Start with the system's security boundary.
These are intended application areas. Scope depends on the models, interfaces, evidence and operational environment.
Scope access to the mission environment
Bind authority to the workload and resource. Test-environment access must not silently carry into operational systems.
Review model and software changes
Connect model versions and proposed actions to the approved policy. Preserve the distinction between a proposal and authorized execution.
Make security decisions inspectable
Give engineering and program reviewers the policy basis, action scope and available evidence for each decision.
Keep authority tied to the mission.
An AI-enabled mission workflow may span operators, models and equipment from several suppliers. Authority must remain tied to the identity, environment and operation approved by the owner.
Test and operational credentials, model updates, connectivity limits and record access need separate treatment. Defense deployment and acquisition requirements must be established for the actual program.