175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.
The productivity benefits of AI tools — writing assistants, code generators, research summarizers, meeting transcription tools — are available to employees before those t…
Every significant AI bias failure that has received public attention has been attributed, at some point in the post-incident analysis, to the training data.
This is not a rhetorical question. It is the governance question that every organization deploying consequential AI systems must be able to answer specifically, before th…
A governance review cycle is typically quarterly. A risk committee meets monthly if you are disciplined about it. A policy update takes weeks to draft, approve, and commu…
A control that exists is not a control that works. Enterprise governance programs measure control implementation: whether a control has been defined, deployed, and docume…
Board risk reporting shows trends: improvement in coverage percentages, reduction in open findings, increase in training completion rates. These are activity trends.
Board risk reporting is built around compliance metrics and audit outcomes: controls in place, assessments completed, findings remediated. What it is not built around is…
Traditional risk management defines risk categories in advance and builds controls against them. AI systems produce behaviors and outcomes that were not anticipated at de…
Traditional governance assumes a human made a decision, a system executed it, and a log recorded it. AI agents make decisions, execute actions, and produce outcomes that…
Your data discovery program scans databases, file systems, and data stores. APIs are none of these things. They are channels through which sensitive data moves continuous…
Discovery tools scan what exists at the moment of the scan. Sensitive data does not wait for the scanner. By the time your classification report is generated, the data it…
A DSPM deployment that produces a comprehensive risk dashboard without triggering a remediation workflow has not improved the organization's security posture.
Data classification produces labels. Labels are not controls. The gap between identifying sensitive data and governing it effectively is wider than most discovery program…
Compliance evidence documents the state of controls at the time evidence was collected. Risk accumulates in the space between evidence collection events.
An audit that confirms compliance confirms that the required elements exist. It does not confirm that those elements produce the intended outcomes.
Purpose limitation requires that data be used only for the purpose for which it was collected. AI systems use data to learn patterns that inform behavior across any purpo…
Data collected for one purpose carries the privacy risk of that purpose. An AI model trained on that data develops inference capabilities that extend far beyond the origi…
You deleted the data. The model learned from it first. What it learned does not leave when the data does. This is the privacy problem that most governance programs have n…
Traditional privacy governance assumes personal data can be collected, used, retained, and deleted as a discrete artifact. AI training data is processed in a way that eli…
Privacy controls were designed for data that is collected, stored, used for a defined purpose, and eventually deleted. AI systems collect data, transform it into learned…
GDPR defines personal data. CCPA defines personal information. PIPL defines personal information. The definitions are similar enough to seem interchangeable.
A consumer exercises their opt-out right. The mechanism is compliant. The signal is recorded. And then it stops propagating, because the architecture was not built to car…
A global data governance framework defines principles, standards, and policies that apply across the organization. A localized control model implements those principles i…
Organizations identify cross-border data risks in assessments, document them in records of processing activities, and note them in risk registers.