A governable AI workflow makes responsibility, permitted data use, sources, review points, confidence limits, exceptions, escalation, and change ownership explicit. The control model must live in the workflow itself—not in a policy document that operators never encounter.