Search⌘ K
AI Features

Design a Control Stack That Matches the Risk

Understand how to design control stacks that align with risk levels in AI workflows for DoD environments. Learn to separate trusted from untrusted context, apply least privilege access, ensure human verification, manage provenance, and address supply-chain dependencies. This lesson guides you in making conditional, evidence-based decisions to safely operate AI tools while preventing prompt injection and data leakage.

We'll cover the following...

A supervisor’s question sounds simple because it is phrased as a switch. Can document search be turned on, and can the assistant draft triage recommendations this week? That framing invites a yes or no, but a responsible answer is a stack of constraints that make the workflow reviewable. The mistake is treating capability as approval, as if adding retrieval only changes speed. Retrieval changes what the system can read, and what it can be steered by, so the approval decision is really about boundaries.

The hard line is not between safe and unsafe tools. The hard line is between information the team can vouch for and information it cannot. Trusted context is information the team controls and can verify, like a curated advisory list or an approved internal template. Untrusted context is information the team did not author or cannot vouch for, like arbitrary web ...