175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.
Global enterprises operate under different regulatory obligations in different jurisdictions. Their systems were built for efficiency, not jurisdictional differentiation.
Security incidents in cross-border data environments do not wait for regulatory notification timelines, governance approval chains, or the coordination complexity of mult…
Data residency controls where data rests. It does not control where data is processed, accessed, or analyzed. In cloud architectures, processing routinely occurs across r…
Encryption is a technically effective data protection control. It prevents unauthorized access to data in transit and at rest. It does not prevent authorized access, incl…
Your data governance program maps the flows you know about. Vendor ecosystems create flows you did not design, did not authorize, and may not know exist.
You contracted with a vendor. You reviewed their DPA. You confirmed their security certifications. What you did not do is follow your data through the subprocessors they…
Data sovereignty requires that data stay within a defined jurisdiction. Distributed systems are architecturally designed to move data across boundaries for resilience, pe…
Data localization requires that data stay within defined geographic boundaries. Cloud architectures are designed to distribute data across boundaries for performance, ava…
Standard Contractual Clauses create a legal framework for cross-border data transfers. They do not create operational controls that constrain what happens to data after i…
Organizations document the cross-border data flows they know about. The flows they do not know about are determined by how their technology architecture actually behaves.
Data residency defines where data should be. Data movement defines where data goes. In modern enterprise architectures, these two things are frequently different, and the…
Every AI governance requirement that references data, training data quality, data minimization, purpose limitation, data subject rights, data lineage, assumes the existen…
Traditional change management was designed for discrete, intentional changes: a software release, a configuration update. AI systems change in ways that are gradual, emer…
AI model development is governed by the best process discipline in most organizations: version control, testing, review, documentation, approval.
Regulatory frameworks govern the AI systems that fall within their explicit scope. What these frameworks do not govern is the full range of AI capabilities that create or…
Every compliance assessment produces a result that was accurate when it was produced. The environment that assessment described has continued changing from the moment it…
Article 72 of the EU AI Act requires deployers of high-risk AI systems to implement post-market monitoring. Most organizations have interpreted this as establishing a mon…
Every AI governance framework that addresses accountability requires traceability: the ability to follow a decision back through the system that made it, to the data that…
Every AI governance framework that addresses bias requires that it be detected and mitigated. What no framework specifies is which measurement methodology constitutes ade…
The quality of an AI model's output is bounded by the quality of the data it learned from. Organizations that deploy AI systems without verifying the quality of their tra…
Human oversight was designed to review AI outputs before they produce consequences. Automated workflows execute AI outputs immediately, at machine speed, connecting AI re…
Human oversight of AI systems is required by virtually every AI governance framework. Organizations implement it through review queues, exception processes, and human-in-…
Regulators require that humans remain in control of consequential AI decisions. Operational reality requires that AI systems process thousands of decisions per hour.
The output of an AI system is what the system produced. The decision logic is why it produced it. These are not the same thing. Governance that evaluates outputs without…