What is a thinking framework for AI?

A thinking framework for AI is a written set of rules that decides how an AI system reasons, what it may do on its own and when it must stop. The model supplies language and pattern recognition; the framework supplies judgement about evidence, authority and risk.

  1. 01A thinking framework sits above the model and survives a change of model.
  2. 02Its core parts are a constitution, decision rights, a challenge duty, a truth layer and kill criteria.
  3. 03It is written and approved before the system is built, not added after something goes wrong.

Why does AI need a thinking framework?

A language model answers whatever it is asked, in a confident voice, whether or not the evidence supports the answer. On a low stakes task that is acceptable. On a decision that commits money, reputation or a person’s data, it is not.

A thinking framework moves judgement out of the model and into written rules that a person has approved. The model can change; the rules stay. The United States National Institute of Standards and Technology makes a similar point in its AI Risk Management Framework, which places governance across the whole life of an AI system rather than at a single checkpoint.

What are the parts of a thinking framework?

Michael S.U. Hudson uses five parts.

A constitution states what the system exists to improve and the principles it must follow, such as simplicity over sophistication and evidence over opinion.

Decision rights set three tiers. In the first, the AI decides and acts, for work such as drafting and analysis. In the second, the AI proposes and a person approves, for changes of scope, architecture or spend. In the third, only a person decides: money, customer commitments and anything customer facing. An unclassified decision defaults to the second tier, and the AI may never move a decision to a lower tier.

A challenge duty requires the AI to question any recommendation that is over engineered, low in return or built on assumptions, including the owner’s own. Each challenge and the final ruling are recorded together.

A truth layer names exactly one authoritative source for each kind of data. Dashboards are views, never truth, and errors are corrected at source.

Kill criteria define, from the first day, the evidence that would reduce the system or shut it down.

What does it look like in a real system?

DIOS, a decision intelligence system for C-suite management, was governed by exactly this structure. Its founding documents were approved before any code ran. AI agents built it inside those rules: they proposed, and Michael decided.

The framework shaped the engineering as well as the governance. When a model judged that a commitment was complete and invented the evidence for it, the write was blocked, because consequential writes were gated behind an explicit switch. The result was an eight rule write standard, including verbatim checking of every quoted piece of evidence before anything reaches the system of record.

The kill criteria were used as written. When usage fell while client work took priority, DIOS reported the decline in its own weekly review, and on 25 August 2026 it was paused on the grounds of non use, with all data kept.

Does it apply outside leadership decisions?

It applies wherever an AI output can cause harm that is hard to reverse. Portraitor, a product that turns a chat conversation into a written portrait of communication patterns, runs on a fixed analysis prompt rather than open conversation. The prompt reads each conversation through four lenses: relationship context, the Big Five personality model, Transactional Analysis and change over time. Every finding carries a confidence score and its stated limitations.

The same framework sets privacy rules. Names, addresses and other identifiers are masked on the user’s own device before anything is sent, and Portraitor holds no conversations, portraits, accounts or email addresses, as its privacy policy states.

How do you start one?

Write the constitution first: one paragraph on what the system is for and what it must never optimise. Then list the decisions it will touch and place each one in a tier. Name the source of truth for every kind of data it reads. Write down, before the build, the evidence that would prove it is not working.

Only then choose the model. A framework that depends on one model is a configuration, not a framework.

Sources

  1. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST, 2023. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
  2. Portraitor. Privacy Policy, version 1.3. Portraitor, 2026. https://portraitor.ai/privacy
  3. Michael S.U. Hudson. DIOS: a decision intelligence system for C-suite management. michaelsuhudson.com, 2026. https://michaelsuhudson.com/work/dios-decision-intelligence-system-for-c-suite-management/

Author

Michael S.U. Hudson is a Creator based in Stockholm. He is Chief AI Officer of Project 54, building AI strategy and systems for energy and industrial companies, and Head AI Content & Analytics Engine Architect at Beeyawn. He is a film writer and director by origin.

Not the economist Michael Hudson.