Summary

Most Responsible AI programs die in a values working group that debates principles for a year while shadow AI spreads through the business unpoliced. The fix is to invert the sequence: ship a small five-piece policy kit in a week, risk-tier every system including the shadow tools nobody logged, and adapt model risk management for hallucination and injection, not drift alone. Map obligations to the EU AI Act as a living document. The test of a real control is simple. It names an owner, an evidence artifact, and a cadence, or it is only an aspiration.

Context

Governance that ships in a week, not a working group that meets for a year

Most Responsible AI efforts die in the same place. A cross-functional working group forms, debates principles for two quarters, and produces a values statement no engineer can act on. Meanwhile shadow AI use spreads through the business unpoliced, accruing risk every day the group deliberates. The executive fix is to invert the sequence. Start with a minimal policy kit and a control framework you can operate immediately, then refine the principles against real cases rather than in the abstract, because a control you can enforce this week beats a principle you will ratify next year.

A workable policy kit is smaller than people expect. It is an acceptable-use policy, a model inventory with risk tiers, a human-in-the-loop standard, an incident runbook, and a disclosure position. A CIO can assemble draft versions of all five in a week by adapting existing templates, then route them through legal and risk for a fast first pass. Mark them provisional and enforce them anyway. A company that ships the provisional kit in week one and finds forty shadow AI tools in its first inventory has already reduced more real risk than a year of principle-drafting would have.

Model risk management, adapted for generative systems

Banks have run model risk management for decades, but classic MRM assumes a model with a stable input space and a measurable error. Generative systems break both assumptions. The input space is open-ended natural language and the failure mode is a fluent, confident, wrong answer. MRM for these systems has to add evaluation on adversarial and edge-case prompts, red-teaming for prompt injection and data leakage, and continuous monitoring for drift in output quality, not a one-time validation sign-off that goes stale the moment the model meets real traffic.

The framework

A control framework you can actually audit

Governance becomes real when each control area names a specific control, the evidence that proves it operates, an accountable owner, and a review cadence. An auditor, internal or external, should be able to walk this table top to bottom and ask for the evidence artifact at each row. If a row cannot produce its artifact on demand, that control does not exist yet, however confidently it is described in a policy document.

Control areaControlEvidenceOwnerCadence
Inventory and tieringEvery AI system registered with a risk tierModel register with tier and use caseHead of AI governanceOn change; reviewed quarterly
Model risk managementValidation plus adversarial and drift testingEval reports; red-team findings logModel risk leadPre-launch; monitored monthly
Human-in-the-loopDefined intervention points for high-risk decisionsOverride logs; approval recordsFunction decision ownerContinuous; audited monthly
ExplainabilityDocumented rationale standard per tierModel cards; decision-rationale samplesProduct ownerPer release
Incident responseRunbook from detection to disclosureIncident tickets; disclosure recordsRisk plus legalTested quarterly
Regulatory readinessMapping to EU AI Act and sectoral rulesObligations matrix; conformity notesCompliance leadQuarterly; on regulatory change

If a control has no evidence artifact, it is an aspiration, not a control.

A worked example

A health insurer stood up the kit in week one and its first inventory found 38 AI systems, 12 of them shadow tools no one had registered. Tiering placed three in the high-risk band, including a claims-triage model. That model had passed a one-time validation but had never been red-teamed. A single adversarial exercise surfaced a prompt-injection path that could flip a denial to an approval, logged as a finding with an owner and a fix date. Human-in-the-loop intervention points were then defined for the three high-risk decisions and override logging was turned on. None of this required the values statement the working group was still drafting.

Recommended actions

Standing up governance without stalling the business

  • Ship the five-piece policy kit in week one: acceptable use, tiered model inventory, human-in-the-loop standard, incident runbook, and disclosure position. Mark them provisional and iterate against real cases.
  • Risk-tier every AI system in use, including the shadow ones, so oversight effort concentrates where a wrong answer causes real harm rather than spreading evenly across trivial use cases.
  • Extend MRM for generative systems: require adversarial and edge-case evaluation, prompt-injection red-teaming, and monthly drift monitoring before any high-tier system goes live.
  • Set human-in-the-loop standards by tier, defining exactly which decisions require human approval, and instrument override logging so the standard is auditable rather than assumed.
  • Build the regulatory obligations matrix now, mapping each high-risk system to EU AI Act duties and any sectoral rules across finance, health, and employment, so readiness is a live document rather than a scramble before a deadline.
Common pitfalls

How Responsible AI programs lose credibility

  • Principles with no controls. A values poster changes no behavior. Fix: convert each principle into a control with an owner, an evidence artifact, and a cadence.
  • Governing every system equally. Uniform oversight starves the high-risk cases of attention. Fix: risk-tier first and concentrate scrutiny on the tiers that can cause harm.
  • Treating generative validation like classic MRM. A one-time sign-off misses drift and injection. Fix: add adversarial testing and monthly monitoring for open-input systems.
  • No rehearsed incident path. Detecting a bad output with no runbook means the first real incident is improvised in public. Fix: write and quarterly-test a detection-to-disclosure runbook.
  • Reading the EU AI Act as a single deadline. Obligations differ by risk class and phase in over time. Fix: maintain a per-system obligations matrix and review it on every regulatory change.
Quick-win checklist

Governance moves for the next 30 to 90 days

  • Publish the provisional five-piece policy kit and route it to legal and risk for a fast first review.
  • Complete a model inventory with a risk tier assigned to every system, shadow use included.
  • Run one adversarial red-team exercise on your highest-tier generative system and log the findings.
  • Define human-in-the-loop intervention points for your top three high-risk decisions and turn on override logging.
  • Draft the EU AI Act obligations matrix for your high-risk systems and assign an owner to keep it current.