AI Assurance: System Risk and Release Decisions
Meridian has ten AI systems and one signature. Build the release decision as an organization-level capability: list what you run, tier it by consequence, assemble the evidence, evaluate on your own terms, challenge it, decide on a signed record that expires - and keep deciding until the day you withdraw it.
6 modules · 23 lessons · ~7.3 hours · AI governance owners, ISSOs, security teams, the engineers shipping AI features, and the leaders who sign for them
Chapter 7 in the Meridian sequence · 9 live so far · builds on Grounded Answers From Documents and Zero Trust Implementation · continues in Operating in Production: On-Call, Incident Command, and Reporting Clocks
Meridian Utilities has ten AI systems on its register — seven in production, two in pilot, one proposed. One of them — the grounded-answers service from the last chapter — can say which model version produced any answer it ever gave. The other nine cannot, and nobody signed for any of them: a vendor chatbot in the customer portal, an outage predictor that positions crews, a code assistant, a resume screener that ranks applicants no human will read, an anomaly detector on a substation network. This training builds the capability that closes that gap: the release decision. You will list what you run and tier it by consequence, assemble what the model and its provider actually claim, evaluate on a sealed set the provider never saw — a classifier, a generator, and the system you cannot open — challenge the evidence by attempt budget rather than by a single lucky run, and put the decision on a signed record with an independent reviewer, verifiable conditions, and an expiry. Then you keep deciding: the provider retires the version you pinned, the trigger fires, and you renew or withdraw. Every lesson drives an AI CLI against a substrate that runs with no account; the training's thesis is deliberately modest: a release decision is a bounded, signed, time-limited claim — never, by itself, a certification. No prior Meridian knowledge needed.
The Curriculum
List What You Run
You cannot assure what you cannot list
Discover the AI estate, register it with owners and a version boundary, tier every system by consequence and reversibility, and learn what a release decision actually is
Assemble the Evidence Packet
The card is a claim
What the model and its provider say about themselves, read from the seat of the person accepting the risk - claims, omissions, applicability, the version you can actually pin, and the lineage you can actually verify
Evaluate on Your Terms
Your data, your gate
Evaluation orchestrated by system type on a sealed set the provider never saw, a workbench that runs with no account and states what each run proves, candidates compared on one contract, and the route for systems you cannot open
Challenge the Evidence
A sample proves a sample
Attack evidence planned from the system's risk, reported by attempt budget with its uncertainty, and the addendum that decides whether an agent may be deployed at all
Make the Release Decision
Signed, reviewed, conditioned
The impact assessment the record was missing, the record itself with evidence links that resolve, conditions somebody can verify, the determinations and waivers that must be written down, and the gate with typed outcomes
Keep the Decision Current
The decision expires
The triggers that suspend or expire a decision, proof of what is actually running, the portfolio view and its bill, and the capstone that renews or withdraws one decision end to end
New to AI CLI tools?
This training assumes you can drive an AI CLI (Claude Code, Codex CLI, Antigravity CLI, or Copilot CLI). If that's new, these modules from our AI-Powered Development training are the fastest preparation — most students need only the first one: