Two-minute study
QP-079 — Q Small Business AI Governance Starter - Public Artifact Edition
TWO-MINUTE RESEARCH PAPER · 1.0.0-r1 · 2026-09-25
STATUS: CANDIDATE RESEARCH — HUMAN/INDEPENDENT REVIEW REQUIRED
WHAT IT IS
This is a small-business AI starter kit that helps you set simple rules for how AI may be used, who checks important outputs, and what to do when something goes wrong.
PROBLEM
Use AI without needing a large compliance department by setting a few clear responsibilities, checks, limits, and stop rules.
WHO IT IS FOR
microbusinesses, small businesses, owners, managers, and small teams beginning to use AI
WHY IT MATTERS
AI-enabled work can fail through weak evidence, stale information, unclear authority, privacy/security gaps, overconfident outputs, or automation that becomes practically irreversible. NIST's AI RMF provides a lifecycle risk-management frame; Q10 applies that direction by requiring explicit scope, evidence, human authority, limitations, review dates, stop conditions, and rollback.
HOW IT WORKS
Name a human owner; define scope; record evidence, unknowns and contradictions; define permissions and prohibited actions; run baseline and adversarial tests; patch and retest; record residual risk; create a dated release receipt; set a review/TTL date.
VALIDATION STATE
Five small-business users
Generated research does not upgrade that evidence.
RISKS / FAILURE MODES
Scope creep; evidence drift; stale sources; authority escalation; false-clear from passing tests; privacy leakage; insecure dependencies; common-mode failure; reviewer fatigue; inaccessible interfaces; rollback failure; unsupported claims repeated as fact.
HUMAN CONTROL
A named human retains consequential approval, override, stop, release, and rollback authority.
KNOWN LIMITS
Not compliance certification
REFERENCE BASIS
NIST AI Risk Management Framework 1.0; NIST Generative AI Profile; NIST Privacy Framework; NIST Cybersecurity Framework 2.0; OWASP Top 10 for LLM and GenAI; UNICEF Guidance on AI and Children v3.
BOUNDARY
Research/education material only. Not legal, medical, financial, engineering, safety-certification, or regulatory advice.
How it works
A separate operating explanation has not yet been recorded for this product. Review the buyer/research paper and technical details below for the currently documented implementation information.
AI boundaries & human responsibility
AI-specific allowed/not-allowed actions have not yet been separately recorded for this listing.
Human control: Human-controlled
Risks, limits & failure modes
Not compliance certification
Failure modes: no separate failure-mode record has been published for this listing yet.
Dependencies, compatibility & deployment
Dependencies: not separately recorded.
Evidence, testing & provenance
Five small-business users
Provenance:
Factory source class: CANONICAL_82
Q spine/source basis: QIFY; Tool Registry; TSLP
Factory source: shopify:q-small-business-ai-governance-starter
Independent validation: No independent-validation status has been recorded; no independent validation is claimed by this listing.
Resources, privacy & security
Separate resource/energy requirements are not yet recorded on this listing.
Privacy and security obligations depend on the product and deployment. Where they have not yet been versioned in the legal/disclosure manifest, they remain an open pre-sale requirement rather than an implied promise.
What the complete package is expected to include
Tool register, policy, vendor checklist and incident plan
Price, license, support & updates
Price / pricing method: $149
License: Not yet recorded as a versioned license model.
Legal, rights & disclosures
A plain-language legal summary has not yet been versioned for this product.
Legal manifest status: LEGAL_SNAPSHOT_NOT_YET_VERSIONED