Where can AI improve reach, speed and synthesis without weakening trust?
AI-native intelligence is a redesigned operating model in which machines extend sensing, retrieval and analysis while accountable people control purpose, evidence standards and consequential judgment. It is not autonomous strategy and not a general chatbot connected indiscriminately to company data.
The architecture should make every material conclusion traceable from decision to claim to evidence, transformation and reviewer.
1. Design principles
- decision-led, not tool-led;
- bounded sources and legitimate data purpose;
- retrieval before unsupported generation;
- deterministic computation for auditable numbers;
- visible provenance and transformation history;
- calibrated uncertainty and abstention;
- human approval proportional to consequence;
- continuous evaluation and incident learning.
NIST’s AI RMF organises risk management around Govern, Map, Measure and Manage.1 Its Generative AI Profile identifies risks including confabulation, privacy, information integrity and harmful overreliance and provides lifecycle actions.2
2. Reference workflow
- Decision intake: owner, deadline, sensitivity and evidence threshold.
- Source governance: rights, quality, geography, freshness and access.
- Ingestion: preserve original, timestamp and content identity.
- Enrichment: entities, topics, language and claim extraction.
- Retrieval: return relevant passages with source metadata.
- Analysis: compare, quantify, generate alternatives and expose gaps.
- Verification: source checks, calculation tests and contradiction review.
- Human judgment: interpret context and approve recommendation.
- Delivery: decision brief with confidence, caveats and trigger.
- Learning: outcome, error and feedback captured for evaluation.
3. Evidence graph
Represent relationships among source, observation, claim, inference, assumption, scenario, recommendation and decision. A summary is not a source. Synthetic data and AI outputs must be labelled. Citation coverage should be measured for material factual claims.
4. Human control model
Use three levels:
- Assist: low-consequence drafting or classification; sampled review.
- Recommend: material interpretation; named analyst approval.
- Decide: high-consequence strategic, legal, customer or people action; accountable owner plus independent challenge.
Automation level depends on impact, reversibility, data sensitivity and detectability of error.
5. Evaluation
Maintain a representative test set covering languages, sectors, source types and known failure modes. Measure retrieval recall, citation correctness, factual consistency, calculation accuracy, unsupported-claim rate, subgroup performance, analyst override and decision usefulness. Test after changes to model, prompt, source or workflow.
NIST’s AI Resource Center emphasises testing, evaluation, verification and validation as part of operationalising AI risk management.3
6. Data and privacy
Create purpose, minimisation, retention, access and deletion rules. Separate public, licensed, confidential and personal data. Protect source confidentiality and research participants. Hong Kong PCPD’s Model Personal Data Protection Framework addresses governance, risk assessment, implementation and ongoing management for AI involving personal data.4
7. Operating roles
Executive risk owner; intelligence product owner; research/method lead; data steward; AI system owner; evaluator; security/privacy reviewer; domain analyst; and independent challenger. Vendors do not remove organisational accountability.
8. APAC and Hong Kong application
Evaluate multilingual retrieval and local context independently; English performance is not a proxy. Track source coverage by market and language. Apply relevant local data, intellectual-property and sector obligations, with qualified advice where required.
9. Adoption roadmap
Start with a bounded, reversible use case such as monitored official sources. Establish baseline human performance, run in shadow mode, verify sources and errors, then expand only after thresholds are met. Avoid enterprise-wide ingestion before purpose and permissions are clear.
11. Decision playbook
Select use cases on value, boundedness and evaluability. Good first cases have known sources, repeatable tasks, reviewable outputs and low irreversible harm. Score each use case for time saved, coverage gained, decision value, data sensitivity, error detectability and cost of failure.
Create a claim-check pipeline: retrieve the original passage, classify the claim type, verify that the passage supports it, check date and scope, search for independent or contrary evidence, then approve. Citation existence and citation entailment are different tests.
Use shadow mode before operational reliance. Compare AI-assisted and baseline human workflows on quality, time and failure modes. A faster process that increases unsupported claims is not an improvement.
12. Failure modes
Avoid unrestricted web synthesis, confidential-data ingestion without purpose, benchmark-only evaluation, automated sentiment treated as customer truth and agents authorised to make consequential external changes. Vendor assurances should be tested against the organisation’s own sources and risk context.
The revised ICC/ESOMAR Code explicitly responds to AI and synthetic data and emphasises accountability, transparency and human oversight.5 This reinforces a central operating principle: technology may perform work, but responsibility remains identifiable.
Sources
1National Institute of Standards and Technology, *AI Risk Management Framework 1.0* (2023). https://www.nist.gov/itl/ai-risk-management-framework
2NIST, *Generative AI Profile, NIST AI 600-1* (2024). https://doi.org/10.6028/NIST.AI.600-1
3NIST, *AI Resource Center*. https://airc.nist.gov/
4Office of the Privacy Commissioner for Personal Data, Hong Kong, *Artificial Intelligence: Model Personal Data Protection Framework* (2024). https://www.pcpd.org.hk/english/resources_centre/publications/files/ai_protection_framework.pdf
5ICC and ESOMAR, *International Code* (2025 revision), on accountability, transparency and human oversight. https://community.esomar.org/uploads/public/knowledge-and-standards/codes-and-guidelines/ICCESOMAR-International-Code_English.pdf
Apply this research
Turn the framework into a decision, evidence plan and practical next move for your organisation.
