Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Your AI Governance Program Won't Save YouRegulatory Obligations Management
5 min readFor Compliance Officers

Your AI Governance Program Won't Save You

The conventional wisdom

Compliance officers are rushing to build AI governance programs. The logic seems solid: the DOJ's September 2024 ECCP revisions highlight AI risks, the EU AI Act sets compliance obligations based on risk levels, and Colorado's AI Act requires "reasonable care" to prevent algorithmic discrimination. So you draft AI policies, map controls to regulations, and check the box.

This approach treats AI governance like any other compliance domain. You're applying the same methods you used for data privacy or third-party risk: identify requirements, document controls, train employees, monitor adherence. Your GRC platform now tracks AI-specific frameworks alongside your existing compliance obligations. You've added "AI risk" to your risk universe and "AI ethics" to your policy library.

The problem? You're building a compliance program for a technology you don't understand, in an operational context you can't see.

Why this approach is incomplete

AI governance isn't a compliance domain you can just add to your existing program. It's a fundamental challenge to how compliance programs work.

Traditional compliance assumes you can write a rule, train people on it, and audit adherence. But AI systems make decisions you didn't program them to make, using logic you can't fully explain, in contexts that change faster than your Policy Gap Analysis cycle. When Deputy Attorney General Lisa Monaco warned in March 2024 that prosecutors would seek stiffer sentences for offenses "made significantly more dangerous by the misuse of AI," she wasn't describing a new category of violation. She was describing a world where your controls can't keep pace with your risk.

Consider what the ECCP revisions actually ask prosecutors to assess. They want to know if you're "monitoring and testing technology to evaluate if it's functioning as intended and consistent with the company's code of conduct." But "as intended" is a moving target when you're using machine learning models that evolve with new data. And "consistent with the code of conduct" requires human judgment about outputs you may not have anticipated.

The conventional approach treats AI as a risk to manage. The reality is that AI is a capability that creates new risks faster than you can document them. Your governance framework needs to match that speed, and most compliance programs aren't built for it.

The evidence

Look at what the ECCP revisions don't say. They don't ask if you have an AI policy. They ask how you're managing emerging risks, curbing unintended consequences, and mitigating deliberate or reckless misuse by insiders. These aren't questions about policy compliance. They're questions about operational visibility and adaptive control.

The Colorado AI Act's "reasonable care" standard creates a rebuttable presumption if you comply with specified provisions. But reasonable care in AI isn't about checking boxes. It's about demonstrating you understood what your system could do wrong and took specific steps to prevent it. That requires technical competence, not just compliance documentation.

The EU AI Act establishes compliance obligations based on risk levels. But who in your compliance function can accurately assess the risk level of a machine learning model? Can you distinguish between a high-risk system that requires conformity assessment and a limited-risk system that needs transparency obligations? If you're relying on business units to self-classify, you're not governing AI. You're documenting what they tell you.

What to do instead

Stop treating AI governance as a compliance workstream. Treat it as an operational discipline that compliance supports.

First, put technical competence on your compliance team. You need someone who can read model documentation, understand training data provenance, and ask meaningful questions about algorithmic decision-making. This doesn't mean hiring data scientists to write policies. It means ensuring your compliance function can have informed conversations with the people building and deploying AI systems.

Second, shift from policy-based controls to outcome-based monitoring. Instead of training employees on "responsible AI use," implement controls that detect when AI systems produce outputs inconsistent with your Impact Tolerance. If you're using AI for credit decisions, monitor for disparate impact in real time. If you're using it for customer service, track escalations that suggest the model misunderstood context. The ECCP asks about controls that "confirm the accuracy or reliability of data used by the business." Build those controls into your operational workflows, not your compliance documentation.

Third, create accountability structures that match how AI systems actually work. The ECCP asks how you monitor and enforce accountability for AI use. Traditional accountability assigns responsibility to individuals. But AI systems involve data engineers, model developers, business owners, and end users. Your governance framework needs to define who's accountable for data quality, model performance, deployment decisions, and ongoing monitoring. Document those accountabilities in operational terms, not compliance abstractions.

Fourth, integrate AI risk into your existing ERM process, but don't treat it like other enterprise risks. The ECCP asks if AI risk management is integrated into broader ERM strategies. Integration doesn't mean adding "AI risk" to your risk register. It means ensuring your ERM process can handle risks that emerge and evolve faster than your quarterly risk reviews. Consider scenario analysis that models how AI systems might fail in ways you didn't anticipate.

When the conventional wisdom is right

There's a place for traditional compliance approaches in AI governance. You need policies that establish ethical boundaries and prohibited uses. You need training that helps employees recognize when AI-generated outputs require human review. You need a whistleblower hotline where people can report AI-related concerns without retaliation.

The conventional wisdom is right that compliance programs play a role in mitigating AI-related risks, as Principal Deputy Assistant Attorney General Nicole Argentieri noted. Your compliance function should own the governance framework, the risk assessment methodology, and the reporting structure.

But own the framework, not the technical decisions. Your job isn't to approve every AI use case or audit every model. Your job is to ensure the organization has the competence, the processes, and the accountability structures to make those decisions responsibly.

The DOJ's ECCP revisions don't ask if you have an AI governance program. They ask if your compliance program can actually mitigate AI risks. For most organizations, the answer depends less on what you've documented and more on whether your compliance function can operate at the speed and technical depth that AI demands.

If you can't, your AI governance program is just paperwork waiting to be tested in a prosecution.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like