Practical Guide: Telecommunications and Media
Closed-loop automation on infrastructure that emergency calls depend on, and content decisions taken millions of times an hour.
- Typical top tier
- Tier 4 — closed-loop network remediation, anything touching emergency service access
- Already-owned ground
- Network change management, service continuity obligations, lawful process handling
- Hardest gate
- G4 — because network automation changes hourly and the approved state must still mean something
- First record to fix
- The authority boundary for every automated remediation action
1. Where the risk actually concentrates
Telecommunications was automating closed loops before the current wave of AI, and the governance question is continuous rather than new: which changes may a system make to the network without a human, under what conditions, and how quickly can that be stopped. The framework's contribution is the authority boundary as a machine-readable record, and the comparison of what the system actually did against what it was permitted to do.
The consequence profile is unusual. Individual errors are cheap — a misrouted packet, a wrong recommendation — but the tail is severe: a remediation action that degrades an emergency call path, or a capacity decision that leaves an area without service during an incident. D1 should be scored against the tail, and the tail is what the sector's licence conditions are about.
Where the operator also runs media or platform services, a second estate sits alongside it: recommendation, moderation, advertising and increasingly generated content. These have low individual consequence, enormous scale, and their own regulatory regime. Do not let one governance conversation cover both estates; the anchors are not the same.
Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.
| Typical system | Illustrative D1–D5 | Tier | What is usually mis-scored |
|---|---|---|---|
| Closed-loop network remediation and self-healing | D1 4 · D2 4 · D3 3–4 · D4 4 · D5 2 | Tier 4 | Scored on typical impact rather than on the tail, which is where the licence conditions live |
| Capacity, traffic steering and prioritization | D1 3–4 · D2 3–4 · D3 3 · D4 4 · D5 2 | Tier 3–4 | Traffic management decisions can engage regulatory rules independent of their technical merit |
| Fault prediction and field dispatch | D1 3 · D2 3 · D3 2 · D4 3 · D5 2 | Tier 2–3 | Restoration order determines who is out of service longest |
| Fraud, SIM-swap and account takeover detection | D1 4 · D2 3 · D3 3–4 · D4 4 · D5 4 | Tier 4 | A missed SIM swap is a customer's whole digital identity; a false positive is a locked-out customer |
| Credit assessment for contracts and device financing | D1 4 · D2 2–3 · D3 3 · D4 4 · D5 3 | Tier 3–4 | Treated as a sales process; it is a credit decision with the same obligations as any other |
| Churn prediction and retention offer selection | D1 2–3 · D2 3 · D3 2 · D4 4 · D5 3 | Tier 2 | Differential offers by segment can become a fairness question at scale |
| Customer care assistant with account and plan actions | D1 3 · D2 3 · D3 3 · D4 4 · D5 3 | Tier 3 | The action scope sets the tier: a plan change is reversible, a port-out is not |
| Content moderation and recommendation on a media service | D1 3 · D2 4 · D3 3 · D4 4 · D5 3 | Tier 3 | Both error directions are consequential and only removal errors generate complaints |
| Generated media content and localization | D1 2–3 · D2 3 · D3 3 · D4 4 · D5 2 | Tier 2–3 | Rights and provenance of training and output material, scored as a technical matter |
2. The regulatory interface
Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.
IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.
| Regime or standard | What it obliges in practice | IRGF record that carries the evidence |
|---|---|---|
| Sector regulation and licence conditions | Service continuity, emergency call access, resilience reporting, and obligations on outage notification. | Emergency path protection recorded as an architectural constraint at G2; outage causes traced through the Drift/Alert Record |
| Network and information security law for essential services (for example NIS2 and equivalents) | Risk management measures, supply chain security, incident reporting within defined windows. | Incident routing aligned to the statutory clock, which is usually faster than any internal cadence |
| Customer data confidentiality rules (for example CPNI-style obligations and telecom privacy law) | Restrictions on use and disclosure of communications and usage data, including for marketing. | Purpose recorded per data flow in the lineage record; secondary use treated as a Major change |
| Consumer rules for electronic communications | Contract transparency, switching and porting rights, and vulnerability protections. | Action scope of assistants constrained so that irreversible customer actions require confirmation |
| Traffic management and open internet rules where applicable | Constraints on differential treatment of traffic, with defined exceptions. | Constraint list recorded in the ADR and enforced in the policy layer, not in documentation |
| Platform, media and copyright regimes where the group operates content services | Recommender transparency, illegal content processes, protections for minors, and rights clearance for generated or derived content. | Transparency compiled from the AI System Card; provenance recorded in the lineage record |
3. Calibrating the five dimensions
The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.
| Dimension | How to read it here | The mis-score to watch for |
|---|---|---|
| D1 Decision Consequence | Score against the tail. Anything that can degrade emergency call access, isolate an area, or take over a customer's identity is 4, however rare. | Averaging across the millions of harmless actions, which is the sector's characteristic mis-score. |
| D2 Autonomy | Closed loop is 4. A human approving a batch of automated actions after the fact is not oversight, it is reporting. | Counting the post-hoc review as a control. Verification matters, but it does not reduce D2. |
| D3 Reversibility Deficit | A port-out, a disclosed record and an outage during an emergency are 4. A configuration change is 2 if it can be rolled back before service impact. | Scoring rollback capability rather than service consequence. |
| D4 Exposure and Scale | Network topology and shared infrastructure make cascade the default assumption. 4 for anything on a shared control or transport path. | Scoring the managed element rather than the blast radius of a wrong instruction. |
| D5 Sensitivity and Uncertainty | Communications metadata and location are 4 in most regimes, regardless of content. Network telemetry is 1 to 2 with high uncertainty for learned components. | Treating metadata as technical data rather than as regulated communications data. |
4. One system, end to end
The overlay above is a map. This is one route across it: a single network event followed from detection to verification, with the record or control that attaches at each step.
5. What each gate adds
Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.
| Gate | Sector addition | Why it is here |
|---|---|---|
| G1 | State whether the system can affect a service path that emergency access depends on, and whether it uses communications data for a new purpose. | Both answers change which regime applies and both are cheap to answer at intake. |
| G2 | Blast radius analysis for any automated action: what is the worst instruction this system can issue, and what stops it. | The boundary is the architecture decision. Everything downstream depends on it being explicit. |
| G3 | Machine-readable authority boundary, rate limits, and a tested stop that does not require the system's own control path. | A stop that depends on the automation being healthy is not a stop. |
| G4 | Expanding the action set, the affected elements or the rate is Material even when the model is unchanged. Scope creep is the change type that matters here. | Automation scope expands continuously and quietly, and each expansion is an autonomy change. |
| G5 | Retention for network and communications records set by statute, not by convenience. | Retention rules in this sector are prescriptive in both directions: minimums and maximums. |
6. Controls and evidence worth adding
| Control | Where it attaches | Evidence it produces |
|---|---|---|
| Machine-readable action allow-list per automation domain | Agent Card; policy engine | Boundary comparable against executed actions, continuously |
| Rate and blast-radius limits with automatic suspension | Runtime control | Enforced limits and the record of every suspension event |
| Emergency path protection as an architectural constraint | Pattern library; ADR | Conformance statement plus a test that the path survives the automation being wrong |
| Out-of-band stop capability, tested quarterly | Kill-switch record | Test date, executor and result |
| Irreversible customer action list requiring confirmation | Assistant action scope; workflow | The list, and evidence that confirmation is enforced rather than displayed |
| Both-direction moderation quality sampling | Assurance cycle | Wrongful removal and wrongful retention rates, reported together |
7. Runtime signals to wire first
Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.
| Signal | Drift category | Suggested response |
|---|---|---|
| Automated action volume or scope exceeds the approved envelope | Agent boundary divergence | Incident at any tier: suspend the loop, preserve state, notify the network duty manager |
| An automation domain gains a new action type | Configuration, with an autonomy consequence | Material change; re-score D2 and re-run the blast-radius analysis |
| Model-driven traffic decisions correlate with a constrained category | Behavioral, with a regulatory consequence | Route to regulatory affairs and engineering together, immediately |
| Fraud model false-positive rate moves by segment | Behavioral | Lockouts are customer harm; treat as a service incident, not a tuning issue |
| Communications data flows into a new consumer of that data | Data lineage and governance | Stop and assess: purpose change in this sector is a legal question before it is an architecture one |
8. Failure modes this sector produces
Scope creep as configuration
The tell. An automation platform gains new playbooks weekly, each added as configuration, and the approved action set in the record is a year old.
The response. Version the action set and compare it to what is enforced. Boundary divergence is an incident at any tier, and this is the sector where it accumulates fastest.
The stop that runs through the thing you are stopping
The tell. The suspension mechanism depends on the same orchestration layer that is misbehaving.
The response. Require an out-of-band stop path and test it. Record the test date in the kill-switch record.
Governing two estates with one conversation
The tell. Network automation and media recommendation are reviewed by the same body with the same questions, and both are governed badly.
The response. Separate the populations and the anchors. They share a framework and nothing else.
The tail nobody scored
The tell. A remediation system is assessed on its median impact and the emergency-path scenario was never written down.
The response. Score D1 against the worst instruction the system can issue, and record that instruction explicitly in the ADR.
9. A ninety-day start
If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.
- List every automation domain that can change network state, with its current action set and rate limits.
- Compare each recorded action set against what is actually enforced. Expect divergence; that gap list is the first backlog.
- Score the top two closed-loop systems against the tail scenario, with network operations present.
- Establish and test an out-of-band stop for each, and record the test.
- Write the irreversible-action list for customer assistants and enforce confirmation.
- Separate the media estate and give it its own scoring session and its own pattern set.
- Wire boundary-divergence alerting for automated actions. It is the single highest-value signal here.
- Run a G3 dry run on the largest closed-loop domain with regulatory affairs in the room.