AI Governance
Your AI policy is a PDF. Your risk is operational.
AI is no longer only automating work. It is shaping how people interpret information and form judgements before decisions are made. Most AI governance inspects the artefacts it can see, the model, the prompt, the output, the approval, and misses the reasoning pathway that produced them.
The Gap
"There is a dangerous delta between the boardroom view, 'we blocked the tool', and the desk view, 'everyone is using AI on their own devices'."
A policy document written six months ago is already obsolete. The models have changed, the vendors have updated their terms, and staff have found new workarounds. But the deeper problem sits above even that: AI is entering the judgement-formation pathway itself, framing the problem, narrowing the options, drafting the recommendation, and no existing governance framework was built to look there.
Figure — The AI Risk Iceberg
Security protects the visible perimeter. The larger mass of the risk sits below the waterline, in behaviour, leadership and strategic alignment.
The Diagnostic
Four questions your risk team should be able to answer today
- 01
Data leakage (input risk)
Most firms block a handful of named AI tools but do not flag the behaviour of pasting client names or portfolio data into any browser text field, including grammar and summarisation tools and PDF analysers nobody has vetted.
- 02
Fourth-party AI sub-processors
You know your vendors. Do you know their AI sub-processors? A research platform you subscribe to integrates a summarisation model. If it hallucinates a figure and someone acts on it, who is liable?
- 03
Ground truth and human-in-the-loop
If someone uses AI to draft advice, what control actually verifies accuracy? Models are sycophantic by default: they tell the user what they expect to hear. Is there a mandatory source check?
- 04
Shadow budget visibility
Staff routinely expense specific AI subscriptions under generic categories like "productivity" or "research" to bypass procurement. Have expense reports actually been audited for this?
The Thesis
"Human in the loop" is weaker than it looks.
It assumes a clean separation: the system recommends, the human reviews, the human decides. But if the same system helped frame the issue, narrow the options and draft the recommendation, the human is not reviewing from a position of clean independence. They are reviewing a decision pathway the machine has already substantially shaped.
The AI Efficacy Sprint
Stress-test the policy against operational reality
A fixed-fee diagnostic that tests the four questions above against your actual environment, not the policy document, and hands back a board-ready finding on where the gap between stated and operational reality actually sits.
Related reading
AI-Mediated Judgement Formation →
The governance problem hiding in plain sight.
The Shadow in the Machine →
Why AI attacks judgement, not data.
Architecting AI Mediation Security →
Why human-in-the-loop fails, and the control taxonomy that secures the judgement layer.
AI Governance Needs to Move Upstream →
Governing the decision after the judgement is already formed is too late.