Deep TrustGovernance Series

Governance that holds up under pressure.

175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.

DTG-AI10 · AI Governance · 4 min

The AI System Your Employees Are Using That IT Doesn't Know About

The productivity benefits of AI tools — writing assistants, code generators, research summarizers, meeting transcription tools — are available to employees before those t…

DTG-AI09 · AI Governance · 5 min

Bias in Training Data Is Not a Technical Problem. It Is a Governance Problem

Every significant AI bias failure that has received public attention has been attributed, at some point in the post-incident analysis, to the training data.

DTG-AI03 · AI Governance · 5 min

Who Is Accountable When the AI Gets It Wrong?

This is not a rhetorical question. It is the governance question that every organization deploying consequential AI systems must be able to answer specifically, before th…

DTG-AI01 · AI Governance · 7 min

Governance Moves in Quarters. AI Risk Moves in Commits

A governance review cycle is typically quarterly. A risk committee meets monthly if you are disciplined about it. A policy update takes weeks to draft, approve, and commu…

DTG-382 · GRC & Control Reality · 10 min

Control Implementation Does Not Equal Control Effectiveness

A control that exists is not a control that works. Enterprise governance programs measure control implementation: whether a control has been defined, deployed, and docume…

DTG-372 · Board & Executive Governance · 9 min

Board-Level Reporting Highlights Trends. Not Exposure

Board risk reporting shows trends: improvement in coverage percentages, reduction in open findings, increase in training completion rates. These are activity trends.

DTG-361 · Board & Executive Governance · 9 min

Boards See Compliance. Not Operational Risk

Board risk reporting is built around compliance metrics and audit outcomes: controls in place, assessments completed, findings remediated. What it is not built around is…

DTG-352 · AI Governance · 11 min

AI Introduces Emergent Risk That Cannot Be Predefined

Traditional risk management defines risk categories in advance and builds controls against them. AI systems produce behaviors and outcomes that were not anticipated at de…

DTG-346 · AI Governance · 11 min

AI Agents Operate Autonomously. Governance Assumes Control

Traditional governance assumes a human made a decision, a system executed it, and a log recorded it. AI agents make decisions, execute actions, and produce outcomes that…

DTG-334 · Data Visibility · 10 min

Discovery Coverage Looks Complete. Until You Include APIs

Your data discovery program scans databases, file systems, and data stores. APIs are none of these things. They are channels through which sensitive data moves continuous…

DTG-329 · Data Visibility · 11 min

Sensitive Data Moves Faster Than It Can Be Discovered

Discovery tools scan what exists at the moment of the scan. Sensitive data does not wait for the scanner. By the time your classification report is generated, the data it…

DTG-326 · Data Visibility · 10 min

DSPM Reveals Risk. It Does Not Reduce It

A DSPM deployment that produces a comprehensive risk dashboard without triggering a remediation workflow has not improved the organization's security posture.

DTG-322 · Data Visibility · 10 min

Sensitive Data Is Identified. It Is Not Controlled

Data classification produces labels. Labels are not controls. The gap between identifying sensitive data and governing it effectively is wider than most discovery program…

DTG-312 · GRC & Control Reality · 9 min

Evidence Is Point-in-Time. Risk Is Continuous

Compliance evidence documents the state of controls at the time evidence was collected. Risk accumulates in the space between evidence collection events.

DTG-303 · GRC & Control Reality · 8 min

Audits Confirm Compliance. Not Effectiveness

An audit that confirms compliance confirms that the required elements exist. It does not confirm that those elements produce the intended outcomes.

DTG-299 · AI Governance · 8 min

AI Systems Process Data. They Do Not Respect Original Purpose

Purpose limitation requires that data be used only for the purpose for which it was collected. AI systems use data to learn patterns that inform behavior across any purpo…

DTG-297 · AI Governance · 8 min

AI Inference Creates New Privacy Risk Outside Original Scope

Data collected for one purpose carries the privacy risk of that purpose. An AI model trained on that data develops inference capabilities that extend far beyond the origi…

DTG-295 · AI Governance · 10 min

AI Models Retain Information You Cannot Fully Extract

You deleted the data. The model learned from it first. What it learned does not leave when the data does. This is the privacy problem that most governance programs have n…

DTG-292 · AI Governance · 9 min

AI Training Data Breaks Traditional Privacy Assumptions

Traditional privacy governance assumes personal data can be collected, used, retained, and deleted as a discrete artifact. AI training data is processed in a way that eli…

DTG-291 · AI Governance · 12 min

AI Systems Use Data Differently. Privacy Controls Do Not Adapt

Privacy controls were designed for data that is collected, stored, used for a defined purpose, and eventually deleted. AI systems collect data, transform it into learned…

DTG-282 · Cross-Border Data · 8 min

Data Processing Categories Don't Align Across Regulations

GDPR defines personal data. CCPA defines personal information. PIPL defines personal information. The definitions are similar enough to seem interchangeable.

DTG-275 · Cross-Border Data · 11 min

Opt-Out Mechanisms Exist. They Do Not Propagate Across Systems

A consumer exercises their opt-out right. The mechanism is compliant. The signal is recorded. And then it stops propagating, because the architecture was not built to car…

DTG-270 · Cross-Border Data · 8 min

Global Data Governance Requires Localized Control Models

A global data governance framework defines principles, standards, and policies that apply across the organization. A localized control model implements those principles i…

DTG-269 · Cross-Border Data · 10 min

Cross-Border Data Risk Is Identified. It Is Not Actively Managed

Organizations identify cross-border data risks in assessments, document them in records of processing activities, and note them in risk registers.

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center