AI Governance

Your AI policy is a PDF. Your risk is operational.

AI is no longer only automating work. It is shaping how people interpret information and form judgements before decisions are made. Most AI governance inspects the artefacts it can see, the model, the prompt, the output, the approval, and misses the reasoning pathway that produced them.

The Gap

"There is a dangerous delta between the boardroom view, 'we blocked the tool', and the desk view, 'everyone is using AI on their own devices'."

A policy document written six months ago is already obsolete. The models have changed, the vendors have updated their terms, and staff have found new workarounds. But the deeper problem sits above even that: AI is entering the judgement-formation pathway itself, framing the problem, narrowing the options, drafting the recommendation, and no existing governance framework was built to look there.

Figure — The AI Risk Iceberg

VISIBLEAbove the waterlineTechnology, tools, processesBelow the waterlineStrategy and alignmentLeadershipBehaviour and engagement

Security protects the visible perimeter. The larger mass of the risk sits below the waterline, in behaviour, leadership and strategic alignment.

The Diagnostic

Four questions your risk team should be able to answer today

  1. 01

    Data leakage (input risk)

    Most firms block a handful of named AI tools but do not flag the behaviour of pasting client names or portfolio data into any browser text field, including grammar and summarisation tools and PDF analysers nobody has vetted.

  2. 02

    Fourth-party AI sub-processors

    You know your vendors. Do you know their AI sub-processors? A research platform you subscribe to integrates a summarisation model. If it hallucinates a figure and someone acts on it, who is liable?

  3. 03

    Ground truth and human-in-the-loop

    If someone uses AI to draft advice, what control actually verifies accuracy? Models are sycophantic by default: they tell the user what they expect to hear. Is there a mandatory source check?

  4. 04

    Shadow budget visibility

    Staff routinely expense specific AI subscriptions under generic categories like "productivity" or "research" to bypass procurement. Have expense reports actually been audited for this?

The Thesis

"Human in the loop" is weaker than it looks.

It assumes a clean separation: the system recommends, the human reviews, the human decides. But if the same system helped frame the issue, narrow the options and draft the recommendation, the human is not reviewing from a position of clean independence. They are reviewing a decision pathway the machine has already substantially shaped.

The AI Efficacy Sprint

Stress-test the policy against operational reality

A fixed-fee diagnostic that tests the four questions above against your actual environment, not the policy document, and hands back a board-ready finding on where the gap between stated and operational reality actually sits.

The policy is written. The operational reality is not tested.

Vyfority stress-tests AI governance against what your organisation actually does, not what the intranet PDF says it does.