Monthly Newsletter - October 2026
AI Is Not the Strategy: Keeping Humans in Control
ControlPointAI examines the growing divide between AI’s extraordinary promise and its potential risks—and why both make human control essential. This month’s issue connects lessons from the Piping UT Demonstration with our new EU AI Act work to explore how data flows, decision authority, evidence, and meaningful human oversight can be engineered into real operational processes.
By Wayne Couch ·

AI Is Not the Strategy
Depending on what you read this month, artificial intelligence is either about to unleash a historic productivity boom—or help bring about the end of humanity.
That's quite a range.
On one side are predictions of extraordinary productivity gains, new industries, scientific breakthroughs, and AI systems allowing people and organizations to accomplish things that previously would have been impossible.
On the other are warnings about widespread job displacement, systems becoming more capable than their designers anticipated, humans losing meaningful control over increasingly autonomous technology—and, at the farthest end of the spectrum, predictions that advanced AI could pose an existential threat to humanity itself.
We aren't going to pretend we know which predictions will prove correct.
But there is something striking about the fact that the same technology can generate conversations ranging from “the next great productivity revolution” to “the end of mankind.”
And that leads to a much more practical question:
While everyone else argues about where AI is taking us, how do we make sure humans remain in control of the systems we're deploying today?
Organizations everywhere are being encouraged to “adopt AI.” But buying an AI tool is not a strategy. Adding an AI assistant to an existing workflow is not a strategy. And replacing today's model with a dramatically more capable model tomorrow does not answer the harder organizational questions that follow.
Who is allowed to use it? What information can it consume? What can it recommend? What decisions can it influence? Who reviews its output? Who has authority to reject it? What evidence needs to be retained?
And when the technology changes—as it inevitably will—how do we ensure that the organization's authority structure does not quietly change with it?
Those questions become even more important if even a fraction of today's most optimistic or most pessimistic predictions prove correct.
If AI delivers the productivity revolution its advocates anticipate, organizations will increasingly embed it in real operational processes.
If AI capabilities advance as rapidly as some researchers warn, those same organizations will need mechanisms capable of keeping authority, accountability, and human control from drifting as the technology changes.
Either way, simply choosing the right AI model isn't enough.
The difficult part is understanding—and controlling—the organization around it.
AI can affect an organization's strategy, structure, systems, skills, staff, management style, and even its shared values. A seemingly simple AI implementation can propagate through an organization in ways that were never part of the original plan.
That is why ControlPointAI has increasingly focused not on predicting what the next AI model will be able to do, but on something much more practical:
Where does the data go?
Where does the decision occur?
Where does authority reside?
What evidence demonstrates what happened?
And where must the human remain in control?
Over the past several months, we've been working those questions from the operational level upward rather than from the technology downward.
This month, two projects have helped turn that idea from a management concept into something much more concrete.
From Concept to Demonstration: The UT Project
Over the past several months, ControlPointAI has been developing a practical demonstration based on a familiar ship-maintenance problem: an ultrasonic testing inspection package moving through a real engineering and quality-assurance workflow.
The purpose was never to demonstrate that AI could perform an engineer’s or inspector’s job. It was almost the opposite.
We wanted to see whether AI could support a complex technical process while preserving the boundaries between the people who perform the work, review the technical results, verify quality requirements, resolve discrepancies, and ultimately retain decision authority.
As the demonstration developed, the interesting problem became less about the AI itself and more about the flow of information, authority, and evidence through the process.
That led us to map the workflow node by node: what information enters each step, who owns the decision, what the AI may propose or assist with, what it may not decide, what evidence must be retained, and what happens when something does not go according to plan.
The result has been more valuable than we originally expected. The UT project is becoming a working test bed for the ControlPointAI data-flow mapping method itself—including lessons about human authority, configuration control, evidence, exception handling, and the danger of allowing seemingly small changes in a workflow to create authority drift.
We are deliberately limiting how much of the detailed demonstration we publish while that work continues. But the larger lesson is one we can share:
Responsible AI governance becomes much easier to discuss when you stop treating it as an abstract policy problem and start mapping what actually happens when data, decisions, and authority move through a real operational process.
That lesson is now helping shape both our Data-Flow Mapping Standard and our next project: applying the same engineering mindset to the EU AI Act.
From Regulation to Operations: Our EU AI Act Work
ControlPointAI has begun a structured review of the EU AI Act as the next application of our data-flow and authority-mapping approach. We have reviewed the current regulatory framework and developed an internal working summary to establish the baseline for the next phase: building a requirement-to-control crosswalk.
One thing is already apparent. The Act is much more than a list of AI rules. For high-risk systems, it addresses an interconnected lifecycle of risk management, data governance, technical documentation, logging, transparency, human oversight, system performance, and continuing monitoring.
That makes the implementation question particularly interesting to us:
How do you translate a regulatory requirement into an operating control—and how do you demonstrate that the control actually works?
Our next step is to map applicable requirements to operational processes, human authority points, data flows, and objective evidence. We are deliberately approaching that work as an engineering problem rather than simply turning the regulation into another compliance checklist.
There is also a striking connection to the work we have already been doing. The Act's treatment of human oversight reinforces a principle at the center of ControlPointAI: meaningful human oversight requires more than placing a person somewhere in the workflow. The human decision-maker needs defined authority, sufficient information, and an executable means to challenge, override, intervene, or stop when necessary.
We'll have more to report as the crosswalk develops.
From Prediction to Control
We started this issue with a rather extraordinary range of predictions.
AI may usher in a historic productivity boom.
AI may eliminate or radically change millions of jobs.
AI may transform science, engineering, government, and industry.
And at the extreme, advanced AI may someday pose an existential threat to humanity.
We don't know which of those predictions will prove correct.
But after working through the UT demonstration and beginning our review of the EU AI Act, we are becoming increasingly convinced of something much less speculative:
The models will keep changing. The authority cannot drift with them.
That may be the central AI governance problem.
The UT project approached it from the bottom up. We started with a real operational process and mapped the movement of data, decisions, evidence, and authority through the people and systems involved.
The EU AI Act approaches many of the same questions from the other direction. It establishes requirements for things such as risk management, documentation, logging, transparency, human oversight, and continuing monitoring. The implementation challenge is translating those requirements into controls that actually function inside an organization.
Those two paths eventually meet in the same place.
A policy saying that humans remain accountable is not enough.
A diagram showing a human somewhere in the workflow is not enough.
And an AI system asking a person to click Approve is not meaningful human oversight if that person lacks the information, authority, or practical ability to say No.
Human control has to be engineered into the process.
That means knowing where the data came from, where it went, what the AI did with it, what the AI was permitted to do, what decision was made, who had authority to make it, what evidence was retained, and what happens when something goes wrong.
That is the problem ControlPointAI is trying to understand.
We are still early in that work. Our UT demonstration continues to teach us lessons that are feeding back into our Data-Flow Mapping Standard, and our EU AI Act crosswalk is only beginning.
But the direction is becoming clearer.
The future of AI may turn out to be considerably better—or considerably worse—than any of today's predictions.
Either possibility makes the same work necessary today:
Map the data. Define the authority. Preserve the evidence. Keep the human in control.
And as the technology changes:
The models can change. The authority cannot drift.