# Buying AI after the demo: a 2023–2026 retrospective

DataXLR8 · Original planning worksheet · Prepared 3 October 2026

Use this alongside the guide. Examples and proposed checks are not client results or a compliance certification.

Guide: https://dataxlr8.ai/blog/ai-buying-retrospective-2023-2026/

## Before you proceed

- [ ] Identify the job, affected parties and consequences of error.
- [ ] Ask how each cited framework applies to the actual use.
- [ ] Map information access and retained copies.
- [ ] Compare a fixed workflow with a proposed agent.
- [ ] Specify allowed actions and approval checks.
- [ ] Request expected and observed evaluation outcomes.
- [ ] Name the operating owner and recovery procedure.

## By 2 October 2026, the useful output is a better brief

By 2 October 2026, the useful output is a better brief

| Evidence strand | Question to put in the brief | Deliverable to request |
| --- | --- | --- |
| General risk management | Which outcomes and errors matter in this job? | Defined scope, affected parties and release criteria |
| Information handling | What information is used and where does each copy go? | Reviewed data-flow and access record |
| Architecture | Why does this task need an agent or custom build? | Comparison with existing tools and a fixed workflow |
| Permissions | Which actions are permitted, and who approves them? | Explicit read/write boundaries and enforced approval checks |
| Evaluation | What happens in ordinary and difficult cases? | Versioned cases, observed outcomes and unresolved failures |
| Operation | Who monitors, corrects and stops the system? | Named owner, support scope and recovery procedure |

## Your decision

Process owner: ____________________
Evidence gaps and next actions: ____________________
Decision / approver / date: ____________________

## Sources

- [Artificial Intelligence Risk Management Framework 1.0](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10)
- [AI Risk Management Framework and generative-AI profile](https://www.nist.gov/itl/ai-risk-management-framework)
- [Guidance on privacy and the use of commercially available AI products](https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products)
- [Introducing the Model Context Protocol](https://www.anthropic.com/news/model-context-protocol)
- [Building effective agents](https://www.anthropic.com/engineering/building-effective-agents)
- [Writing effective tools for agents](https://www.anthropic.com/engineering/writing-tools-for-agents)
- [LLM06:2025 Excessive Agency](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/)
- [Australia’s AI Ethics Principles and adoption-guidance history](https://www.industry.gov.au/publications/australias-ai-ethics-principles)
- [Guidance for AI Adoption: implementation guidance](https://www.ai.gov.au/staying-safe-and-responsible/essential-ai-practices/guidance-ai-adoption-implementation-guidance)
