last confirmed, and by whom?
Did we tell a different buyer something different last quarter?
A reviewer with answers to those five is running a control. A reviewer without them is proofreading. Both look identical in the workflow diagram, and only one of them is doing anything.
This is why use AI where it is strongest is a governance sentence, not a productivity one. AI is excellent at high-volume, repeatable, checkable work — drafting from approved material, comparing four hundred answers against each other, flagging the ones that disagree. It is worst exactly where companies most want to point it: producing a position nobody has decided yet. The failure is not the model inventing something. It is the model fluently filling a gap a human was supposed to close, well enough that nobody notices the decision was never made.
The customer can tell
None of this stays internal. The moment AI-assisted content crosses to the buyer, two failures show up, and they are not the same failure.
Inaccurate is the one everyone plans for. It is also the recoverable one — you correct it, and a vendor who proactively corrects itself reads as governed.
Inauthentic is the one nobody plans for, and it does quieter damage. Fluent, generic, competent, and clearly not written by anyone who understands this buyer’s situation. Nobody writes back to tell you. They just move you into a mental category, and you never learn which one. In a regulated evaluation — where the same reader is scoring six vendors on how seriously each takes their own commitments — that category is expensive.
The rule I would hold: AI drafts from what you have already decided. A person owns anything the buyer will read as a promise.
One governed layer, many readers
Here is the part that makes it a system rather than a policy.
Your tools are better at this than people assume. Answer expiry, an approver of record, conflict detection inside a library — those ship as features now. If you have a modern response platform, open the admin panel; a good deal of what a consultant might try to sell you as governance is a settings page you already own.
Your response tool governs its own library. Nobody governs the response function.
That is the boundary every one of those features dies at. The same fact is claimed in four places — the CRM, the response library, the quote, the scoping document — plus a Slack thread and a solutions engineer’s head, which are in no tool at all. Four teams maintain those four systems and have never compared notes. Each system is doing its job correctly. No layer underneath them is asking whether they agree.
That layer is where AI earns its keep instead of adding risk, because volume and comparison are the two things it is genuinely best at: run the consistency check across systems, surface the disagreements, route each one to the named human who owns that domain. What comes out is a set of facts that sales, delivery, security and finance can all draw from — because a person decided each one, once, and it carries a date.
To be exact about the boundary: I govern the answer, not the model. No GxP, no computer-system validation — that is a different discipline and a different vendor.
The check to run this week
Pull the last AI-assisted answer your team sent a buyer. Ask the person who approved it the five questions above.
If they can answer two, you have a checkpoint. If they can answer five, you have a control. Most teams find out which one they have the first time somebody asks.
Related: The approval that took four days · Two buyers. Same question. Two answers.