32 articles in the AI Governance track of the Deep Trust Governance Series.
The proposition has intuitive appeal: if AI systems are too complex and too fast-moving for human governance processes to keep pace with, use AI to govern them.
Prompt injection is an attack technique in which malicious instructions are embedded in content that an AI system reads and processes, causing the system to follow the ma…
Third-party risk management was built around a manageable abstraction: the vendor has access to data or systems, the vendor's security practices affect the organization's…
Privacy law is built around data. Personal data is collected, processed, stored, and shared — and each of these activities creates obligations.
The EU AI Act came into force in August 2024. Its first wave of obligations — prohibitions on unacceptable-risk AI systems — applied from February 2025.
AI vendor safety claims are expressed as general properties: the model has been red teamed, content safety filters are applied, the model has been evaluated on standard b…
Model risk management was developed in financial services to govern the quantitative models used in credit scoring, trading, and risk calculation.
AI agents are not chatbots. They are autonomous systems that plan multi-step tasks, use tools to interact with external systems, make decisions without human approval at…
The productivity benefits of AI tools — writing assistants, code generators, research summarizers, meeting transcription tools — are available to employees before those t…
Every significant AI bias failure that has received public attention has been attributed, at some point in the post-incident analysis, to the training data.
This is not a rhetorical question. It is the governance question that every organization deploying consequential AI systems must be able to answer specifically, before th…
A governance review cycle is typically quarterly. A risk committee meets monthly if you are disciplined about it. A policy update takes weeks to draft, approve, and commu…
Traditional risk management defines risk categories in advance and builds controls against them. AI systems produce behaviors and outcomes that were not anticipated at de…
Traditional governance assumes a human made a decision, a system executed it, and a log recorded it. AI agents make decisions, execute actions, and produce outcomes that…
Purpose limitation requires that data be used only for the purpose for which it was collected. AI systems use data to learn patterns that inform behavior across any purpo…
Data collected for one purpose carries the privacy risk of that purpose. An AI model trained on that data develops inference capabilities that extend far beyond the origi…
You deleted the data. The model learned from it first. What it learned does not leave when the data does. This is the privacy problem that most governance programs have n…
Traditional privacy governance assumes personal data can be collected, used, retained, and deleted as a discrete artifact. AI training data is processed in a way that eli…
Privacy controls were designed for data that is collected, stored, used for a defined purpose, and eventually deleted. AI systems collect data, transform it into learned…
Every AI governance requirement that references data, training data quality, data minimization, purpose limitation, data subject rights, data lineage, assumes the existen…
Traditional change management was designed for discrete, intentional changes: a software release, a configuration update. AI systems change in ways that are gradual, emer…
AI model development is governed by the best process discipline in most organizations: version control, testing, review, documentation, approval.
Regulatory frameworks govern the AI systems that fall within their explicit scope. What these frameworks do not govern is the full range of AI capabilities that create or…
Article 72 of the EU AI Act requires deployers of high-risk AI systems to implement post-market monitoring. Most organizations have interpreted this as establishing a mon…