Skip to main content
Theme 02 of 16

AI Governance

The distance between what these systems can do and what any institution is equipped to oversee is the widest in any field we work on, and it is still opening. Rules drafted for products that ship once, in a fixed form, with a manufacturer who can be inspected, do not fit systems that change weekly, behave differently in each deployment, and are frequently assembled from components nobody in the chain fully controls.

The failure mode we see most often is not absent regulation but unenforceable regulation. An obligation is written in terms that cannot be audited — 'appropriate safeguards', 'adequate human oversight' — and is then administered by a body with two technical staff for several hundred deployments. What follows is a compliance industry rather than compliance: documentation improves, assessment reports multiply, and nobody establishes whether the systems concerned produce defensible decisions. A well-documented bad system reads better than a badly documented good one, every time.

We work on governance that survives contact with practice. Obligations expressed with enough technical specificity that an auditor could fail a system against them. Evaluation that measures behaviour in the population actually being treated rather than laboratory performance. Review triggered before deployment rather than after harm, with a stopping rule defined in advance. Supervisory bodies with the staff, the pay scales and the statutory access to exercise the powers they already hold. And, throughout, the question that is asked far less often than it should be: does this mechanism change outcomes, or does it only change what gets written down?

16 items across our work