Posts

Showing posts from August, 2026

AI Governance Has a Control Problem, Not a Policy Problem

Image
We’re getting good at writing policies about how AI should be used. Responsible AI principles. Acceptable-use policies. AI risk frameworks. Approval processes. Governance committees. All of these have a place. But there is a harder question that I think organisations need to start asking: What evidence proves those controls actually work? Because AI is changing the nature of the control problem. We are moving from AI that simply provides information to AI that can increasingly access data, make decisions, call tools, trigger workflows and take actions. And much of our traditional assurance thinking still assumes there is a human sitting somewhere in the process. That assumption is becoming increasingly uncomfortable.  Autonomy is scaling faster than assurance Consider a relatively simple AI agent. It might be able to: Read information from internal systems  Search documents and databases  Make decisions based on predefined criteria  Trigger workflows  Create or...