DTG-AI34 · AI Governance · 4 min

Using AI to Govern AI: Promise, Limitation, and Practical Reality

The proposition has intuitive appeal: if AI systems are too complex and too fast-moving for human governance processes to keep pace with, use AI to govern them.

DTG-AI31 · AI Governance · 5 min

Prompt Injection Is Not a Niche Threat. It Is a Governance Gap

Prompt injection is an attack technique in which malicious instructions are embedded in content that an AI system reads and processes, causing the system to follow the ma…

DTG-AI29 · AI Governance · 5 min

AI Supply Chain Risk Is Third-Party Risk at a New Level of Complexity

Third-party risk management was built around a manageable abstraction: the vendor has access to data or systems, the vendor's security practices affect the organization's…

DTG-AI28 · AI Governance · 5 min

The Privacy Risk Nobody Modeled: What AI Inference Can Reconstruct

Privacy law is built around data. Personal data is collected, processed, stored, and shared — and each of these activities creates obligations.

DTG-AI26 · AI Governance · 4 min

When the AI Model Becomes a Regulatory Subject

The EU AI Act came into force in August 2024. Its first wave of obligations — prohibitions on unacceptable-risk AI systems — applied from February 2025.

DTG-AI23 · AI Governance · 4 min

The Vendor Said the Model Was Safe. Safe for Whom?

AI vendor safety claims are expressed as general properties: the model has been red teamed, content safety filters are applied, the model has been evaluated on standard b…

DTG-AI22 · AI Governance · 4 min

Rethinking Model Risk Management for the Generative AI Era

Model risk management was developed in financial services to govern the quantitative models used in credit scoring, trading, and risk calculation.

DTG-AI15 · AI Governance · 6 min

Agentic AI Has Arrived. Your Governance Program Has Not

AI agents are not chatbots. They are autonomous systems that plan multi-step tasks, use tools to interact with external systems, make decisions without human approval at…

DTG-AI10 · AI Governance · 4 min

The AI System Your Employees Are Using That IT Doesn't Know About

The productivity benefits of AI tools — writing assistants, code generators, research summarizers, meeting transcription tools — are available to employees before those t…

DTG-AI09 · AI Governance · 5 min

Bias in Training Data Is Not a Technical Problem. It Is a Governance Problem

Every significant AI bias failure that has received public attention has been attributed, at some point in the post-incident analysis, to the training data.

DTG-AI03 · AI Governance · 5 min

Who Is Accountable When the AI Gets It Wrong?

This is not a rhetorical question. It is the governance question that every organization deploying consequential AI systems must be able to answer specifically, before th…

DTG-AI01 · AI Governance · 7 min

Governance Moves in Quarters. AI Risk Moves in Commits

A governance review cycle is typically quarterly. A risk committee meets monthly if you are disciplined about it. A policy update takes weeks to draft, approve, and commu…

DTG-352 · AI Governance · 11 min

AI Introduces Emergent Risk That Cannot Be Predefined

Traditional risk management defines risk categories in advance and builds controls against them. AI systems produce behaviors and outcomes that were not anticipated at de…

DTG-346 · AI Governance · 11 min

AI Agents Operate Autonomously. Governance Assumes Control

Traditional governance assumes a human made a decision, a system executed it, and a log recorded it. AI agents make decisions, execute actions, and produce outcomes that…

DTG-299 · AI Governance · 8 min

AI Systems Process Data. They Do Not Respect Original Purpose

Purpose limitation requires that data be used only for the purpose for which it was collected. AI systems use data to learn patterns that inform behavior across any purpo…

DTG-297 · AI Governance · 8 min

AI Inference Creates New Privacy Risk Outside Original Scope

Data collected for one purpose carries the privacy risk of that purpose. An AI model trained on that data develops inference capabilities that extend far beyond the origi…

DTG-295 · AI Governance · 10 min

AI Models Retain Information You Cannot Fully Extract

You deleted the data. The model learned from it first. What it learned does not leave when the data does. This is the privacy problem that most governance programs have n…

DTG-292 · AI Governance · 9 min

AI Training Data Breaks Traditional Privacy Assumptions

Traditional privacy governance assumes personal data can be collected, used, retained, and deleted as a discrete artifact. AI training data is processed in a way that eli…

DTG-291 · AI Governance · 12 min

AI Systems Use Data Differently. Privacy Controls Do Not Adapt

Privacy controls were designed for data that is collected, stored, used for a defined purpose, and eventually deleted. AI systems collect data, transform it into learned…

DTG-240 · AI Governance · 11 min

AI Governance Depends on Data Governance That Does Not Exist

Every AI governance requirement that references data, training data quality, data minimization, purpose limitation, data subject rights, data lineage, assumes the existen…

DTG-238 · AI Governance · 7 min

Change Management Exists. AI Evolution Outpaces It

Traditional change management was designed for discrete, intentional changes: a software release, a configuration update. AI systems change in ways that are gradual, emer…

DTG-237 · AI Governance · 10 min

Model Development Is Controlled. Deployment Introduces New Risk

AI model development is governed by the best process discipline in most organizations: version control, testing, review, documentation, approval.

DTG-230 · AI Governance · 8 min

AI Governance Must Extend Beyond Regulatory Scope

Regulatory frameworks govern the AI systems that fall within their explicit scope. What these frameworks do not govern is the full range of AI capabilities that create or…

DTG-225 · AI Governance · 7 min

Post-Market Monitoring Is Required. It Is Not Continuous

Article 72 of the EU AI Act requires deployers of high-risk AI systems to implement post-market monitoring. Most organizations have interpreted this as establishing a mon…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center