87%
of leaders in the highest-adopting sectors planned further generative-AI investment within a year.
Research briefing · Auditrol, Inc. · September 2026
Why AI governance starts beneath the AI — in the data, policies, and control plane every model and agent draws on.
Thought leadership · The Iceberg of AI Governance
01 · The Gap
Generative and agentic AI reached production faster than assurance. With no prescriptive U.S. standard, each organization must define its own standard and prove that it holds.
“A policy document applies when someone remembers to check it.”
87%
of leaders in the highest-adopting sectors planned further generative-AI investment within a year.
90%
of those had a dedicated budget — adoption is funded and accelerating.
5%
reported privacy-risk measures for LLMs.
A written employee-use policy is not a control: it shows intent, not what actually happened.
Insights · Visual brief
Blotato-grade visuals from Governing the Machine — swipe or use the controls.
02 · System Risk
Agentic systems combine foundation models, tools and connectors, retrieval services, and third-party agents at runtime — often over unstructured data the organization does not own. Observability must cover decisions and actions end-to-end.
Then
Classical model validation assumed a bounded artifact. Governance inventories tracked models.
Now
Runtime composition of models, tools, retrieval, and third-party agents. The risk object moved one layer out — and one layer down into context.
The failure mode is not a system crashing. It is a system that appears to be working.
An apparently successful system producing an unrequested result — or claiming success for an action it did not take.
42%
of distinct controls overlap between AI governance and established predictive-model governance.
33
AI risks mapped across security, operational, regulatory, content-harm, and model-risk classes.
“The risk lives one layer down, in the data and policies every model and agent draws on.”
03 · Four Trends
From Governing the Machine — four structural shifts that move governance from documents into the platform.
Generative and agentic AI reached production faster than assurance. With no prescriptive U.S. standard, each organization must define its own standard and prove that it holds.
“You write the standard, and you prove it holds.”
The risk object has changed from a model to an assembled system. Agentic systems combine foundation models, tools and connectors, retrieval services, and third-party agents at runtime — often over unstructured data the organization does not own.
“The failure mode is not a system crashing. It is a system that appears to be working.”
Controls must match named risks and tiers. The paper maps 33 AI risks across security, operational, regulatory, content-harm, and model-risk classes. One framework applied everywhere is too heavy for the safe systems and too light for the dangerous ones.
“One framework applied everywhere is too heavy for the safe systems and too light for the dangerous ones.”
Governance should move into a platform control plane enforced as code — identity, entitlement, filtering, approval, and logging — rather than remaining in documents, committees, and meetings. A platform rule applies to every agent and produces evidence as a by-product.
“Controls have to live in the control plane of the platform itself…written as code rather than policy.”
04 · Reference Model
Agents interpret intent and produce plans. A control plane enforces policy and approvals. Deterministic workflows execute approved plans. Immutable logs, metering, and quality signals create evidence.
Agents interpret intent
Agents interpret intent and produce plans — they reason; they do not silently execute irreversible action.
Policy enforced as code
Identity, entitlement, filtering, approval, and logging enforced in the platform itself — not remembered in a document.
Approved plans only
Deterministic workflows execute approved plans. The dangerous failure mode is an apparently successful unrequested result.
Immutable by design
Immutable logs, metering, and quality signals create evidence as a by-product of the control plane.
“Every model and agent is only as sound as the data, documents and policies beneath it.” Governing the underlying context — fit-for-purpose data, quality, privacy, metadata, lineage, ownership/stewardship and access policies — is essential.
05 · Agenda
Practical moves from Governing the Machine that put governance beneath the AI, not beside it.
Define the standard your organization will hold itself to — then build the means to prove it holds.
Inventory assembled systems: models, tools, connectors, retrieval services, and third-party agents — not models alone.
Fit-for-purpose data, quality, privacy, metadata, lineage, ownership/stewardship, and access policies. Do not govern agents and models without governing the data and policies underneath them.
Move identity, entitlement, filtering, approval, and logging into a control plane written as code — so a rule applies to every agent and evidence is a by-product.
Map preventive gateway controls to security risk, continuous detective controls to operational risk, and classical validation to model risk — across the 33 named AI risks.
Whitepaper
Why AI Governance Starts Beneath the AI
Chris Nobili & Ashwin Nayak · Auditrol, Inc. · September 2026 · 12 pages
“Do not govern agents and models without governing the data and policies underneath them.” Read the full argument for a control plane that produces evidence as a by-product.
Governing the Machine
Why AI Governance Starts Beneath the AI
Chris Nobili & Ashwin Nayak
September 2026 · Auditrol, Inc.