AI Governance Frameworks in the Age of Regulation
The EU AI Act’s high-risk obligations are enforceable now. The organisations coping best extended the data governance they already had rather than building a separate compliance function.
White papers from delivery work — what actually moves a governance programme forward, and what quietly stalls one.
Free to read. No registration.
The EU AI Act’s high-risk obligations are enforceable now. The organisations coping best extended the data governance they already had rather than building a separate compliance function.
Most framework diagrams are pictures of an ideal state nobody reaches. Five layers built around accountability, enforcement and evidence — and which one fails first.
Run privacy as a legal workstream parallel to governance and you get two inventories, two classification schemes and two answers for the same regulator.
Generative AI broke the assumptions model governance was built on. Provenance, prompt and output auditing, and authority tiers for agents that act rather than answer.
A model produces an answer, someone senior asks why, and nobody can trace it back. That answer lives in metadata — and it has to be captured before it is needed.
Centralised governance stops scaling; fully devolved governance produces an estate nobody can reconcile. How to draw the global–local line so federation actually holds.
The first catalog generation answered “what data do we have?” Almost nobody asked. Active metadata answers “can I use this?” — and enforces the answer.
Most organisations do not lack a governance framework. They lack a governance practice. A phased roadmap for closing the gap, and what to sequence first.
Governance programmes are rarely killed outright — they are defunded quietly because nobody could articulate what the last two years bought. How to build a case finance accepts.
These papers reflect problems we see repeatedly. If one of them describes your situation, we would be glad to compare notes.
Get in Touch