Thanks for this. The register nails ownership, but banking already ran this experiment under model risk management, and inventory alone never produced the accountability regulators wanted. U.S. bank regulators just revised that guidance this April, replacing the 2011-era SR 11-7 rules, and it still rests on the same three pillars: inventory, independent validation, and governance, with inventory being the easiest of the three to build. Validation is the pillar that actually bites: someone with no stake in the model's success, testing whether the owner's controls actually hold. Your behavioral-testing-before-onboarding move is reaching for exactly that, so the sharper version of your 72-hour test might be whether the executive can also name who checks the owner, independent of the owner.
Christine Dietzsch shared your article with me, and it immediately resonated.
I especially appreciated your point that AI governance isn't fundamentally a technology problem—it's an organizational one. Policies, accountability, leadership, and culture must work together. Otherwise, governance becomes something people work around instead of something that enables innovation.
That's the same conclusion we've reached at Ethic Vault from a complementary direction. Our work is centered on Governance Before Consequence—ensuring AI-assisted actions are evaluated against organizational policies, trusted data, and delegated authority before they become organizational commitments.
Our governed execution layer sits between AI recommendations and organizational commitments. If an action is within policy, it proceeds. If it isn't, it stops. If judgment is required, it routes the decision to the appropriate person with the supporting evidence and records the outcome for accountability and continuous improvement.
The goal isn't to slow innovation; it's to make the governed path the easiest path.
I suspect we're trying to solve the same problem from different directions. I'd enjoy comparing notes sometime.
Thank you — and my thanks to Christine for passing it along.
"Making the governed path the easiest path" is the line I would underline twice. Most shadow AI I've seen wasn't built out of defiance. It was built because the official path was slower than the workaround.
One question your model raises for me: an execution layer can enforce policy at machine speed. It cannot own the policy. When judgment is required, it routes the decision to "the appropriate person" — which works exactly as long as the organization can name that person. Same problem, one layer down. In my experience, that's where implementations get quiet.
So yes: same problem, two directions. You start from enforcement, I start from ownership. Neither works without the other. Happy to compare notes.
Thanks for this. The register nails ownership, but banking already ran this experiment under model risk management, and inventory alone never produced the accountability regulators wanted. U.S. bank regulators just revised that guidance this April, replacing the 2011-era SR 11-7 rules, and it still rests on the same three pillars: inventory, independent validation, and governance, with inventory being the easiest of the three to build. Validation is the pillar that actually bites: someone with no stake in the model's success, testing whether the owner's controls actually hold. Your behavioral-testing-before-onboarding move is reaching for exactly that, so the sharper version of your 72-hour test might be whether the executive can also name who checks the owner, independent of the owner.
Christine Dietzsch shared your article with me, and it immediately resonated.
I especially appreciated your point that AI governance isn't fundamentally a technology problem—it's an organizational one. Policies, accountability, leadership, and culture must work together. Otherwise, governance becomes something people work around instead of something that enables innovation.
That's the same conclusion we've reached at Ethic Vault from a complementary direction. Our work is centered on Governance Before Consequence—ensuring AI-assisted actions are evaluated against organizational policies, trusted data, and delegated authority before they become organizational commitments.
Our governed execution layer sits between AI recommendations and organizational commitments. If an action is within policy, it proceeds. If it isn't, it stops. If judgment is required, it routes the decision to the appropriate person with the supporting evidence and records the outcome for accountability and continuous improvement.
The goal isn't to slow innovation; it's to make the governed path the easiest path.
I suspect we're trying to solve the same problem from different directions. I'd enjoy comparing notes sometime.
Thank you — and my thanks to Christine for passing it along.
"Making the governed path the easiest path" is the line I would underline twice. Most shadow AI I've seen wasn't built out of defiance. It was built because the official path was slower than the workaround.
One question your model raises for me: an execution layer can enforce policy at machine speed. It cannot own the policy. When judgment is required, it routes the decision to "the appropriate person" — which works exactly as long as the organization can name that person. Same problem, one layer down. In my experience, that's where implementations get quiet.
So yes: same problem, two directions. You start from enforcement, I start from ownership. Neither works without the other. Happy to compare notes.