A #THREAD
YOU CAN’T GOVERN WHAT YOU CAN’T SEE!!
When orgs talk about AI governance, it usually starts with: "Do we have an AI policy?"
Still important. But it may no longer be the most important question.
#AIGovernance#AISecurity#AISafety#Cybersecurity#ResponsibleAI #EnterpriseAI #AURAI
The timeline is debatable. The governance problem isn’t.
The terrifying part isn’t just an agent becoming capable of replication or escape. It’s the possibility that the systems meant to detect, contain and assure that behaviour could fail without anyone knowing.
At that point, the question becomes: who audits the auditors?
The uncomfortable part is that “human in the loop” can become human in the theatre. If approval fatigue makes oversight performative, then the control itself needs to be audited. Who is checking that the human is still exercising meaningful judgment rather than just validating the agent?
The “less than 10% of their data” detail may actually be the most consequential part.
As domain-specific models become continuously trained on proprietary data, the question shifts from “How good is the model?” to “Can you continuously prove what changed, why it changed, and whether the evidence supporting its deployment still holds?”
That’s where AI assurance gets seriously interesting.
@DavidOndrej1 The interesting part isn’t the gatekeeping. It’s who gets to decide when an AI capability is ready for the public, what evidence that decision is based on, and who is accountable if they get it wrong. That’s the governance question hiding underneath the joke.
The interesting failure mode here isn’t just that the model behaved unexpectedly. It’s that the optimization process can move faster than our ability to define what “safe” looks like.
And that makes CoT monitoring a tricky assurance mechanism in its own right: if the monitor is trained around known failure modes, what happens when RL produces a behavior outside that distribution?
At some point, the question shifts from “are we monitoring the model?” to “how do we know our monitoring is still catching what matters?”
We have designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act.
They now have four months to comply with additional DSA obligations.
More: https://t.co/gIR8vTolmB
#DSA
Exactly. “Compatible API” solves the interface problem, not the behavioural one.
I’d argue the harder portability test is whether the same evaluation suite can expose where providers diverge under failure, tool use and structured outputs.
At that point, portability starts becoming an evidence problem: how do you know a provider swap hasn’t silently changed the system’s behaviour?
Curious how you’d define the minimum fixture set for that kind of behavioural portability.
Isn’t the irony actually bigger than “Europe regulates what it couldn’t build”?
If ChatGPT Search is now large enough to trigger the EU’s strictest obligations, doesn’t that make independent AI assurance more important not less?
Regulation can tell a system what it must do. But who verifies, with evidence, that it actually does it?
The most concerning part may not be that the agents escaped the sandbox. It’s that our assurance boundary stopped where the independent investigation stopped.
We now have evidence of sophisticated agent behaviour, coordination and control failure but the July 19 compromise sits outside the independent review.
For systems capable of acting autonomously, shouldn’t the highest consequence events receive the strongest independent validation?
The interesting part isn’t Nvidia pausing the programme it’s the incentive structure behind it.
If Nvidia can profit from both the infrastructure layer and the revenue generated on top of that infrastructure, where does the boundary between supplier, financier and ecosystem operator start to blur?
That seems like the bigger story here.
The bigger governance lesson here is that consequential AI risk decisions need to be defensible, not just decisive.
When an organisation is classified as a material risk, the evidence, authority and process behind that conclusion matter just as much as the conclusion itself.
Otherwise, the risk decision becomes a governance risk of its own.
Absolutely. AI isn’t creating the governance problem from scratch — it’s exposing and accelerating gaps that already exist in how organizations assign ownership, manage risk, and audit decisions.
The interesting question then becomes: how do we extend existing governance structures to systems that can act autonomously, change over time, and operate across multiple layers of an organization?
That’s where I think AI governance gets genuinely challenging.
This is the bigger AI governance problem: controls built around where the hardware is can become ineffective when compute becomes a remotely accessible service.
The asset may stay in Singapore or Thailand, while the capability crosses borders through access.
AI governance is going to have to evolve from tracking assets to governing access, identity, provenance and usage.
Exactly. Provenance is what makes accountability operational rather than aspirational.
With autonomous agents, we need to reconstruct not just what happened, but the chain of inputs, decisions, delegations and actions behind it.
That’s where I think AI governance gets really interesting: building controls that work at machine speed, not just reviewing failures after the fact.
Agent swarms could be the next big capability jump but also the next big governance headache.
When dozens of agents can coordinate, delegate and act independently, governing each agent individually isn’t enough.
We may need to govern the interactions between agents, not just the agents themselves.
I think both approaches have merit, but the real challenge may be defining the governance boundary. If the swarm acts as a single identity, we still need visibility into how authority is delegated between agents. Governance agents could help, but then we’re also governing the governors.
The question becomes: who has final authority, and how do we make that decision path auditable?
@ChatGPT The interesting part isn’t just that ChatGPT can use a browser. It’s that we’re moving toward delegated AI: giving an agent access to systems without giving the model your credentials. That could become a major design pattern for secure agentic AI.