AI Governance Has a Control Problem, Not a Policy Problem
We’re getting good at writing policies about how AI should be used. Responsible AI principles. Acceptable-use policies. AI risk frameworks. Approval processes. Governance committees. All of these have a place. But there is a harder question that I think organisations need to start asking: What evidence proves those controls actually work? Because AI is changing the nature of the control problem. We are moving from AI that simply provides information to AI that can increasingly access data, make decisions, call tools, trigger workflows and take actions. And much of our traditional assurance thinking still assumes there is a human sitting somewhere in the process. That assumption is becoming increasingly uncomfortable. Autonomy is scaling faster than assurance Consider a relatively simple AI agent. It might be able to: Read information from internal systems Search documents and databases Make decisions based on predefined criteria Trigger workflows Create or...