AI Governance: Who's Accountable When the Machine Decides?
AI tools have quietly moved out of isolated dev environments and into the middle of how real work gets done. That shift is genuinely exciting, and it brings a fresh set of risks worth sitting with. In this solo episode, Ryan works through what it takes to govern AI well, all of it anchored on one idea he keeps coming back to: a human has to stay accountable for the decisions that matter. He gets into why AI strains the governance habits IT already leans on, how to weigh centralized, decentralized, and hybrid approaches against your own risk tolerance, what ISO 42001 and the NIST AI RMF actually ask of you, and where the law is heading. He closes with a practical playbook for pulling shadow AI into the open while keeping the room for creativity that made folks reach for these tools in the first place.
In this episode
- Why AI puts pressure on the governance habits IT already has, from non-determinism to data drift and concept drift, and the blind spots those quietly create
- Splitting your governance model (who holds the decision rights) from your operating model (how the work actually gets run)
- The three big archetypes: the fortress-style centralized model, the fast and messy decentralized model, and the hybrid in between, plus how to match one to your risk tolerance and threat model
- A few examples from Ryan's own teams — engineers getting their bearings in old repos in about twenty minutes instead of a full day, designers prototyping fast enough to have a richer discovery conversation
- What ISO 42001 and the NIST AI Risk Management Framework actually require, including named human owners and a real kill switch
- The principle the whole episode hangs on: an AI tool can't be the one held accountable, since a machine isn't a legal or moral agent
- Where regulation is going, including EU GDPR Article 22, California's coming CCPA automated-decision rules, EU NIS2, and a White House executive order on AI and national security
- The frontier-developer laws worth knowing about even if they never regulate you directly
- Why these efforts stall out, and a grounded playbook: sanctioned tools folks will actually use, a living AI inventory, cross-functional discovery, and metrics anchored in real value
Key takeaways
- Lower the barrier to secure tools so people stop quietly routing around you
- Keep a human clearly accountable on every RACI chart
- Get real value to real people fast, then learn from how they actually use the tools
- Treat the AI in your stack as something to govern, not just something you installed
Resources and shoutouts
- ISO/IEC 42001, the AI management system standard
- NIST AI Risk Management Framework
- EU GDPR, Article 22 (solely automated decisions)
- California's CCPA automated decision-making technology (ADMT) rules, enforced by the CPPA, in effect Jan 1, 2027
- EU NIS2 Directive
- California's frontier-model transparency law, plus the state's AI content-transparency and watermarking rules
- The June 2026 White House executive order on AI and national security
- Related episodes:
- SpecOps → https://civictech.chat/episodes/the-specops-method
- AI Readiness with Brian Chidester of Adobe → https://civictech.chat/episodes/what-is-ai-readiness
- Legacy Lockpicks with David D'Silva of Nava, the one that ran just ahead of this → https://civictech.chat/episodes/legacy-lockpicks
- Music credit: Tumbleweeds by Monkey Warhol