Governance applies across all phases.
Scope & Safety Controls (Authorization First): Define in-scope channels (email/chat/voice), approved target groups, and strict boundaries. Establish "do-not-ask" rules (no passwords/OTPs, no banking data, no national IDs, no coercion or threats).
Scenario Design (Defensive, Realistic, Non-Harmful): Develop AI-assisted scenarios that reflect real workflows while avoiding harmful content and avoiding impersonation of real external entities or authorities.
Controlled Execution (Human-Reviewed Content): Run simulations using approved infrastructure and test identities. No malware, no exploits, and no real credential collection. Operate with stop conditions and a kill switch.
Safe Telemetry & Reporting: Measure minimal outcomes: interaction, verification compliance, reporting actions, and time-to-report. Default to aggregated reporting by role/department and apply defined retention and access controls.
Remediation & AI-Resilience Hardening: Deliver targeted micro-training and procedural fixes: stronger verification/callback steps, approval workflow hardening, and practical guidance for detecting AI-style persuasion tactics.
Outcomes vary based on baseline processes, reporting UX maturity, and leadership enforcement.