AI Controls and Governance
Governing what an agent is given before it acts. The input layer that sits between policy and monitoring.
10 answers
- What is AI governance?AI governance isn't a document. It's the ability to answer four questions about a specific decision. Most organisations can answer three; the one they can't is what the agent was working from before it acted.
- Who is responsible when an AI agent makes a wrong decision?Agents aren't legal persons, so accountability sits with the organisation and has to land somewhere specific. The question isn't just what the agent did; it's what it was working from before it acted.
- What's the difference between AI governance and AI monitoring?Governance sets the rules. Monitoring checks compliance. Neither governs what the agent was actually working from before it acted. The third layer most AI deployments are missing.
- How do I explain an AI decision to the board?Boards don't want the technical trace. They want to know what the agent was working from and who approved it. The explanation that survives scrutiny is a record created before the decision, not reconstructed after.
- What is an AI accountability owner?Every organisation running AI agents already has an accountability owner, usually unnamed and often assigned by accident. What the role is, why it isn't the CTO or CEO, and what the person doing it actually needs.
- What controls do I need before deploying an AI agent?The controls that get skipped before agent deployment aren't technical; they're decisions nobody wrote down. A readiness test built on four questions, plus the outsider test: could someone outside the room answer them from the record?
- What is AI drift, and why does it matter?AI drift isn't just model decay. The organisational kind, where agents work from a brief the organisation has moved past, produces no incidents, fires no alerts, and compounds quietly along three axes: compliance, goal, and values.
- Can I be held accountable for what an AI agent does?In most jurisdictions, yes. The practical question is whether you can demonstrate what the agent was given before it acted. Personal exposure, the closed defences, and the record your position turns on.
- What is shadow AI and how do I manage it?Shadow AI is two problems wearing one name. Approving tools solves the first. The second, ungoverned context flowing in and unattributed judgement flowing out, survives the approval. Five moves to manage it.
- How do GDPR and AI audit requirements interact?The GDPR's erasure right and AI audit retention look contradictory and mostly aren't. The real conflict is architectural: entangling personal data with the records that explain AI behaviour. Separation by design dissolves most of it.