Something fundamental has changed in our relationship with artificial intelligence.
For years, AI operated largely in the background. It scored applications, ranked candidates, detected fraud and priced risk. The people affected by those decisions often did not know that an algorithm had participated in the process.
Today, AI is visible and invited into everyday work. It drafts communication, analyses documents, generates content and supports decisions. The next shift is already underway: AI systems are beginning to plan tasks, use tools, initiate workflows and execute actions on behalf of organisations.
Each stage increases capability. Each stage also changes what governance has to ask.
Why Responsible AI remains essential
Responsible AI provides the principles for developing and using intelligent systems fairly, safely and accountably. It asks whether people are treated properly, whether risks are recognised, whether outcomes can be explained and whether organisations accept responsibility for the systems they deploy.
Its importance does not diminish when AI becomes more useful. It increases. A system that influences a decision creates risk; a system that can execute the decision creates operational consequences.
From principles to operational governance
Responsible AI is best understood as a connected stack. Principles express what an organisation believes it should do. Law establishes binding obligations. Governance translates both into structures, decision rights, reviews, controls and named ownership.
This third layer becomes critical for autonomous and agentic AI. High-level commitments such as fairness, transparency and accountability remain necessary, but they do not by themselves tell an organisation what a system may be permitted to do, when it must stop, or when a person must take control.
The new governance question
Predictive AI produces an output for someone to consider. Generative AI produces content for someone to review. Autonomous AI can move further: it may select an action, call another system, change a record, communicate with a customer, approve a request or initiate a transaction.
For business, this is not simply another improvement in model capability. It is a transfer of limited decision authority from people to systems.
Accuracy alone cannot govern that transfer. A highly accurate system may still act outside its mandate, use an inappropriate tool, proceed without sufficient evidence or create harm before a person can intervene. The organisation must therefore establish not only whether the model performs well, but whether the system is authorised and prepared to act.
That is the gap TATTVA addresses.
TATTVA
Tattva denotes essence or constitutive principle. TATTVA is a six-part governance framework for systems that act — an instrument of that third layer, used to assess whether an autonomous system is ready for deployment and to define the decisions it may take on its own.
The framework is designed for business leaders, process owners, risk teams, technology teams and governance functions. It turns Responsible AI from a set of broad commitments into six operational tests that can be examined before deployment and monitored after the system begins to act.
Together, the six tests answer three practical questions:
The depth of evidence each test requires should scale with the consequence of the action. A system that drafts an internal summary and a system that can issue a payment are held to the same six tests, but not to the same standard of proof.
Transparency of Purpose
A mandate a non-technical owner can understand and approve.
The purpose of an autonomous system must be stated in business language: the objective it serves, the users and processes it affects, the data and tools it may access, and the outcomes it is expected to produce. A technical description of the model is not an adequate mandate.
Business relevance: A customer-service agent designed to resolve routine requests should not gradually become a sales, pricing or eligibility decision-maker simply because it can access those tools.
Governance requirement: Document the approved purpose, prohibited uses, affected stakeholders, success measures and material risks. Any expansion of purpose should require renewed approval.
Accountability of Action
A named human owner before deployment.
Autonomy does not remove organisational responsibility. Every deployed system needs an accountable business owner with sufficient authority to approve its mandate, accept its risks, review its performance and suspend its operation when necessary.
Business relevance: When an AI agent sends an incorrect communication, rejects a valid request or initiates an inappropriate transaction, accountability cannot be dispersed across the model provider, developer, data team and user.
Governance requirement: Assign a named owner, define operational and oversight responsibilities, establish escalation routes and specify who can pause, override or retire the system.
Traceability of Decision
Provenance logged and reconstructable.
An organisation must be able to reconstruct how a consequential action occurred. This requires more than storing the final output. The record should show the instruction received, relevant context, data and tools used, intermediate decisions, approvals requested, action executed and resulting outcome.
Business relevance: If an autonomous procurement agent selects a supplier or an HR system changes a candidate status, reviewers need evidence of the path that produced the action, not only the final selection.
Governance requirement: Maintain tamper-evident logs, version information, tool-call histories, timestamps, decision rationale and links between the system’s action and the responsible business process.
Trust of Adoption
Trust measured, not assumed.
A technically capable system may still fail if employees do not understand it, customers perceive it as unfair or managers cannot judge when to rely on it. Trust is therefore an adoption outcome that must be evaluated through evidence, not inferred from usage or accuracy.
This is the one test that cannot be completed before deployment. What is examined beforehand is whether the means to measure it exist: a way to check comprehension, a working route to challenge a decision, and a record of where people override the system.
Business relevance: High usage may reflect convenience or lack of alternatives rather than informed confidence. Low challenge rates may indicate uncertainty, fear or an ineffective appeal process rather than acceptance.
Governance requirement: Measure comprehension, appropriate reliance, user confidence, override behaviour, complaints and appeal outcomes across the stakeholder groups affected by the system.
Verifiability of Reliability
Tested against failure modes, not only for accuracy.
Model accuracy describes performance under defined evaluation conditions. Reliability asks whether the complete system continues to behave safely when information is incomplete, instructions conflict, tools fail, data shifts or an unusual case falls outside normal operating conditions.
Business relevance: An agent may answer routine questions correctly and still fail dangerously when it receives ambiguous authority, encounters a duplicate transaction or loses access to a required source.
Governance requirement: Test normal, adverse and boundary conditions; simulate tool and data failures; define acceptable error rates; monitor drift; and verify that safe fallback and human escalation mechanisms work as intended.
Autonomy Boundaries
Decision rights enforced in the architecture.
The system’s authority must be explicit and technically enforced. Policies written in a document are insufficient if the agent can bypass them through its tools, permissions or workflow design.
Business relevance: A finance agent may prepare a payment but require human approval above a threshold. A recruitment agent may shortlist candidates but must not issue a final rejection without review. A service agent may refund a standard amount but escalate exceptional cases.
Governance requirement: Define permitted and prohibited actions, monetary and risk thresholds, approval gates, tool permissions, rate limits, stop conditions and mandatory escalation points within the system architecture.
How the six tests work together
The letters spell TATTVA. The working order is different, and deliberately so.
Transparency defines why the system exists. Autonomy Boundaries translate that purpose into enforceable decision rights. Accountability identifies the person who owns those decisions. Traceability preserves evidence of how each action occurred. Verifiability tests whether the system remains dependable under realistic conditions. Trust examines whether people can adopt and challenge it appropriately.
Passing one test cannot compensate for failing another. A traceable system may still exceed its authority. A reliable system may still have no accountable owner. A trusted system may still operate without sufficient evidence. Deployment readiness depends on the integrity of the complete governance structure.
Using TATTVA across the system lifecycle
Define the mandate, identify the owner, classify the decisions the system may take, test foreseeable failure modes and establish the evidence required for approval.
Monitor actions, exceptions, overrides, escalation frequency, stakeholder trust, performance drift and changes in tools, data or purpose.
Reconstruct the decision path, determine whether the system acted within its mandate, identify the accountable control failure and revise the relevant boundary, test or approval.
A test that is not met is not an observation. It is a block. Where a test cannot be satisfied, the system is not deployed at that level of autonomy: the mandate is narrowed, the boundary tightened, or the decision returned to a person until the evidence exists.
From Responsible AI to responsible autonomy
Responsible AI established the principles by which intelligent systems should be judged. TATTVA carries those principles into the operating conditions of autonomous AI.
As AI moves from predicting and assisting to deciding and acting, the central governance question changes. It is no longer only: can this system perform the task?
The business must now ask: should this system be authorised to act? Within what boundaries? On whose authority? With what evidence? And under whose accountability?
TATTVA provides a structured way to answer those questions before autonomy is granted — and to keep answering them while the system remains in operation.