Name the problem
What is slow, expensive, error-prone, difficult to scale, or impossible today?
AI can be extraordinarily useful. That does not mean every workflow needs a model, every product needs a chatbot, or every lawn mower needs to develop opinions.
The principle: use AI when AI earns its place. If ordinary software solves the problem, that is a successful answer.
The technology comes after the problem. If the problem cannot be explained without using the word AI, the proposal is not ready to be evaluated.
What is slow, expensive, error-prone, difficult to scale, or impossible today?
Could a process change, query, rule, script, API, template, or scheduled job handle it?
Identify the specific improvement that comes from probabilistic or generative capability.
Use the least data, access, authority, autonomy, and persistence needed to get the benefit.
If you cannot explain the problem without using the word AI, you probably are not ready to propose AI as the solution.
Conventional software is often faster to test, easier to reason about, cheaper to operate, and less surprising when the requirements are stable.
Sometimes your revolutionary autonomous agent is a cron job wearing a venture-capital hat.
AI earns its place when its incremental value is meaningful, measurable, and difficult to obtain with deterministic technology alone.
Once AI survives the first test, the next design question is not how powerful the system can become. It is how little additional capability is required to obtain the benefit.
You would not expose every service on every server to the public internet just because you could.
You should not add AI capabilities to every system just because models are available. Unnecessary capability is unnecessary attack surface.
Seven short questions. Four defensible outcomes. No maturity score, no email gate, and no obligation for the answer to create a security engagement.
Choose the closest answer each time. The result will explain which signals drove the conclusion.
This is a decision aid, not a security assessment, ROI model, or certification.
Each teardown starts with the problem, tests the deterministic alternative, identifies what AI adds, and ends with a verdict.
A push mower probably does not need a chatbot. A robotic mower may have a more interesting case.
Verdict: it depends → 02 · Common business failureWhen three rules and a webhook solve the job, autonomy is not innovation. It is extra surface.
Verdict: automation → 03 · A legitimate caseA real example where unstructured information and adaptive reasoning materially change the solution.
Verdict: AI, kept small →AI adds system complexity, dependencies, and potential attack paths. Those costs can be justified when the capability creates enough value. They are unnecessary when it does not.
No. The check does not invent financial precision. It asks whether the AI creates a defensible, measurable improvement over ordinary software or process change.
No. It is an upstream decision aid. If AI is justified and the system has material access, authority, autonomy, or business consequence, independent assurance may be the next step.
No. The check runs locally in your browser. It does not require a signup and does not send your answers to LeftOut Security.
After the use case survives this test—especially when it needs sensitive data, integrations, tool access, external action, or becomes important to normal business operations.
Don’t expose a port you don’t need.
Don’t grant authority you don’t need.
Don’t collect data you don’t need.
Don’t deploy AI you don’t need.