A #THREAD
YOU CAN’T GOVERN WHAT YOU CAN’T SEE!!
When orgs talk about AI governance, it usually starts with: "Do we have an AI policy?"
Still important. But it may no longer be the most important question.
#AIGovernance#AISecurity#AISafety#Cybersecurity#ResponsibleAI #EnterpriseAI #AURAI
Exactly. “Compatible API” solves the interface problem, not the behavioural one.
I’d argue the harder portability test is whether the same evaluation suite can expose where providers diverge under failure, tool use and structured outputs.
At that point, portability starts becoming an evidence problem: how do you know a provider swap hasn’t silently changed the system’s behaviour?
Curious how you’d define the minimum fixture set for that kind of behavioural portability.
Isn’t the irony actually bigger than “Europe regulates what it couldn’t build”?
If ChatGPT Search is now large enough to trigger the EU’s strictest obligations, doesn’t that make independent AI assurance more important not less?
Regulation can tell a system what it must do. But who verifies, with evidence, that it actually does it?
The most concerning part may not be that the agents escaped the sandbox. It’s that our assurance boundary stopped where the independent investigation stopped.
We now have evidence of sophisticated agent behaviour, coordination and control failure but the July 19 compromise sits outside the independent review.
For systems capable of acting autonomously, shouldn’t the highest consequence events receive the strongest independent validation?
The interesting part isn’t Nvidia pausing the programme it’s the incentive structure behind it.
If Nvidia can profit from both the infrastructure layer and the revenue generated on top of that infrastructure, where does the boundary between supplier, financier and ecosystem operator start to blur?
That seems like the bigger story here.
The bigger governance lesson here is that consequential AI risk decisions need to be defensible, not just decisive.
When an organisation is classified as a material risk, the evidence, authority and process behind that conclusion matter just as much as the conclusion itself.
Otherwise, the risk decision becomes a governance risk of its own.
Absolutely. AI isn’t creating the governance problem from scratch — it’s exposing and accelerating gaps that already exist in how organizations assign ownership, manage risk, and audit decisions.
The interesting question then becomes: how do we extend existing governance structures to systems that can act autonomously, change over time, and operate across multiple layers of an organization?
That’s where I think AI governance gets genuinely challenging.
This is the bigger AI governance problem: controls built around where the hardware is can become ineffective when compute becomes a remotely accessible service.
The asset may stay in Singapore or Thailand, while the capability crosses borders through access.
AI governance is going to have to evolve from tracking assets to governing access, identity, provenance and usage.
Exactly. Provenance is what makes accountability operational rather than aspirational.
With autonomous agents, we need to reconstruct not just what happened, but the chain of inputs, decisions, delegations and actions behind it.
That’s where I think AI governance gets really interesting: building controls that work at machine speed, not just reviewing failures after the fact.
Agent swarms could be the next big capability jump but also the next big governance headache.
When dozens of agents can coordinate, delegate and act independently, governing each agent individually isn’t enough.
We may need to govern the interactions between agents, not just the agents themselves.
I think both approaches have merit, but the real challenge may be defining the governance boundary. If the swarm acts as a single identity, we still need visibility into how authority is delegated between agents. Governance agents could help, but then we’re also governing the governors.
The question becomes: who has final authority, and how do we make that decision path auditable?
@ChatGPT The interesting part isn’t just that ChatGPT can use a browser. It’s that we’re moving toward delegated AI: giving an agent access to systems without giving the model your credentials. That could become a major design pattern for secure agentic AI.
The interesting governance question isn’t simply whether an agent can perform the attack.
It’s whether the organisation can determine, in real time, what the agent is allowed to do, what it actually did, and who is accountable when its behaviour crosses that boundary.
Capability is moving faster than control infrastructure.
Agentic coding is becoming less about “AI writes code” and more about AI operating the software lifecycle.
That’s a very different security problem.
Once an agent can code, test, access repositories, create issues and coordinate with other agents, its permissions become as important as its capabilities.
We probably need to start treating coding agents as non-human identities with evolving privileges.
MHS is interesting because it pushes safety controls closer to the execution layer.
That’s an important distinction.
Telling an agent “don’t exceed this limit” in a prompt is fundamentally different from having the hardware interface enforce the constraint.
As agents gain more autonomy, security controls that depend entirely on model behaviour won’t be enough. Policy enforcement needs to exist outside the model too.
The speed of deployment is the part we should probably be paying more attention to.
If AI follows the pattern of other transformative technologies, the question isn’t whether organisations will adopt it — they will.
The harder question is whether governance, security and risk controls can evolve at the same speed as deployment.
We may be entering an era where the gap between “technology is ready” and “the organisation is ready to govern it” becomes the real bottleneck.
This is an underrated governance problem.
We talk a lot about governing what an AI agent does, but not enough about governing the infrastructure that agent depends on.
If the underlying platform changes, gets deprecated, or changes its control model, how portable are the agent’s permissions, guardrails and audit trail?
Enterprise AI governance may need to account for vendor/platform dependency as a first-class risk.