Change control for enterprise AI
Your AI believes things nobody approved.
People no longer open the policy. They ask the assistant, and they act on the answer. That answer is now load-bearing, and nothing governs when it is allowed to change.
AME is change control for what your AI believes. A belief cannot change until it survives challenge, meets an evidence threshold, and leaves an audit trail.
BROKEN MODEL vs WORKING MODEL
The thesis
Most AI failures are not model failures. They are belief failures.
- In the last two years your organization stopped retrieving documents and started consuming beliefs. People act on what the assistant says, not on what the document says.
- Every other load-bearing artifact has change control. Code has review. Documents have versioning. Financial data has reconciliation. The beliefs your AI serves have none.
- The failure is not hallucination, which everyone watches for. It is confident assertion of superseded truth, which nobody watches for, because the answer was correct when it was written.
- The fix is a control layer above whatever your AI reads: no belief changes without surviving challenge, meeting an evidence threshold, and leaving a trail.
The operating layer · six stages
Every signal earns its place in active state.
Captured. Not trusted.
- Every artifact fingerprinted on capture
- Screened for prompt injection before anything downstream reads it
- Nothing enters active use by default
- Origin and boundary recorded for every artifact
Weigh the source.
- Every source assigned a weight; not all sources carry equal say
- Injection risk labeled: none, low, medium, high
- Reliability tracked over time, not assumed
- Signed sources separated from unsigned
Context with provenance.
- Evidence assembled around the question, not loose fragments
- Every excerpt carries its source and its weight
- Contradicting evidence travels with supporting evidence
- The model reads context; it cannot rewrite it
Changes are contested before they take effect.
- Triggered by staleness, contradiction, or impact
- The case for keeping and the case for changing are both argued
- Supporting and opposing evidence weighed together
- Ruling recorded: confirmed, revised, retracted, or held for review
Rules in code, not prompts.
- Every state change checked against thresholds before it lands
- Changes require corroboration from independent sources that meet the threshold
- Caps on how much a single update is allowed to change
- Human approval required on high-impact changes
Every change on the record.
- A permanent record of every change, with justification and sources
- Current state can be rebuilt from the record and checked against it
- Every belief carries a review-by date; nothing is permanent by default
- Every answer traces back to who approved what, and when
A procurement tool
Six questions before trusting an AI output.
The belief audit
How often is your assistant confidently wrong?
Your AI assistant is confidently telling people things that are no longer true. You have no way to know how often, no way to stop it, and no record of who approved what it believes.
In three weeks, for a fixed fee, we will tell you exactly how often, show you the specific answers, and leave you a remediation map. Whether or not you ever buy anything from us.
Ask about the belief auditFor CIOs, AI risk officers, and data leaders
Request a briefing.
A structural walkthrough of the control layer, mapped to your stack. No demo theater.