AI Governance Must Extend Beyond Regulatory Scope

Regulatory frameworks govern the AI systems that fall within their explicit scope. What these frameworks do not govern is the full range of AI capabilities that create organizational, operational, and societal risk but fall below or outside each regulation's specific scope definitions.

RCDr. Richard Chingombe · Founder, Verisq·8 min read·Practitioner perspective, not legal advice

Governance programs built to satisfy regulatory requirements govern what regulators have defined. The risk that AI creates is not similarly bounded.

Why This Matters Now

Regulatory AI governance frameworks are inherently retrospective and definitional. They are designed by regulators who must define scope precisely enough to create enforceable obligations. These definitions create clarity about what is within regulatory scope. They also create gaps: the AI systems that create significant risk without falling within any regulatory definition.

AI capability is evolving faster than regulatory definitions. The large language models, agentic AI systems, and AI-powered decision tools deployed in enterprise environments today do not all fit cleanly into the regulatory categories that were defined before they existed.

Regulatory scope defines the floor of AI governance, not the ceiling. The governance appropriate for any specific AI deployment is determined by the risk that deployment creates, not by whether it falls within a regulatory definition.

The Governance Problem Beneath the Surface

The governance problem is the compliance mindset applied to a risk management challenge. Compliance asks: does this AI system fall within the regulatory scope that requires governance? Risk management asks: does this AI system create risks that governance should address? These questions produce different answers for AI systems that create significant risk but fall outside regulatory definitions.

Organizations that have built AI governance programs in response to regulatory requirements have built programs designed for the regulatory scope question. They are less equipped for the risk management question, which requires assessing AI risk independently of whether regulation has caught up to it.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

What This Actually Means in Enterprise Practice

Foundation Model APIs Fall Outside Current High-Risk Classification

Large language models accessed through APIs by internal teams for drafting, analysis, summarizing, and decision support are not typically classified as high-risk AI under the EU AI Act unless they are deployed in specifically enumerated high-risk use cases. Yet foundation model APIs used for consequential organizational functions, including legal analysis, hiring-related research, and financial assessment, create AI governance risks related to accuracy, bias, privacy, and reliance that are material regardless of regulatory classification.

Internal AI Tools Below Regulatory Thresholds

AI systems developed for internal use, not deployed in consumer-facing contexts, not used in the enumerated high-risk categories, may fall below the threshold of explicit regulatory governance requirements. An AI system that helps prioritize internal engineering work or allocates internal resources creates governance considerations around fairness, accountability, and reliability that internal deployment does not exempt it from.

The governance requirement that applies to an AI system that influences consequential organizational decisions is determined by the impact of those decisions, not by whether the system is consumer-facing or internally-deployed.

AI-Augmented Human Decisions in Gray Areas

Humans making decisions with AI assistance occupy governance gray areas. The final decision is human. The AI provides information, analysis, or scoring that influences the human decision substantially. Whether this constitutes automated decision-making subject to regulatory governance depends on definitional judgments that organizations may be resolving in the most convenient rather than the most defensible direction.

Emerging AI Capabilities Without Governance Frameworks

Agentic AI systems that take actions autonomously rather than producing recommendations for human review occupy a governance space that existing regulatory frameworks were not designed for. The EU AI Act's oversight provisions envision humans reviewing AI outputs. AI agents that execute multi-step plans without per-step human review create a governance architecture for which the existing regulatory framework does not provide clear guidance.

How Different Teams See This: Where They All Miss

Legal and ComplianceIdentifying AI systems within regulatory scope. Not typically assessing risk of systems outside regulatory scope.
AI GovernanceBuilding governance programs in response to regulatory requirements. May not have a framework for governing AI systems that fall outside regulatory definitions.
Business UnitsDeploying AI tools that improve operational efficiency. Not typically assessing whether tools below regulatory threshold create governance-relevant risk.
TechnologyProvisioning AI capabilities for organizational use. Not typically distinguishing regulatory-threshold AI from below-threshold AI for governance purposes.

The gap between regulatory scope and organizational AI governance need is the space where risk accumulates as AI adoption outpaces regulatory definition. Organizations must make deliberate governance decisions about how to govern what regulation has not yet reached.

Framework Control Reference

The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.

EU AI Act | Article 9(4) and Recital 47Risk management must address reasonably foreseeable risks. Regulatory classification determines mandatory governance floors. Reasonably foreseeable risk determines appropriate governance ceilings.
NIST AI RMF | Map 1.1Organizations must categorize AI systems by risk level and govern appropriately. NIST explicitly envisions risk-based governance that extends beyond regulatory minimum requirements.
ISO 42001 | Clause 6.1AI risk and opportunity assessment must address the full range of organizational context, not only explicitly regulated AI deployments.
OECD AI Principles | Principle 1.3AI actors should proactively consider potential adverse impacts beyond regulatory minimum requirements and ensure appropriate governance throughout the AI lifecycle.
NIST CSF 2.0 | GV.RM-02Risk tolerance must be established and used to govern all activities including technology governance. Risk-based governance applies to AI regardless of regulatory classification.
SEC Cybersecurity Rules | 17 CFR 229.106Material risks from AI that affect organizational operations require disclosure and governance regardless of whether AI-specific regulation explicitly covers them.

These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.

The Enterprise Reality Gap

The enterprise AI governance reality gap beyond regulatory scope is the AI deployment population that creates organizational risk without triggering explicit regulatory governance requirements. This population is growing as AI adoption accelerates and as organizations deploy AI tools in ways that regulatory definitions did not specifically anticipate.

The AI governance gap is the space between what AI can do to an organization and what regulation has required organizations to govern. This space is larger than most AI governance programs acknowledge and growing as AI capability expands faster than regulatory definition.

Enterprise Scenario

The setupA professional services firm deploys an AI tool that assists managers in preparing performance reviews. The tool analyzes employee work product, communication patterns, and project outcomes to suggest performance ratings and promotion recommendations. The tool is not consumer-facing, is used internally, and does not fall within any enumerated high-risk AI category under the EU AI Act.
The governance gapThe tool influences consequential employment decisions for all employees. Its outputs may reflect training data that embeds historical patterns of promotion bias. Employees have no visibility into the AI tool's role in their performance assessment. Managers treat AI-suggested ratings as authoritative rather than as inputs to their own judgment. No bias assessment has been conducted.

The tool is below regulatory scope under current EU AI Act high-risk definitions. Its governance implications, including bias risk, transparency obligations to employees, and accountability for employment decisions influenced by AI, are material regardless of its regulatory classification. Governing by regulatory scope alone leaves these risks unaddressed.

Industry Signal

Employment AI governance is one of the fastest-developing areas of regulatory attention. The EU AI Act's high-risk classification of AI used in employment was developed in response to documented harms from employment AI that preceded the regulation's passage. Organizations that deployed employment AI before regulation required governance, and governed only what earlier regulations required, were exposed to risks that governance programs built to earlier regulatory standards did not address.

Regulatory scope expands to cover harms that have already occurred. Organizations that govern only what regulation currently requires will be exposed to the harms that drive the next regulatory expansion. Risk-based governance closes the gap.

Enabling Capabilities

  • AI risk assessment independent of regulatory classification: Methodology for assessing AI risk based on impact and likelihood rather than regulatory category.
  • Internal AI inventory with risk-based classification: Inventory of all AI deployments with risk assessment that produces governance requirements independent of regulatory scope.
  • Below-threshold governance standards: Defined governance standards for AI that falls below regulatory scope but creates material organizational risk.
  • Horizon scanning for regulatory evolution: Monitoring of regulatory development to anticipate scope expansion before it becomes effective.

A Practical Starting Point

Audit your AI deployment inventory for consequential influence: which AI tools influence decisions about employees, customers, or other individuals in material ways, regardless of regulatory classification? For each tool identified, apply a basic risk assessment: what harm could result from bias or error, and who would be affected?

Risk-based AI governance starts with the impact question, not the regulatory classification question. What harm could this AI cause? Who could be affected? That is the governance starting point.

Questions Leaders Should Be Asking

  • Do we have an inventory of all AI tools used to make or influence consequential decisions about employees or customers, regardless of whether those tools fall within explicit regulatory high-risk categories?
  • For AI tools that fall below regulatory scope thresholds, have we conducted risk assessments based on impact and potential harm rather than regulatory classification?
  • What is our governance standard for AI tools that create material risk but fall outside current regulatory requirements?
  • How does our AI governance program anticipate regulatory scope expansion rather than reacting to it after effective dates pass?

What to Require From Vendors

Ask directly:

"Beyond regulatory compliance documentation, what risk-based governance does your organization apply to AI tools that fall below regulatory scope thresholds but influence consequential decisions about users?"

Expect as evidence:
  • Risk-based governance standards applied to all consequential AI, not only regulatory-classified high-risk AI
  • Bias assessment records for AI tools below regulatory thresholds
  • Transparency documentation for AI influence on consequential decisions

A vendor who provides AI governance documentation only for regulatory-classified high-risk AI without governance for below-threshold AI that influences consequential decisions has built compliance-minimum governance. Ask for risk-based governance evidence.

Demonstrating Diligence

  • Documentation: AI inventory with risk-based classification beyond regulatory scope; governance standards for below-threshold AI; impact-based risk assessment records.
  • Process: Risk-based AI governance extension process; regulatory horizon scanning; below-threshold AI governance review program.
  • Technical evidence: Below-threshold AI risk assessment records; bias assessment for employment AI; transparency documentation for AI-influenced decisions.

AI governance diligence requires demonstrating that governance follows risk, not only regulatory classification.

Closing Perspective

Regulatory AI governance frameworks define important minimum standards. They are designed to be enforceable, which requires precision in scope definition. This precision inevitably creates gaps: the AI deployments that create material risk without fitting precisely within regulatory definitions.

Organizations that govern only what regulation requires are accepting the risk that falls in those gaps.

AI governance should be determined by the risk AI creates, not by the boundaries of what regulators have so far defined. Build governance that follows the risk.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.