Detailed answer
Key answer: A LERA Execution Risk Diagnostic begins with enough information to understand what the AI system can propose, what it can execute, and what consequences may follow.
Core explanation
A LERA Execution Risk Diagnostic begins with enough information to understand what the AI system can propose, what it can execute, and what consequences may follow.
The organization does not need to prepare perfect documentation before starting.
An initial diagnostic may use interviews, workflow descriptions, screenshots, architecture diagrams, policy documents, or demonstrations of the relevant process.
Useful information may include:
System Purpose
- What is the AI system intended to do?
- Who uses it?
- Which business or operational objective does it serve?
- Is it advisory, semi-autonomous, or autonomous?
- Capabilities and Access
- Which tools can the system call?
- Which APIs, machines, accounts, or databases can it access?
- Can it send messages, move funds, change records, operate equipment, or initiate workflows?
- Can it act without real-time human approval?
- Action Pathways
- What actions can the AI propose?
- Which proposed actions can become execution?
- Which external systems carry out those actions?
- Where does the organization believe the Execution Boundary is located?
- Human Roles
- Who reviews or approves actions?
- What information do they receive?
- Do they have sufficient time and expertise?
- Do they possess legitimate authority?
- Who is responsible if the action causes harm?
- Rules and Constraints
- Which operational, safety, legal, contractual, or institutional rules apply?
- Where are those rules stored?
- How do they affect execution?
- Who can change them?
- Are exceptions documented and governed?
- Consequences
- Which people, assets, systems, rights, or institutions may be affected?
- Are actions reversible?
- How quickly can harm occur?
- Can one action trigger additional systems?
- Could the impact extend beyond the organization?
- Existing Concerns
- Have there been incidents, near misses, unexpected actions, or disputed approvals?
- Which future capabilities create the greatest concern?
- What is leadership most worried about?
The diagnostic does not require access to every source-code detail in order to begin.
Its initial goal is to expose the organizational and architectural path from AI output to consequence.
More detailed technical information may be required later for architecture design, implementation, validation, or integration work.
Confidentiality, access scope, intellectual-property treatment, and information-handling conditions should be defined as part of the engagement.
The most important starting information is not only how the model works, but what the surrounding system allows the model’s output to do.