§1.4 · FOUNDATIONS · 3 MIN READ · EDITION 1.0
What this guideline does not cover
Data protection law, export control, cybersecurity engineering, contractual liability and certification schemes are specialist domains with their own owners; this guideline sets a quality-control model that sits alongside them, not in place of them.
Referencing a legal or regulatory concern in a use-case discussion is appropriate; resolving it is not this guideline's job. Route those questions to the function that actually owns them before a use case proceeds.
Treat this scope boundary as a control in itself: a project that quietly absorbs legal or security decisions into a quality-team AI initiative has expanded its own authority without the matching expertise or accountability.
PUT THIS INTO PRACTICE
- 01Name the specialist owner for legal, security and export-control questions.
- 02Escalate rather than resolve concerns outside the quality domain.
- 03Keep this guideline's authority limited to quality and APQP control.
CITE THIS SECTION
§1.4 · Edition 1.0 · What this guideline does not cover