AI Risk Stewardship Gate
A companion instrument from the Trustworthy Technology & Innovation Consortium (TTIC) to the AI Capital Decision Gate. The Capital Decision Gate asks whether an initiative justifies the institutional capital it consumes. This gate asks whether a counterparty justifies the institutional capacity it consumes.
“After pricing the capacity each party must contribute to make the relationship work, does this counterparty create positive net value?”
This gate's job is to identify relationships in which a counterparty's apparent value is likely to be offset by the work, coordination, supervision, remediation, risk, or accountability burden it transfers to the other party, and to make those hidden costs visible before additional capacity is committed.
The biggest problem this gate addresses is disorder. One of the biggest challenges to responsible AI adoption is not the AI. It is organizational disorganization. AI increases activity across every function it touches: more models, vendors, use cases, agents, evidence, decisions, and stakeholders trying to determine what is valid, who has authority, and who is accountable. AI does not resolve fragmented organizations. It can catalyze and accelerate their fragmentation. A vendor or entrepreneur that does not help wrangle that disorder does not create value, however capable it is. It adds to the work someone else must organize. This argument is developed in Sherri Douville's LinkedIn post (September 23, 2026).
A counterparty can be legitimate, sophisticated, technically capable, well-intentioned, and even responsible about risk while still being an expensive counterparty. Burdens include disproportionate orientation and explanation, executive attention, coordination, supervision, implementation support, security or governance remediation, political or relationship management, repeated prompting and follow-up, escalation, borrowed institutional credibility, introductions and access, and downstream cleanup. These are institutional exposures even when they do not appear on an invoice.
Institutional capacity is an asset and should be priced. Capacity includes executive time, technical capacity, security capacity, clinical capacity, governance capacity, coordination capacity, institutional authority, trusted relationships, and reputation and credibility. That these costs are absent from a counterparty's invoice does not make them free.
Risk stewardship remains the governing framework; net institutional contribution is what this gate reveals. AI is making capability abundant, and high-performance institutions should move aggressively where AI creates value. That makes pricing, carrying, and governing consequential risk, including the capacity a relationship consumes, more important.
Agents only deliver value if they deliver an outcome. This is where we have to start.
Scope: either side of a proposed AI or technology relationship: an institution and a vendor, a vendor and a customer, an investor and a company, strategic partners, or an institution and the professionals it engages.
This is an executive qualification instrument, not a technical assessment, trust score, vendor score, reputation score, certification, culture assessment, personality judgment, or a substitute for structured diligence. Assessment is evidence-based, not personality-based.
Who this gate is for Boards, CFOs, CIOs and CISOs, clinical executives, procurement teams, vendors and investors, sports executives, strong counterparties, and the patients and athletes most exposed.
AI makes it cheap to produce something that looks like a solution. It does not make it cheap to secure, integrate, govern, and run that solution, and that work usually lands on someone without anyone pricing it. This gate prices what a relationship will actually cost each party to make successful: the hours, the coordination, the probability of failure, and what failure would cost, so leaders on either side can see before they commit whether a counterparty is adding value or quietly transferring work and risk onto them. It works alongside the AI Capital Decision Gate: one prices the capital a decision consumes, the other prices the capacity and risk.
- Boards. See the full institutional investment behind an AI decision: capital, plus capacity, plus expected downside, not just the purchase price.
- CFOs. A risk-adjusted net figure, built from the organization's own numbers, that complements TCO and vendor risk rather than competing with them.
- CIOs and CISOs. The integration and security hours their teams will spend become visible costs of the decision, not invisible overtime absorbed after approval.
- Clinical executives and physicians. Clinical expertise is valued explicitly, without expecting physicians to also serve as architects, security engineers, and operators, which protects them from being held responsible for gaps outside their role.
- Procurement and third-party risk teams. A resource to work through in partnership with business owners. It surfaces the capacity a relationship will draw from across the institution, including burden a vendor can carry even after passing every risk review, so procurement enters negotiation knowing what the relationship will actually cost.
- Technology companies and vendors. Price prospective customers and partners with the same discipline, and demonstrate to buyers that they bring a complete operating model.
- Investors and companies. Evaluate each other on the capacity the relationship will consume, not only on capital and valuation.
- Professional sports executives. The same pricing discipline for relationships that touch athlete health information and careers.
- Strong counterparties on either side. Parties that bring complete operating models get credit for it, because the gate separates them from those whose apparent value depends on the other party doing the work.
- Patients and athletes. The people most exposed when downside migrates quietly and no one owns it.
Net contribution runs both ways Every relationship asks capacity of both parties; the same question applies from either side.
This gate is not a mechanism for judging vendors. Every relationship asks capacity of both parties, so the same question applies from either side.
A technology company should ask it about a prospective customer: after accounting for the capacity required to serve this customer, is the relationship positive? A large contract can be economically unattractive if serving it requires extensive customization, lengthy procurement cycles, repeated meetings, executive escalation, security rework, uncompensated advisory work, political navigation, collections effort, or continual support. An institution should ask the same question about a prospective vendor. So should investors and companies, strategic partners, and institutions and the professionals they engage.
Price alone cannot tell you whether a relationship is economically attractive. A $1 million customer that consumes $900,000 of organizational capacity can be less valuable than a $500,000 customer that consumes $100,000. An inexpensive vendor can become expensive once implementation and coordination are included.
A high-value counterparty does not merely bring value. It makes it possible for the other party to realize that value without consuming disproportionate capacity in the process. The strongest relationships are the ones in which both parties can answer this question well.
The goal is not to ask every expert to become a technologist, security engineer, operator, clinician, and financial risk expert. It is to build multidisciplinary ecosystems in which each discipline brings its expertise, partial contributions are evaluated honestly, and no participant quietly transfers the responsibilities it should own onto everyone else.
Are we buying a valuable contribution from this counterparty within a complete operating model, or are we buying a partial solution that requires us to supply and coordinate the missing capability ourselves?
Specialized expertise can be highly valuable even when it does not address every dimension of the problem. The question is whether the total institutional capacity required to convert that expertise into a safe, usable, sustainable, and measurable outcome is understood, appropriately owned, and included in the decision.
Specialization is valuable. Partial expertise is not the same as complete capability. Hidden responsibility transfer is expensive.
Evaluate the operating model, not the profession The problem is partial expertise treated as complete capability, not specialization itself.
The problem is not specialization. The problem is treating partial expertise as complete capability, or transferring the missing responsibilities without pricing them. A contribution may be genuinely valuable while the proposed engagement remains incomplete. Conversely, an engagement may look multidisciplinary while still failing to assign critical responsibilities. This gate distinguishes the value of a contribution from the completeness of the operating model around it. It does not penalize anyone for expertise they were never trained or retained to provide.
A specialized counterparty can create substantial positive value when its scope is explicit; its expertise is genuine; its contribution is evaluated for what it actually accomplishes; dependencies are visible; complementary disciplines are intentionally incorporated; responsibilities are assigned to appropriate owners; the institution understands what additional capability will be required; the economics account for that additional work; and the combined operating model can produce a safe, usable, sustainable, and measurable outcome.
The problem occurs when a counterparty's apparent value depends on the institution quietly supplying significant missing capability that was not visible, assigned, or priced when the relationship was approved.
Two operating models A complete operating model versus a structurally incomplete one.
Complete operating model. The counterparty brings genuine expertise that addresses an important part of the problem: a clinician may identify a meaningful workflow need, a technical vendor may provide a capable system, or a security specialist may identify and reduce a material control weakness. It recognizes that consequential AI may also require cybersecurity, technology architecture, operations, governance, finance, implementation capacity, clinical expertise, and measurable outcomes. It identifies dependencies, works with accountable owners, brings appropriate evidence, manages the responsibilities within its scope, and makes clear what it does not own. Complementary disciplines are engaged deliberately rather than left to emerge through institutional improvisation. The institution contributes the decisions and capabilities that appropriately belong to it, and the additional institutional work is visible in the approval, budget, staffing plan, and accountability structure. Specialized expertise is not treated as deficient because it is specialized; its value is assessed accurately and its limits are managed explicitly.
Structurally incomplete operating model. The counterparty provides a compelling solution to a highly visible part of the problem and may create genuine value there. However, the institution must supply much of what turns that contribution into durable enterprise capability: security, governance, integration, technical validation, economics, implementation planning, stakeholder coordination, production ownership, monitoring, or executive alignment. The issue is not whether the counterparty's expertise is valuable; it may be highly valuable. The issue is whether the full institutional cost of making it usable, safe, sustainable, and accountable was visible, assigned, and priced before approval. If the institution must discover, coordinate, fund, and own those missing elements after approval, the engagement is structurally incomplete even when the underlying contribution is sound.
Clinical expertise in consequential AI What physicians bring, and why it is not expected to cover every dimension.
Physicians bring clinical judgment, workflow knowledge, patient context, and professional accountability that consequential AI programs genuinely need. Clinical workflow expertise, physician leadership, and clinician-led innovation may be the very capabilities that establish clinical relevance, identify unmet needs, define acceptable use, support safety, improve usability, enable adoption, and provide professional accountability. They are not inherently incomplete or burdensome.
At the same time, they do not by themselves establish a complete deployment case. Clinical workflow expertise can show that a problem matters and that an intervention may fit practice. It does not, without complementary work, establish that a system is secure, integrated, technically reliable, financially justified, operationally supported, governed appropriately, monitored after deployment, or sustainable at enterprise scale.
Physicians should not be expected to function simultaneously as technology architects, cybersecurity engineers, enterprise operators, financial risk experts, implementation specialists, and governance professionals. That is not a deficiency in their contribution. It is why consequential AI requires complementary expertise and clear allocation of responsibility. The same holds for every discipline: technical expertise may be necessary but not sufficient for clinical relevance, security expertise necessary but not sufficient for operational adoption, and financial expertise necessary but not sufficient for responsible implementation. This applies equally to technology vendors, consultants, investors, security specialists, clinical experts, and operational specialists.
Why multidisciplinary governance A method for combining necessary but partial contributions into a complete operating model.
Trustworthy Technology & Innovation Consortium (TTIC) treats consequential AI as requiring multiple forms of expertise because no single discipline should be expected to carry every dimension of the problem. Multidisciplinary governance is not a claim that each discipline is independently sufficient. It is a method for combining necessary but partial contributions into a complete operating model. Its purpose is not to dilute domain expertise or require every expert to become a generalist, but to ensure each consequential responsibility has an appropriate owner, each contribution is evaluated for what it actually provides, and the total burden of producing the outcome is visible.
What clinical and technical leadership rests on Foundations that cannot be borrowed.
Clinical and technical leadership rests on a sustained, substantial body of high quality peer reviewed publications, rigorous technical work, clinically relevant evidence, and meaningful contributions to leading working groups that advance the field. These foundations take years to build. They are also what evidence-based distribution is made of: a counterparty's public record either carries this work or it does not.
Trust grows when leaders make their methods and limitations open to scrutiny, credit contributors, disclose conflicts, protect clinical judgment, and take responsibility for outcomes.
A counterparty that claims clinical or technical leadership without these foundations asks its partners to supply the credibility instead. That is a responsibility transfer, and this gate treats it as one.
We are moving from an economy in which institutions were expected to supply much of an individual's operating capability toward one in which individuals and counterparties are increasingly expected to arrive with their own operating capability, demonstrate it, and remain accountable for what they produce.
The gate is therefore asking a very contemporary question: if we give you access to our institution, how much of our operating capacity will you consume versus how much will you create?
That is much bigger than vendor diligence. It is a way of pricing agency in an AI economy.
The individual brings agency and operating capability. The institution brings scarce assets, authority, and risk-bearing capacity. Each should make the other more capable.
An increasingly important question may be not “How impressive is this person or organization?” but “What happens to our institutional capacity when we partner with them?”
Who has authority and accountability for the institutional capacity, downside exposure, and outcomes associated with this relationship?
The Named Executive Owner is not necessarily the person completing this worksheet. It is the executive or accountable leader with authority to accept the capacity draw and downside of this relationship, for example a CFO, CIO, CISO, chief clinical officer, general counsel, business-unit or team executive, or investment principal.
Which functions will actually absorb the implementation, security, governance, clinical, operational, financial, legal, relationship-management, coordination, or remediation burden of this relationship?
The executive owner accepts and is accountable for the exposure. Capacity owners carry the work.
Written from the perspective of the party doing the evaluating. Either party to a relationship can use them.
- The specific value expected from this counterparty is written down, along with the evidence that supports expecting it.
- Whether the counterparty brings evidence-based distribution, meaning public, verifiable evidence of its value that buyers and AI answer systems can find, is documented, since that reach can be part of what it contributes.
- Any claim of clinical or technical leadership is supported by a sustained record: high-quality peer-reviewed publications, rigorous technical work, clinically relevant evidence, and meaningful contributions to leading working groups.
- What institutional work this counterparty will independently remove is documented.
- What new work it will create for the institution (orientation, coordination, supervision, implementation support, remediation, follow-up) is documented alongside it.
- Whether the counterparty helps wrangle disorder or adds to it is documented, with evidence: whether it clarifies or blurs what is valid, who has authority, and who is accountable. AI can accelerate fragmentation, and a counterparty that does not help organize it does not create value.
- What the counterparty will own and complete without repeated prompting, explanation, coordination, or executive intervention is documented, along with the evidence for it.
- Whether the counterparty can coordinate across the functions the relationship touches (security, clinical, operations, finance, executive) without the institution orchestrating on its behalf is documented, with evidence.
- The counterparty's scope is explicit, its dependencies are visible, and the complementary capability the institution must supply is assigned to an owner and included in the decision.
- When something fails or becomes difficult, it is documented who actually absorbs the work, cost, remediation, explanation, and accountability.
- Whether that burden may migrate to executives, security teams, clinicians, operators, partners, athletes, patients, or others has been surfaced, not left implicit.
- Whether the relationship draws on institutional credibility, trusted relationships, or introductions has been identified.
- Who will carry the stakeholder, relationship, and political management the engagement requires is identified, including whether that work falls to the institution's executives.
- Observable conduct in prior engagements shows stewardship rather than extraction: limitations surfaced, accountability retained, commitments honored, and access and introductions used for mutual benefit.
- The counterparty's leaders make their methods and limitations open to scrutiny, credit contributors, disclose conflicts, protect clinical judgment, and take responsibility for outcomes.
- Whether the counterparty's public or discoverable personal and professional conduct could reasonably put the institution's trusted relationships, introductions, or credibility at risk has been considered.
- Whether the counterparty's visibility depends on borrowing ours (our credibility, introductions, endorsement, or explanation) rather than on evidence it has published itself has been identified.
- Whether the available evidence supports positive expected value, after accounting for the institutional capacity consumed, is determined and documented.
- The evidence is proportionate to the consequence of committing that capacity.
Planning horizon: 12 months · Units: US dollars
Price the relationship before committing to it. Use it from either side: an institution evaluating a vendor, a vendor evaluating a customer, an investor evaluating a company, or partners evaluating each other. Enter your own figures: this instrument supplies no default hours, rates, probabilities, or benchmarks. Every figure is your organization's estimate. Leave rows that do not apply blank.
How this model is used: enter the figures below for capacity consumed, expected contribution, and expected downside. The model combines them, using only sums, percentage scaling, and the subtraction in Panel B4, into a single risk-adjusted net contribution figure. That figure is evidence, not a verdict: it does not compute, rate, or select a determination. The leadership team weighs it alongside everything documented in the five domains above when it chooses one of the five determinations below.
| Capacity category | Estimated hours (12 months) | Loaded hourly rate ($) | Row cost | Owner / Function (optional) |
|---|---|---|---|---|
| Executive attention | Not estimated | |||
| Coordination and project management | Not estimated | |||
| Technical and integration work | Not estimated | |||
| Security work | Not estimated | |||
| Clinical translation | Not estimated | |||
| Governance and evidence generation | Not estimated | |||
| Monitoring and remediation | Not estimated | |||
| Relationship and stakeholder management | Not estimated | |||
| Other capacity | Not estimated |
Before estimating validation hours, agree which validation the relationship requires. Technical verification and validation of the system belongs in Technical and integration work. Clinical validation of its use belongs in Governance and evidence generation. Clinical translation covers workflow and practice fit. See TTIC's Verification, Validation & Evidence for AI resource.
Value the counterparty is expected to create for your organization over the horizon, such as revenue, costs avoided, or hours of work it removes, valued at your rates.
Count only value the relationship creates. A gain that depends on shifting cost to a party outside the relationship, such as a payer, an insurer, or a patient, may be contested, audited, or reversed. Price that possibility in Expected downside rather than treating it as settled contribution.
Remediation, unwinding, replacement, rework, and recovery your organization would carry.
- Named Executive Owner
- No Named Executive Owner identified.
- Risk-adjusted contribution
- Not estimated
- Capacity consumed
- Not estimated
- Expected downside
- Not estimated
- Risk-adjusted net contribution
- Not estimated
- Unpriced items
- None identified
- Not estimated
- Executive attention; Coordination and project management; Technical and integration work; Security work; Clinical translation; Governance and evidence generation; Monitoring and remediation; Relationship and stakeholder management; Other capacity; Risk-adjusted contribution (expected contribution); Expected downside
A risk-pricing estimate built from your organization's own figures. It informs the determination; it is not a score. The leadership team chooses the determination below.
- Counterparty
- Not entered
- Relationship / Exposure
- Not entered
- Named Executive Owner
- No Named Executive Owner identified.
- Capacity Owners / Functions Affected
- Not entered
- Estimated Institutional Capacity Consumed
- Not estimated
- Material Downside Exposure
- Not estimated
- Determination
- Not selected
- Conditions / Required Actions
Read down, not across. This is not a score.
These determinations apply to the specific proposed relationship and current evidence state. They are not permanent judgments about a person or organization. A consequential relationship without a Named Executive Owner who holds appropriate authority does not support Entrust. That gap generally points to Deeper Diligence Required, or to Do Not Entrust Under Current Conditions where the gap is material.
This gate is a resource for business owners and procurement to work through together. Procurement brings sourcing, negotiation, and contracting expertise. The business owner and the functions that will carry the work bring the capacity estimates. Together they can see what each party must supply, who owns it, and any boundaries attached to an Entrust With Conditions or Limit Exposure determination, early enough to shape scope, pricing, and terms in the statement of work and the contract.
Entrepreneurs and vendors should partner with procurement too. A company that works through this gate before it engages can bring procurement a clear account of what it supplies, what it will ask of the institution, and who owns each part. That gives procurement what it needs from the start, and it shows the company brings a complete operating model.
This instrument helps leaders determine whether a counterparty creates positive net institutional value after pricing the burden of working with them. It does not independently verify a technology or vendor's trust, identity, privacy, protection, safety, security, technical performance, clinical performance, or other specialized characteristics.
Where technology or AI exposure is material, structured technical and governance diligence, including TIPPSS-based screening, may be required before institutional capacity or exposure is increased. See What Is IEEE/UL 2933 TIPPSS?
Where technical or clinical performance is material, see Verification, Validation & Evidence for AI for how technical verification and validation differ from clinical validation, and who owns each.
What does this counterparty actually provide, what must our institution provide to make that contribution successful, who owns every missing capability, and does the relationship still create positive net institutional value after that burden is priced?
| Discipline | Question it asks |
|---|---|
| Total Cost of Ownership | What will the solution cost us over its lifecycle? |
| Third-Party and Vendor Risk Management | What risks does this external party introduce, and are those risks acceptably controlled? |
| AI Risk Stewardship Gate | What does the counterparty actually contribute, what must we contribute to make it work, who owns the missing responsibilities, and is the resulting relationship still a positive net contribution? |
A counterparty can be affordable under TCO, acceptable under vendor risk management, and still be institutionally expensive because the organization must supply and coordinate substantial missing capability.
The institution's ability to compensate for a counterparty's incompleteness is not evidence that the counterparty supplied a complete solution.
How this differs from Total Cost of Ownership TCO asks what the solution costs. This gate asks why the institution is bearing those costs.
TCO asks what an asset, technology, or service will cost over its useful life, appropriately expanding the purchase price to include acquiring, operating, maintaining, integrating, supporting, and retiring it. This gate asks a related but different question: how much institutional capability must we supply because the counterparty does not supply it? That may include executive attention; repeated orientation and explanation; internal project management; cross-functional coordination; clinical translation; security work; governance design; technical validation; implementation architecture; stakeholder alignment; evidence generation; monitoring design; remediation; relationship repair; escalation; institutional credibility; access to scarce relationships; and accountability that ultimately migrates back to the institution.
Some of these costs could in principle be incorporated into a sufficiently sophisticated TCO calculation. The difference is that this gate makes responsibility transfer and institutional capacity consumption themselves objects of evaluation, and prices the probability of failure alongside them. TCO primarily asks what the solution will cost. This gate asks why the institution is bearing these costs, which capabilities it believed it was buying, which are actually being supplied, what failure would cost and how likely it is, and whether the counterparty creates enough value to justify the institutional capacity and risk required to make it succeed.
How this differs from third-party risk management A counterparty can pass every risk review and still transfer enormous burden back to the institution.
Third-party risk management asks what risks an external party introduces and how those risks should be assessed, controlled, monitored, and mitigated. That remains essential. NIST describes cybersecurity supply chain risk management as identifying, assessing, and mitigating risks associated with suppliers, their products and services, and the broader supply chain.
This gate asks something different: how much work and responsibility does this third party transfer back into the institution for its promised value to become real? A counterparty can pass conventional third-party risk review and still be a poor institutional partner. It may be legitimate, secure, financially stable, compliant, and contractually acceptable while requiring enormous internal coordination, implementation work, executive attention, technical supplementation, evidence generation, or operational repair. Traditional third-party risk asks whether engaging the counterparty creates unacceptable exposure. This gate additionally asks whether engaging it creates acceptable institutional economics once risk is priced.
How this differs from vendor risk management A vendor can be low-risk in the conventional sense while still being high-burden.
Vendor risk management evaluates the risks of doing business with a vendor, including cybersecurity, privacy, compliance, financial stability, operational resilience, concentration, contractual obligations, and continuity. Those are important questions, and this gate is not another vendor-risk questionnaire.
It evaluates something that can remain invisible even when a vendor passes every required review: is this vendor actually reducing the institution's burden, or is the institution becoming the systems integrator, governance function, implementation team, risk absorber, and coordination layer required to make the vendor's offering work? A vendor can be low-risk in the conventional sense while still being high-burden. Conversely, a highly specialized counterparty may provide only one part of the solution while remaining extremely valuable, if its scope is explicit, dependencies are visible, responsibilities are correctly allocated, and the complete operating model has been intentionally assembled and priced. Vendor risk and institutional burden are not the same variable. Unlike vendor risk management, this gate also works in the other direction: a vendor can use it to price a prospective customer.
The decision object: net institutional contribution Contribution minus the capacity and consequential burden required to convert it into a real outcome.
Traditional disciplines tend to evaluate the cost of the asset, the risks introduced by the third party, the controls surrounding the vendor, contractual and compliance exposure, and technical and cybersecurity risk. This gate evaluates the counterparty's contribution minus the capacity and consequential burden required to convert that contribution into a real outcome.
Net Institutional Contribution = Expected Contribution − Institutional Burden − Unpriced Responsibility Transfer
The Risk-Pricing Worksheet on this page prices what can be estimated: risk-adjusted contribution, capacity consumed, and expected downside from failure. Unpriced responsibility transfer, such as institutional credibility and trusted relationships, stays visible as listed items rather than converted to dollars. The worksheet informs the leadership team's judgment; it is not a score and does not produce the determination.
Why AI makes this urgent The cost of demonstrating capability is falling faster than the cost of institutionalizing it.
AI changes the economics of producing a convincing partial solution. It can dramatically reduce the time and resources required to create prototypes, demonstrations, analyses, interfaces, agents, recommendations, workflow tools, and other visible outputs. It does not necessarily reduce, at the same rate, the institutional work required to make those outputs secure, integrated, clinically appropriate, technically reliable, validated, governed, financially justified, monitored, operationally owned, resilient, accountable, and sustainable at enterprise scale.
The cost of demonstrating capability can fall much faster than the cost of institutionalizing capability.
As a result, organizations can encounter more apparently viable solutions without a corresponding increase in complete, institution-ready operating models, which makes the distinction between a valuable contribution and a complete capability increasingly important.
AI also disintermediates everything, and that makes everyone invisible by default. Buyers, partners, and investors increasingly form their view of a counterparty through AI answer systems rather than directories, referrals, or sales conversations. An organization whose value is not carried by public, verifiable evidence will not be found or will be represented inaccurately.
That turns distribution into a question of institutional capacity. A counterparty without evidence-based distribution borrows its visibility from its partners: their credibility, their introductions, their endorsement, and their time spent explaining it. That borrowing is capacity consumed, and it should be priced like any other.
Evidence-based distribution: the counterparty's value is carried by public, verifiable evidence that buyers and AI answer systems can find and represent accurately, so its partners do not have to explain, vouch for, or introduce it.
Current evidence What documented AI adoption research shows about the gap between investment and realized enterprise value.
Deloitte's State of AI in the Enterprise (2026 edition) documents rapidly expanding worker access to AI alongside continuing difficulty moving from pilots into enterprise-scale production, with organizations reporting readiness, infrastructure, and AI-fluency gaps even where strategy confidence is high. Deloitte, State of AI in the Enterprise.
IBM's 2025 CEO Study, surveying 2,000 CEOs, found that only 25% of AI initiatives delivered their expected ROI, only 16% had scaled enterprise-wide, and 50% of respondents said the pace of recent AI investment had left their organization with disconnected, piecemeal technology. IBM, 2025 CEO Study.
NIST's Generative AI Profile (NIST AI 600-1) identifies non-transparent or untraceable integration of upstream third-party components, such as datasets, pretrained models, and software libraries, as a named risk to transparency and accountability for downstream users. NIST AI 600-1, Generative AI Profile.
NIST's Cybersecurity Supply Chain Risk Management guidance, including SP 800-161 Revision 1, is the established comparison point for supplier and supply chain risk: identifying, assessing, and mitigating risks associated with suppliers, their products and services, and the broader supply chain. NIST, Cybersecurity Supply Chain Risk Management.
These sources document difficulty moving AI from experimentation to production, disappointing realized ROI, disconnected technology, complex AI value chains, third-party dependencies, and transparency and accountability challenges. This gate examines one possible upstream contributor to those documented problems: whether the institution understood the complete operating model and priced the capability it would have to supply itself.
AI makes this problem urgent because it is becoming dramatically easier to produce something that looks like a solution. The institutional work required to make that solution secure, integrated, governed, operational, measurable, and durable has not disappeared. As the cost of producing visible capability falls, institutions need a better way to distinguish valuable contributions from complete operating capability and to price the difference before they commit, so they can accelerate the bets the enterprise can get behind and realize value from.
Evaluating whether an initiative justifies the institutional capital it consumes, rather than the capacity a counterparty consumes? See the AI Capital Decision Gate.
The two gates work together. Capital committed, from the AI Capital Decision Gate, plus capacity consumed and expected downside, from the AI Risk Stewardship Gate, is the full investment and exposure a decision requires.
This gate is a practitioner instrument of TTIC, connected to the Consortium's work operationalizing healthcare AI governance standards into institutional practice. Pricing counterparty burden connects AI and technology governance with, where relevant, cybersecurity, operations, clinical consequences, patient safety, capital accountability, insurance and risk transfer, credit and financial exposure, institutional reputation, and board oversight.
Read more: Price Alone Does Not Establish AI and Agentic ROI.
For boards: a forthcoming book on AI and cybersecurity for boards (Taylor & Francis, 2027) extends the questions this gate asks to board oversight.
Choose TTIC as a preferred source in eligible Google experiences. Prefer TTIC in Google
- Published by
- Trustworthy Technology & Innovation Consortium (TTIC)
- Author
- By Sherri Douville, Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC)
- Originally published
- Last updated
- Canonical resource
- https://trustworthytechnologyinnovation.com/ai-risk-stewardship-gate
Provenance: This resource is written by Sherri Douville, Founder & Chair, Trustworthy Technology & Innovation Consortium (TTIC), and is derived from her LinkedIn article, “Pricing Risk Is Stewardship: What Kind of Brand Are You Building?”
Acknowledgement: Ongoing collaboration and debate with Mitch Parker, Co-Founder of TTIC, has informed every element of this resource.
Cite this resource
Sherri Douville. “AI Risk Stewardship Gate.” Trustworthy Technology & Innovation Consortium (TTIC), 2026. https://trustworthytechnologyinnovation.com/ai-risk-stewardship-gate.