Governing the Machine

Why AI governance starts beneath the AI — in the data, policies, and control plane every model and agent draws on.

Thought leadership · The Iceberg of AI Governance

Adoption outran assurance.

Generative and agentic AI reached production faster than assurance. With no prescriptive U.S. standard, each organization must define its own standard and prove that it holds.

“A policy document applies when someone remembers to check it.”

87%


of leaders in the highest-adopting sectors planned further generative-AI investment within a year.

90%


of those had a dedicated budget — adoption is funded and accelerating.

5%

reported privacy-risk measures for LLMs.

Written policy 68%
LLM privacy measures 5%

A written employee-use policy is not a control: it shows intent, not what actually happened.

Adoption Outran Assurance — 87% planning more gen-AI investment, 90% with dedicated budget, 5% with LLM privacy measures.
Adoption is funded and accelerating — assurance has not kept pace.
Policy is not Control — 68% written employee-use policy vs 5% LLM privacy measures in place. Intent is not evidence.
68% written policy vs 5% LLM privacy measures — intent is not evidence.

Key findings, in slides.

Blotato-grade visuals from Governing the Machine — swipe or use the controls.

From the model to the assembled system.

Agentic systems combine foundation models, tools and connectors, retrieval services, and third-party agents at runtime — often over unstructured data the organization does not own. Observability must cover decisions and actions end-to-end.

The failure mode: a system that appears to be working — not a crash, an unrequested result claiming success.
The dangerous failure mode is an apparently successful system producing an unrequested result.
Diagram: risk shifted from a bounded model to an assembled agentic system
Risk moved from a bounded model to the assembled agentic system.

Then

Model risk

Classical model validation assumed a bounded artifact. Governance inventories tracked models.

Now

Assembled agentic system

Runtime composition of models, tools, retrieval, and third-party agents. The risk object moved one layer out — and one layer down into context.

The failure mode is not a system crashing. It is a system that appears to be working.

An apparently successful system producing an unrequested result — or claiming success for an action it did not take.

42%


of distinct controls overlap between AI governance and established predictive-model governance.

33


AI risks mapped across security, operational, regulatory, content-harm, and model-risk classes.

“The risk lives one layer down, in the data and policies every model and agent draws on.”

Separate reasoning from execution.

Agents interpret intent and produce plans. A control plane enforces policy and approvals. Deterministic workflows execute approved plans. Immutable logs, metering, and quality signals create evidence.

Working Reference Model — Reasoning, Control plane, Deterministic execution, Evidence with labeled components
Working reference model — Intent → plan → policy & approval → approved execution → immutable evidence
Reasoning Control plane Deterministic execution Evidence Intent → plan → policy & approval → approved execution → immutable evidence
01

Reasoning

Agents interpret intent

Agents interpret intent and produce plans — they reason; they do not silently execute irreversible action.

02

Control plane

Policy enforced as code

Identity, entitlement, filtering, approval, and logging enforced in the platform itself — not remembered in a document.

03

Deterministic execution

Approved plans only

Deterministic workflows execute approved plans. The dangerous failure mode is an apparently successful unrequested result.

04

Evidence

Immutable by design

Immutable logs, metering, and quality signals create evidence as a by-product of the control plane.

“Every model and agent is only as sound as the data, documents and policies beneath it.” Governing the underlying context — fit-for-purpose data, quality, privacy, metadata, lineage, ownership/stewardship and access policies — is essential.

What to do now.

Practical moves from Governing the Machine that put governance beneath the AI, not beside it.

  1. 01

    Set the standard

    Define the standard your organization will hold itself to — then build the means to prove it holds.

  2. 02

    Build an AI register beyond the model inventory

    Inventory assembled systems: models, tools, connectors, retrieval services, and third-party agents — not models alone.

  3. 03

    Govern the underlying layer

    Fit-for-purpose data, quality, privacy, metadata, lineage, ownership/stewardship, and access policies. Do not govern agents and models without governing the data and policies underneath them.

  4. 04

    Encode controls in the platform

    Move identity, entitlement, filtering, approval, and logging into a control plane written as code — so a rule applies to every agent and evidence is a by-product.

  5. 05

    Match controls to risk

    Map preventive gateway controls to security risk, continuous detective controls to operational risk, and classical validation to model risk — across the 33 named AI risks.

Governing the Machine

Why AI Governance Starts Beneath the AI

Chris Nobili & Ashwin Nayak · Auditrol, Inc. · September 2026 · 12 pages

“Do not govern agents and models without governing the data and policies underneath them.” Read the full argument for a control plane that produces evidence as a by-product.

AI Control.bot

Governing the Machine

Why AI Governance Starts Beneath the AI

Chris Nobili & Ashwin Nayak

September 2026 · Auditrol, Inc.