AI governance isn't a policy document. It's 6 layers, and most skip the first 5: Teams rush to write a policy and call it governance. But a policy you can't enforce is just a PDF. And you can't audit what you never inventoried in the first place. I've spent the last 8 years building AI products... And governance is the part nobody puts on the roadmap. Here's the full 6-layer stack 👇 (See the visual for all 30 components) 1️⃣ AI Inventory ↳ You can't govern what you can't see. Run a shadow AI pass and list every AI tool in use that nobody officially approved. ↳ Then tag each system with an owner and a risk tier. 2️⃣ Data Foundation ↳ Track where every training input comes from, and screen it for bias before it touches a model. ↳ Stale data is its own failure mode. Monitor freshness. 3️⃣ Data Security & Access ↳ Encryption, anonymization, role-based access. ↳ Least privilege by default. Not everyone needs the model keys. 4️⃣ Model Assurance ↳ Write a model card for everything in production: what it does, what it trained on, where it breaks. ↳ Then red-team it and watch for drift. 5️⃣ Human Oversight ↳ Name who can override the model, and who's accountable when it's wrong. In writing, before you need it. 6️⃣ Compliance & Audit ↳ EU AI Act mapping, GDPR alignment, audit trails. ↳ This is the layer everyone starts with. It only holds if the 5 below it exist. Most teams have a governance policy. Almost none have governance. The difference is the 5 layers nobody sees. And the EU AI Act won't wait for you to build them. Which layer is your org already implementing? Drop a comment below. ♻️ Repost to help the builders and PMs in your network. And follow Basia Kubicka for more on building AI responsibly.
AI Governance Practices
Explore top LinkedIn content from expert professionals.
-
-
Claude.ai just announced that their Microsoft 365 connector is now available on EVERY plan, including free and personal accounts. That means ANY of your end users with a free Claude account can now connect it directly to your company's Microsoft 365 environment and start pulling in emails, files, spreadsheets, whatever they have access to. That should make you uncomfortable. Because unless your tenant requires admin approval for third-party app connections, any employee can enable this on their own. No ticket, no approval, no one in leadership even knows it happened. And now sensitive client data is sitting inside a platform you didn't evaluate, didn't approve, and don't control. A public AI model is potentially learning from your sensitive data, and almost definitely storing it. This isn't a Claude problem. Every major AI platform is racing to build connectors into your business tools, and every one of them is a potential data exposure event if you're not ready. Here's what I'd recommend doing as soon as possible: - Lock down third-party app permissions. Require admin approval for all app connections in your Microsoft 365 tenant. If you're not sure whether this is on, assume it isn't. - Audit your environment. Do you know where your sensitive data lives and who can access it? Most companies find out the hard way that employees are over-permissioned, and AI makes that exponentially more dangerous because it makes finding and extracting data faster than ever. - Communicate and educate. Most employees aren't being reckless, they just don't know this is a problem. Send a simple message this week: don't connect any AI tools to company systems without approval. Then start building a real AI use policy, even a one-pager. - Review your client agreements. If you handle sensitive client data, your contracts probably don't address AI processing yet. Close that gap before a client asks about it. This isn't about being anti-AI. Every new AI capability is a new governance question, and most businesses aren't asking it fast enough. At the same time, it's imperative that companies start preparing for AI integration because it is inevitable for those that want to move forward with technology in a meaningful way. Have questions? Shoot me a message. Client or not, I'm happy to chat more if I can help!
-
This new white paper by Stanford Institute for Human-Centered Artificial Intelligence (HAI) titled "Rethinking Privacy in the AI Era" addresses the intersection of data privacy and AI development, highlighting the challenges and proposing solutions for mitigating privacy risks. It outlines the current data protection landscape, including the Fair Information Practice Principles, GDPR, and U.S. state privacy laws, and discusses the distinction and regulatory implications between predictive and generative AI. The paper argues that AI's reliance on extensive data collection presents unique privacy risks at both individual and societal levels, noting that existing laws are inadequate for the emerging challenges posed by AI systems, because they don't fully tackle the shortcomings of the Fair Information Practice Principles (FIPs) framework or concentrate adequately on the comprehensive data governance measures necessary for regulating data used in AI development. According to the paper, FIPs are outdated and not well-suited for modern data and AI complexities, because: - They do not address the power imbalance between data collectors and individuals. - FIPs fail to enforce data minimization and purpose limitation effectively. - The framework places too much responsibility on individuals for privacy management. - Allows for data collection by default, putting the onus on individuals to opt out. - Focuses on procedural rather than substantive protections. - Struggles with the concepts of consent and legitimate interest, complicating privacy management. It emphasizes the need for new regulatory approaches that go beyond current privacy legislation to effectively manage the risks associated with AI-driven data acquisition and processing. The paper suggests three key strategies to mitigate the privacy harms of AI: 1.) Denormalize Data Collection by Default: Shift from opt-out to opt-in data collection models to facilitate true data minimization. This approach emphasizes "privacy by default" and the need for technical standards and infrastructure that enable meaningful consent mechanisms. 2.) Focus on the AI Data Supply Chain: Enhance privacy and data protection by ensuring dataset transparency and accountability throughout the entire lifecycle of data. This includes a call for regulatory frameworks that address data privacy comprehensively across the data supply chain. 3.) Flip the Script on Personal Data Management: Encourage the development of new governance mechanisms and technical infrastructures, such as data intermediaries and data permissioning systems, to automate and support the exercise of individual data rights and preferences. This strategy aims to empower individuals by facilitating easier management and control of their personal data in the context of AI. by Dr. Jennifer King Caroline Meinhardt Link: https://lnkd.in/dniktn3V
-
Europe just defined how AI must be secured On 15 Jan, the European Telecommunications Standards Institute (ETSI) published a standard, EN 304 223, defining baseline cybersecurity requirements for AI models and systems. ➡️ A common set of AI cybersecurity controls, usable across jurisdictions, vendors, supply chains. Why this matters now Traditional cybersecurity was built for software & networks. AI changes the attack surface: ▫️ training data can be poisoned ▫️ models can be manipulated or obfuscated ▫️ prompts can be indirectly injected ▫️ behaviour can drift in invisible ways ➡️ EN 304 223 explicitly names these risks, treating them as security failures. How this takes effect EN 304 223 is already being pulled into procurement processes, security questionnaires, internal audits, vendor due diligence, insurance reviews. With the EU AI Act, high-risk AI systems will need to demonstrate compliance through conformity assessment either via internal control with robust technical documentation, or through assessment by a notified body. ➡️ EN 304 223 is the operational “how” that law and auditors will rely on. The real breakthrough: lifecycle security The standard defines 13 principles and 72 trackable requirements, organised across 5 phases of the AI system lifecycle: 1️⃣ secure design 2️⃣ secure development 3️⃣ secure deployment 4️⃣ secure maintenance 5️⃣ secure end of life ➡️ Retraining a model = redeploying a system from a security standpoint. AI security becomes a continuous operational discipline. Accountability made operational EN 304 223 assigns accountability across 3 technical roles: ✔️ developers ✔️ system operators ✔️ data custodians ➡️ AI risk lives between teams. This standard makes ownership explicit. The target: production AI EN 304 223 applies to deep neural networks and GenAI models already embedded in products, services, and operational decisions. Academic or research environments are excluded. ➡️ This standard is about AI that is live, scaled, and consequential, particularly in finance, healthcare, and critical infrastructure. What “compliance” means Complying with legal, audit, procurement, and insurance expectations using EN 304 223 as evidence: mapping controls across the lifecycle and ownership across roles. What Boards and executives should do now 1️⃣ Mandate an AI inventory: What AI is live, where, doing what, using which data pipelines, supplied by whom. 2️⃣ Assign named accountability across the lifecycle: Align to the standard’s role logic per system. 3️⃣ Require an AI security evidence pack per high-impact system, mapped across its lifecycle. 4️⃣ Decide your assurance route early. For high-risk systems plan for internal control vs notified body assessment. The bigger signal EU is turning AI security into auditable infrastructure. Trustworthy AI is becoming a standard of execution. For companies operating globally, proof of AI security is becoming the baseline. #AI #GenAI #AIGovernance #AISecurity #Boardroom
-
How To Handle Sensitive Information in your next AI Project It's crucial to handle sensitive user information with care. Whether it's personal data, financial details, or health information, understanding how to protect and manage it is essential to maintain trust and comply with privacy regulations. Here are 5 best practices to follow: 1. Identify and Classify Sensitive Data Start by identifying the types of sensitive data your application handles, such as personally identifiable information (PII), sensitive personal information (SPI), and confidential data. Understand the specific legal requirements and privacy regulations that apply, such as GDPR or the California Consumer Privacy Act. 2. Minimize Data Exposure Only share the necessary information with AI endpoints. For PII, such as names, addresses, or social security numbers, consider redacting this information before making API calls, especially if the data could be linked to sensitive applications, like healthcare or financial services. 3. Avoid Sharing Highly Sensitive Information Never pass sensitive personal information, such as credit card numbers, passwords, or bank account details, through AI endpoints. Instead, use secure, dedicated channels for handling and processing such data to avoid unintended exposure or misuse. 4. Implement Data Anonymization When dealing with confidential information, like health conditions or legal matters, ensure that the data cannot be traced back to an individual. Anonymize the data before using it with AI services to maintain user privacy and comply with legal standards. 5. Regularly Review and Update Privacy Practices Data privacy is a dynamic field with evolving laws and best practices. To ensure continued compliance and protection of user data, regularly review your data handling processes, stay updated on relevant regulations, and adjust your practices as needed. Remember, safeguarding sensitive information is not just about compliance — it's about earning and keeping the trust of your users.
-
In a moment when AI threatens to outpace democratic governance, Ireland’s parliament (the Oireachtas) has produced a comprehensive framework for ensuring that AI serves society rather than the other way round. The Oireachtas Joint Committee on Artificial Intelligence has published its first interim report containing 85 recommendations. The centrepiece recommendation calls for establishing a National AI Office by August 2026, positioned with sufficient independence to avoid conflicts between promoting AI industry, deploying AI in public services, and regulating AI systems. The institutional architecture proposed is ambitious, including recommending that the AI Advisory Council (of which I am a member) should be placed on permanent footing with state funding and broad representation; an AI Observatory should track real-time issues and project future impacts on jobs and skills; the nine authorities designated to safeguard fundamental rights under the EU AI Act should receive dedicated, ring-fenced and multi-annual funding. The committee recommends regulatory sandboxes be established by August 2026, allowing companies to develop AI products safely while understanding compliance obligations. It calls for mandatory algorithmic impact assessments for high-risk AI systems in public services. On recommender systems, the committee in my view goes too far by suggesting algorithms should be switched off by default. It also recommends that social media companies should be banned from turning them on for children’s accounts. The report shows sophisticated understanding of how AI systems perpetuate inequalities. It recommends equality by design as core to all development phases, with pathways ensuring marginalised groups participate in designing and assessing AI tools. Thorough research and testing, keeping humans in the loop, and unbiased training data should be mandatory. It recommends that companies or public bodies deploying biased or discriminatory AI systems should face prosecution and liability. On energy and environment, it says AI development must account for Ireland’s obligations under the EU Energy Efficiency Directive and Climate Act. On copyright, it calls for strengthening the EU Copyright Directive so content cannot be used to train AI models without creators’ consent. The committee emphasises education and awareness. Following Finland’s example, it calls for coordinated national efforts across education from primary school to workplace, covering digital literacy, rights regarding consent and data use, and how to identify scams. Throughout runs commitment to transparency and accountability. The committee calls for a publicly accessible central register of all algorithmic systems used by government, including details about developers, procurement costs and assessment findings. Where AI systems are used for decision-making, they must be transparent, auditable and demonstrate non-discrimination on the nine grounds in Irish equality law.
-
AI Governance Isn't a Policy Document. It's a System. Most organizations approach AI governance by writing policies. The leaders are building governance into the architecture itself. As AI adoption accelerates, governance can no longer be treated as a compliance checkbox. It needs to be embedded across the entire AI lifecycle. A practical way to think about it is through these 6 layers of AI Governance: 1. AI Inventory You can't govern what you don't know exists. Maintain visibility into AI systems through model registries, risk tiering, ownership assignment, system classification, and shadow AI detection. 2. Data Foundation The quality of AI outcomes depends on the quality of the data behind them. Track data sources, lineage, freshness, quality, and potential bias before they become business risks. 3. Data Security & Access Governance starts with controlling who can access what. Encryption, anonymization, role-based access controls, least-privilege principles, and strong key management form the foundation of trust. 4. Model Assurance Models should be continuously evaluated, not just deployed. Performance benchmarking, fairness testing, red teaming, drift detection, and model documentation help ensure reliability over time. 5. Human Oversight AI should support decisions, not operate without accountability. Decision reviews, escalation paths, override authority, output validation, and accountability mapping keep humans in control when it matters most. 6. Compliance & Audit Regulations are evolving rapidly. Organizations need clear audit trails, policy enforcement mechanisms, incident reporting processes, and alignment with frameworks such as GDPR and the EU AI Act. The biggest challenge in AI governance isn't technology. It's creating a framework where innovation can move fast without compromising security, compliance, accountability, or trust. The organizations that get this right will scale AI confidently. The ones that don't may spend more time managing risk than creating value. Which of these six layers do you think organizations struggle with the most today? #AIGovernance #AI #ResponsibleAI #GenAI
-
Shipping AI agents into production without governance is like deploying software without security, logs, or controls. It might work at first. But sooner or later, something breaks - silently. As AI agents move from experiments to real decision-makers, governance becomes infrastructure. This framework breaks AI Governance into the core functions every production-grade agent system needs: - Policy Rules Turn business and regulatory expectations into enforceable agent behavior - defining what agents can do, must avoid, and how they respond in restricted scenarios. - Access Control Limits agents to approved tools, datasets, and systems using identity verification, RBAC, and permission boundaries — preventing accidental or malicious misuse. - Audit Logs Create a full activity trail of agent decisions: what data was accessed, which tools were called, and why actions were taken — making every outcome traceable. - Risk Scoring Evaluates agent actions before execution, assigns risk levels, detects sensitive operations, and blocks unsafe decisions through thresholds and safety scoring. - Data Privacy Protects confidential information using PII detection, encryption, consent management, and retention policies — ensuring agents don’t leak regulated data. - Model Monitoring Tracks real-world agent performance: accuracy, drift, hallucinations, latency, and cost - keeping systems reliable after deployment. - Human Approvals Adds human-in-the-loop controls for high-impact actions, enabling escalation, overrides, and sign-offs when automation alone isn’t enough. - Incident Response Detects failures early and enables rapid containment through alerts, rollbacks, kill switches, and post-incident reporting to prevent repeat issues. The takeaway: AI agents don’t just need intelligence. They need guardrails. Without governance, agents become unpredictable. With governance, they become enterprise-ready. This is how organizations move from experimental AI to trustworthy, compliant, production systems. Save this if you’re building agentic systems. Share it with your platform or ML teams.
-
Montgomery Singman 🔜 PGC Shanghai / ChinaJoy
Montgomery Singman 🔜 PGC Shanghai / ChinaJoy is an Influencer Managing Partner @ Radiance Strategic Solutions | xSony, xElectronic Arts, xCapcom, xAtari
27,952 followersOn August 1, 2024, the European Union's AI Act came into force, bringing in new regulations that will impact how AI technologies are developed and used within the E.U., with far-reaching implications for U.S. businesses. The AI Act represents a significant shift in how artificial intelligence is regulated within the European Union, setting standards to ensure that AI systems are ethical, transparent, and aligned with fundamental rights. This new regulatory landscape demands careful attention for U.S. companies that operate in the E.U. or work with E.U. partners. Compliance is not just about avoiding penalties; it's an opportunity to strengthen your business by building trust and demonstrating a commitment to ethical AI practices. This guide provides a detailed look at the key steps to navigate the AI Act and how your business can turn compliance into a competitive advantage. 🔍 Comprehensive AI Audit: Begin with thoroughly auditing your AI systems to identify those under the AI Act’s jurisdiction. This involves documenting how each AI application functions and its data flow and ensuring you understand the regulatory requirements that apply. 🛡️ Understanding Risk Levels: The AI Act categorizes AI systems into four risk levels: minimal, limited, high, and unacceptable. Your business needs to accurately classify each AI application to determine the necessary compliance measures, particularly those deemed high-risk, requiring more stringent controls. 📋 Implementing Robust Compliance Measures: For high-risk AI applications, detailed compliance protocols are crucial. These include regular testing for fairness and accuracy, ensuring transparency in AI-driven decisions, and providing clear information to users about how their data is used. 👥 Establishing a Dedicated Compliance Team: Create a specialized team to manage AI compliance efforts. This team should regularly review AI systems, update protocols in line with evolving regulations, and ensure that all staff are trained on the AI Act's requirements. 🌍 Leveraging Compliance as a Competitive Advantage: Compliance with the AI Act can enhance your business's reputation by building trust with customers and partners. By prioritizing transparency, security, and ethical AI practices, your company can stand out as a leader in responsible AI use, fostering stronger relationships and driving long-term success. #AI #AIACT #Compliance #EthicalAI #EURegulations #AIRegulation #TechCompliance #ArtificialIntelligence #BusinessStrategy #Innovation
-
Most "AI governance" frameworks are data governance with a fresh coat of paint. I keep seeing the same checklist. Access control. Data quality. Audit logs. Inventory. Security. Lineage. This is very 2015. None of it tells you whether your model is safe to ship. Whether it's quietly drifting in production. What your agent is allowed to do when no one's watching. That's the AI part. And it's usually the part that's missing. Here's the version I'd build. Eight pillars: 1. AI Inventory & Ownership Every system, tiered by risk, with a named owner. 2. Data Foundation Where the data came from, whether it's clean, whether you're allowed to use it. 3. Model Lifecycle Test it before it ships. Watch it after. You need to be able to pull it back. A model that passed review in March can be dangerous by June. 4. Data Security & Privacy Protect the data, and the model, against attacks aimed at it. 5. Access Control Who/what can access data/APIs, on behalf of whom, and until when? 6. Agent Governance Tool permissions, action limits, a human in the loop, a kill switch. The moment it can act on your behalf, "what could it do" stops being hypothetical. 7. Human Oversight A person owns the outcome. 8. Compliance & Audit Meet the rules, document the system, keep a record you can defend. Two of these are new in the AI age: Model Lifecycle and Agent Governance. They're new because they're the hard part. The part that fails in production. The data checklist keeps auditors happy. The model and the agent are what keep you up at night. Govern those. What's on your governance list that isn't just data governance? -- I’m building a newsletter to go deeper: Build What Matters. Weekly drops on AI agents + emerging workflows. Subscribe Here 👉 https://lnkd.in/dsP2uu3k ♻️ Repost if someone in your network needs to read this. ➕ Follow Luís Rodrigues for practical AI + Business insights