What are the six controls?
Six places where AI-assisted development either stays safe or quietly creates risk: who owns the code, which models you use, your tooling, your testing, security, and your data. Governed well, AI speeds your team up. Left ungoverned, it ships problems faster.
Score your team 1 to 4 on each. Your lowest score is where to start.
Score each control 1 to 4: 1 Ad hoc (no shared practice) · 2 Emerging (some, inconsistent) · 3 Defined (documented, mostly followed) · 4 Governed (enforced and evidenced).
Human ownership & sign-off
Principle. A person owns and signs off on every change AI helps write.
Ask yourself. Could you say who approved a given piece of AI-generated code?
Model strategy & neutrality
Principle. You stay free to switch AI models instead of locking into one vendor.
Ask yourself. If your main AI provider changed its price or terms, how fast could you move?
Developer platform & tooling
Principle. A defined set of approved AI tools, not a free-for-all.
Ask yourself. Do you know every AI tool your developers actually use?
Quality assurance
Principle. More AI-written code means more testing and review, not less.
Ask yourself. Has your testing kept pace with the extra code AI produces?
Security & compliance
Principle. Your AI controls are enforced and recorded, so you can show an auditor.
Ask yourself. Could you show evidence of your AI controls this quarter?
Data governance
Principle. You decide what data AI tools can see, and you can prove it.
Ask yourself. Do you know where your prompt data goes and how long it is kept?
Get the full playbook
The complete Six Controls playbook: what good looks like for each control, the 2026 data behind them, and the scorecard to bring to your team.
Not sure where to start based on these results? Email nikoleta.lazarova@resolutesoftware.com.