FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Leadership ¡ 4 minute read

An AI Decision Rights Framework for Executives

An AI decision rights framework assigns each recurring AI decision to a level: the board oversees thesis and appetite; the CEO sets them; the accountable executive runs the program; functional executives own outcomes and autonomy within appetite; business and technical owners run agents; engineering decides implementation. Each decision names its evidence, so it is made once and made fast.

By FISTA Solutions¡ AI-Native Engineering Team¡
An AI Decision Rights Framework for Executives article cover

Most delays in AI programs are decision delays: a project waits weeks because nobody is sure who may approve the autonomy change, the vendor, or the deployment, and the question travels upward until it reaches someone willing to own it. This guide gives executives a decision rights framework that assigns each recurring AI decision to a level, names the evidence it needs, and lets decisions be made once and fast.

Why do AI decisions stall?

Because they are new, cross-functional, and consequential, and because the organization has no precedent for them. Who decides whether an agent may issue refunds alone? The head of support, the CFO, the CISO, legal, or the CEO? Without a framework, all of them, sequentially, and the answer is usually to wait. FISTA's executive guide to AI agent governance describes the governance structure; this piece assigns the decisions within it.

What does the framework look like?

DecisionBoardCEOAccountable executiveFunctional executiveBusiness and technical ownersEngineering
AI thesis and measuresOverseesDecidesProposesConsulted
Risk appetite and policy linesOverseesDecides with risk, security, legalProposesConsulted
Operating model and funding structureInformedDecidesProposesConsulted
Use-case selection and committed outcomesInformedApproves top outcomesRecommendsDecides within functionProposes with baseline
Funding tranchesInformedDecides at gatesConsultedPresents evidence
Autonomy changesInformedConsultedDecides within appetiteProposes with evidenceImplements
Model, architecture, toolsConsultedDecides within gateway and evaluation
Vendor selectionInformed if materialApprovesConsultedEvaluates on casesRecommends
Deployment approvalApproves tier 3Approves tier 1 and 2 on pass rateReleases
Incident responseEscalated if materialInformedDirects tier 3Directs tier 2Runs tier 1Executes
RetirementInformedApprovesDecidesRecommends with evidenceExecutes

The exact placement varies by company; the principle is that every row has exactly one "decides."

What principles shape the assignment?

  1. Decide at the lowest level with the accountability and the evidence. Owners run agents; executives change authority; the CEO sets direction.
  2. Escalate by consequence tier, not by anxiety. The how much autonomy should AI agents have guide defines the tiers.
  3. Name the evidence for each decision in advance, so the decision is about numbers.
  4. Separate what from how. The business decides what agents do and what counts as acceptable; engineering decides how.
  5. Risk, security, and legal hold lines; they do not approve every agent. Their policy is enforced by tier, and their review is reserved for the high tier.

What does the board decide?

Nothing operational. The board oversees the thesis, the appetite, and the governance structure, reviews evidence that the structure works, and receives escalation of material incidents. The board director's guide to AI and agentic AI describes what oversight looks like in practice.

What does the CEO decide?

The thesis, the risk appetite with risk, security, and legal, the operating model and funding structure, and approval of the top committed outcomes. The CEO's guide to AI and agentic AI sets out these four decisions and why they cannot be delegated.

What do functional executives and owners decide?

Functional executives decide which outcomes their function commits to, approve autonomy changes within appetite on evidence presented by owners, and approve high-tier deployments. Business owners propose outcomes with baselines, run agents, handle exceptions, and propose autonomy changes; technical owners run the systems and release on pass rates. The AI operating rhythm for leadership teams guide places these decisions in the monthly and quarterly reviews.

How is the framework recorded and used?

In one table, approved by the executive team, referenced in every review, and revised annually. When a decision arrives, the first question is which row it belongs to; the second is whether the evidence that row requires is present. Decisions that have no row are added at the next quarterly review. The AI program RACI template provides a starting artifact.

What should executives ask?

  • For each recurring AI decision, can we name the one level that decides?
  • What evidence does each decision require, and is it defined in advance?
  • Which decisions were delayed last quarter because nobody knew who could make them?
  • Are autonomy changes decided by executives within appetite, or by project teams?
  • When was the framework last reviewed?

How can FISTA Solutions help?

FISTA Solutions helps executive teams build the decision rights table, the tiering, and the evidence definitions through its AI enablement practice, and delivers AI agents whose permissions, gates, and metrics implement and inform those decisions. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.

To remove the decision delays from your AI program, talk to FISTA on WhatsApp, or read how to run an AI steering committee for the group that administers the framework.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01What is an AI decision rights framework?

A written assignment of each recurring AI decision to a level of the organization, with the evidence that decision requires. It covers thesis, appetite, funding, use-case selection, autonomy changes, vendor and model choice, deployment approval, incident response, and retirement. Its purpose is to make decisions once, at the right level, without re-litigation.

02Which AI decisions belong to the board?

Oversight of the thesis, the risk appetite, and the governance structure; review of evidence that the structure operates; and escalation of material incidents. Boards do not approve individual agents, choose models, or set autonomy levels, but they should expect to see how those decisions were made and on what evidence.

03Who should decide AI agent autonomy levels?

The functional executive accountable for the process, within the risk appetite set by the CEO, on evidence presented by the business owner, at the quarterly review. Risk, security, and legal hold the policy lines. Engineering implements the decision as permissions and gates. Autonomy should never be decided by a project team alone.

04Which AI decisions should engineering make?

Implementation: architecture, model choice within the gateway and evaluation results, tool design, evaluation methods, observability, and release once the pass rate meets the threshold the business set. Engineering does not decide what work agents do, what they may do alone, or what counts as an acceptable outcome.

05How do you handle AI decisions that cross functions?

By consequence tier. Low-tier decisions stay with owners; mid-tier go to the accountable executive; high-tier go to the executive team with risk, security, and legal present. The tier is determined by what the agent can do and whom it affects, not by who is nervous. Record the tiering with the framework.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project