Governance decisions ยท Before the pilot

What AI governance controls matter before the first pilot?

Direct answer. Before the first production prompt, name an owner, write the data class, set a success metric, choose a published model id such as claude-sonnet-4-6, gpt-5-4 or gemini-3-flash, and rehearse a kill condition. Scoring v1.0 weights cost at 20 percent and privacy at 10 percent. Skipping those controls is ungoverned use, not a pilot.

Before a pilot, the risk is not a missing slide in a policy binder. The risk is a prompt that already touches production data, a tool that can write to a live system, or a success story with no stop rule. This page lists the controls that have to exist before that first real prompt. It does not repeat the standing governance page, which describes how AI is run after it is allowed. The controls here are narrower: a named owner, a written data class, a success metric, a named model id (claude-sonnet-4-6, gpt-5-4 or gemini-3-flash), and a kill condition that does not require a meeting. Scoring version v1.0 weights task at 25 percent, cost at 20 percent, context at 15 percent, and safety and privacy at 10 percent each. A pilot that ignores cost and privacy will pick a model the match engine would not. Choose the model for the pilot job from the dataset, keep affiliate status out of that choice, and do not connect write access until the stop rule has been used once in rehearsal.

A pilot is not the standing policy

Governance basics covers approved tools, data handling, review, access and escalation once AI is allowed. A first pilot fails earlier than that, usually by touching live data or a live write API before anyone has named a stop. Write the controls in this section first.

Controls that exist before the first production prompt

ControlDone when
Named ownerOne person can halt the pilot without a committee.
Data classThe prompt may use only text you have already classified as allowed.
Success metricA number you can fail, not a demo that "looked good".
Model choiceA named id from ai-comparison-2026.json, such as claude-sonnet-4-6, gpt-5-4 or gemini-3-flash. Not a vendor pitch.
Kill conditionWritten, and rehearsed once, before write access exists.

Figures from /data/ai-comparison-2026.json. Last verified 2026-06-26. Scoring version v1.0. Affiliate links are off.

Choosing the pilot model from published scores

Version v1.0, recorded on methodology, weights task at 25 percent, cost at 20 percent, context at 15 percent, speed at 10 percent, safety at 10 percent and privacy at 10 percent. Integration and adoption are 5 percent each. A pilot that picks only on a benchmark headline ignores the cost and privacy weights the match engine uses. The model-choice control names an id from the dataset. These three ids are the ones with profiles, and the scores show why "a model" is not a control:

Model idPublished evidence for the control
claude-sonnet-4-6Truth 96, privacy 94, safety 93, HIPAA true. Weighted 87. Name this id when the data class needs the strongest published truth and privacy marks.
gpt-5-4Task 92, privacy 82, HIPAA true. API $2.50 in and $15 out per million tokens. Weighted 85. Name this id when the pilot depends on that task score and the data class still requires HIPAA true.
gemini-3-flashSpeed 95, privacy 72, HIPAA false. API $0.50 in and $3 out per million tokens. Weighted 86. Name this id for fast, cheap drafts. The HIPAA flag blocks it when the data class is medical-record text.

If the first job is a narrow internal task, what to automate first is the companion page. The model index lists the published profiles for claude-sonnet-4-6, gpt-5-4 and gemini-3-flash.

Stop rules before write access

Do not connect a tool that can email customers, move money or edit production records until the owner has stopped a dry run. Binding outcomes stay blocked under final decisions even after the pilot looks successful. Small teams can use best AI for small business to choose the job, then keep this page's controls in front of the first prompt.

Ready to choose the model, not the slogan? The match engine applies the published weights. It does not waive the kill condition.

FAQ

Is a pilot the same as the governance policy?

No. The policy describes ongoing guardrails. These controls have to exist before production data is used at all.

Can affiliate availability change the pilot model?

No. Affiliate links are off, and the published scores do not move for placement.

Which weights should the pilot respect?

Version v1.0 weights task 25 percent, cost 20 percent, context 15 percent, speed 10 percent, safety 10 percent and privacy 10 percent.

Which model ids are evidence for the model-choice control?

claude-sonnet-4-6 (truth 96, privacy 94, HIPAA true), gpt-5-4 (task 92, privacy 82, HIPAA true) and gemini-3-flash (speed 95, privacy 72, HIPAA false). Profiles: /models/claude-sonnet-4-6, /models/gpt-5-4 and /models/gemini-3-flash. Scores are from the dataset last verified 2026-06-26.