Governance programs built to satisfy regulatory requirements govern what regulators have defined. The risk that AI creates is not similarly bounded.
Why This Matters Now
Regulatory AI governance frameworks are inherently retrospective and definitional. They are designed by regulators who must define scope precisely enough to create enforceable obligations. These definitions create clarity about what is within regulatory scope. They also create gaps: the AI systems that create significant risk without falling within any regulatory definition.
AI capability is evolving faster than regulatory definitions. The large language models, agentic AI systems, and AI-powered decision tools deployed in enterprise environments today do not all fit cleanly into the regulatory categories that were defined before they existed.
Regulatory scope defines the floor of AI governance, not the ceiling. The governance appropriate for any specific AI deployment is determined by the risk that deployment creates, not by whether it falls within a regulatory definition.
The Governance Problem Beneath the Surface
The governance problem is the compliance mindset applied to a risk management challenge. Compliance asks: does this AI system fall within the regulatory scope that requires governance? Risk management asks: does this AI system create risks that governance should address? These questions produce different answers for AI systems that create significant risk but fall outside regulatory definitions.
Organizations that have built AI governance programs in response to regulatory requirements have built programs designed for the regulatory scope question. They are less equipped for the risk management question, which requires assessing AI risk independently of whether regulation has caught up to it.
What This Actually Means in Enterprise Practice
Foundation Model APIs Fall Outside Current High-Risk Classification
Large language models accessed through APIs by internal teams for drafting, analysis, summarizing, and decision support are not typically classified as high-risk AI under the EU AI Act unless they are deployed in specifically enumerated high-risk use cases. Yet foundation model APIs used for consequential organizational functions, including legal analysis, hiring-related research, and financial assessment, create AI governance risks related to accuracy, bias, privacy, and reliance that are material regardless of regulatory classification.
Internal AI Tools Below Regulatory Thresholds
AI systems developed for internal use, not deployed in consumer-facing contexts, not used in the enumerated high-risk categories, may fall below the threshold of explicit regulatory governance requirements. An AI system that helps prioritize internal engineering work or allocates internal resources creates governance considerations around fairness, accountability, and reliability that internal deployment does not exempt it from.
The governance requirement that applies to an AI system that influences consequential organizational decisions is determined by the impact of those decisions, not by whether the system is consumer-facing or internally-deployed.
AI-Augmented Human Decisions in Gray Areas
Humans making decisions with AI assistance occupy governance gray areas. The final decision is human. The AI provides information, analysis, or scoring that influences the human decision substantially. Whether this constitutes automated decision-making subject to regulatory governance depends on definitional judgments that organizations may be resolving in the most convenient rather than the most defensible direction.
Emerging AI Capabilities Without Governance Frameworks
Agentic AI systems that take actions autonomously rather than producing recommendations for human review occupy a governance space that existing regulatory frameworks were not designed for. The EU AI Act's oversight provisions envision humans reviewing AI outputs. AI agents that execute multi-step plans without per-step human review create a governance architecture for which the existing regulatory framework does not provide clear guidance.
How Different Teams See This: Where They All Miss
The gap between regulatory scope and organizational AI governance need is the space where risk accumulates as AI adoption outpaces regulatory definition. Organizations must make deliberate governance decisions about how to govern what regulation has not yet reached.
Framework Control Reference
The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.
These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.
The Enterprise Reality Gap
The enterprise AI governance reality gap beyond regulatory scope is the AI deployment population that creates organizational risk without triggering explicit regulatory governance requirements. This population is growing as AI adoption accelerates and as organizations deploy AI tools in ways that regulatory definitions did not specifically anticipate.
The AI governance gap is the space between what AI can do to an organization and what regulation has required organizations to govern. This space is larger than most AI governance programs acknowledge and growing as AI capability expands faster than regulatory definition.
Enterprise Scenario
The tool is below regulatory scope under current EU AI Act high-risk definitions. Its governance implications, including bias risk, transparency obligations to employees, and accountability for employment decisions influenced by AI, are material regardless of its regulatory classification. Governing by regulatory scope alone leaves these risks unaddressed.
Industry Signal
Employment AI governance is one of the fastest-developing areas of regulatory attention. The EU AI Act's high-risk classification of AI used in employment was developed in response to documented harms from employment AI that preceded the regulation's passage. Organizations that deployed employment AI before regulation required governance, and governed only what earlier regulations required, were exposed to risks that governance programs built to earlier regulatory standards did not address.
Regulatory scope expands to cover harms that have already occurred. Organizations that govern only what regulation currently requires will be exposed to the harms that drive the next regulatory expansion. Risk-based governance closes the gap.
Enabling Capabilities
- AI risk assessment independent of regulatory classification: Methodology for assessing AI risk based on impact and likelihood rather than regulatory category.
- Internal AI inventory with risk-based classification: Inventory of all AI deployments with risk assessment that produces governance requirements independent of regulatory scope.
- Below-threshold governance standards: Defined governance standards for AI that falls below regulatory scope but creates material organizational risk.
- Horizon scanning for regulatory evolution: Monitoring of regulatory development to anticipate scope expansion before it becomes effective.
A Practical Starting Point
Audit your AI deployment inventory for consequential influence: which AI tools influence decisions about employees, customers, or other individuals in material ways, regardless of regulatory classification? For each tool identified, apply a basic risk assessment: what harm could result from bias or error, and who would be affected?
Risk-based AI governance starts with the impact question, not the regulatory classification question. What harm could this AI cause? Who could be affected? That is the governance starting point.
Questions Leaders Should Be Asking
- Do we have an inventory of all AI tools used to make or influence consequential decisions about employees or customers, regardless of whether those tools fall within explicit regulatory high-risk categories?
- For AI tools that fall below regulatory scope thresholds, have we conducted risk assessments based on impact and potential harm rather than regulatory classification?
- What is our governance standard for AI tools that create material risk but fall outside current regulatory requirements?
- How does our AI governance program anticipate regulatory scope expansion rather than reacting to it after effective dates pass?
What to Require From Vendors
Ask directly:
"Beyond regulatory compliance documentation, what risk-based governance does your organization apply to AI tools that fall below regulatory scope thresholds but influence consequential decisions about users?"
Expect as evidence:
- Risk-based governance standards applied to all consequential AI, not only regulatory-classified high-risk AI
- Bias assessment records for AI tools below regulatory thresholds
- Transparency documentation for AI influence on consequential decisions
A vendor who provides AI governance documentation only for regulatory-classified high-risk AI without governance for below-threshold AI that influences consequential decisions has built compliance-minimum governance. Ask for risk-based governance evidence.
Demonstrating Diligence
- Documentation: AI inventory with risk-based classification beyond regulatory scope; governance standards for below-threshold AI; impact-based risk assessment records.
- Process: Risk-based AI governance extension process; regulatory horizon scanning; below-threshold AI governance review program.
- Technical evidence: Below-threshold AI risk assessment records; bias assessment for employment AI; transparency documentation for AI-influenced decisions.
AI governance diligence requires demonstrating that governance follows risk, not only regulatory classification.
Closing Perspective
Regulatory AI governance frameworks define important minimum standards. They are designed to be enforceable, which requires precision in scope definition. This precision inevitably creates gaps: the AI deployments that create material risk without fitting precisely within regulatory definitions.
Organizations that govern only what regulation requires are accepting the risk that falls in those gaps.
AI governance should be determined by the risk AI creates, not by the boundaries of what regulators have so far defined. Build governance that follows the risk.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
