Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI governance and non-determinism: what GRC teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: AI governance is shifting from deterministic rule enforcement to judgment-based GRC as non-deterministic systems make old policy models less reliable, according to ActiveFence. The practical implication is that AI oversight now depends on red teaming, human review, and clearer accountability, especially where AI behaves like a tool with its own runtime decisions.

NHIMG editorial — based on content published by ActiveFence: Curiouser Soundbites on what D&D taught us about AI governance

Questions worth separating out

Q: How should organisations govern AI systems that can make consequential decisions?

A: Organisations should govern consequential AI systems with the same discipline used for high-risk identities: defined ownership, least privilege, logging, approval boundaries, and human override.

Q: Why does human-in-the-loop matter for identity and access management?

A: IAM decisions affect who can reach sensitive systems, so errors have direct security consequences.

Q: What do enterprises get wrong about AI red teaming maturity?

A: Many teams stop at attack simulation and assume the test itself is the control.

Practitioner guidance

  • Map AI decision boundaries Document which AI outputs are advisory, which are operational, and which can influence access, approvals, or customer-impacting decisions.
  • Add adversarial testing to governance cycles Use red teaming to test prompt sensitivity, workflow abuse, and inconsistent outputs before AI is allowed into production decisions.
  • Treat AI-connected workflows as identity surfaces Inventory where AI connects to tools, datasets, and enterprise systems, then verify what authority it inherits and whether that authority is excessive.

What's in the full article

ActiveFence's full podcast discussion covers the conversational detail this post intentionally leaves for the source:

  • The D&D-to-governance analogy and the speaker’s reasoning behind it.
  • The podcast discussion of why judgment matters when controls cannot fully predict AI output.
  • The red-team perspective on balancing human and automated testing.
  • The closing discussion on how AI governance shifts when rules behave more like guidance than hard constraints.

👉 Read ActiveFence's podcast discussion on AI governance, D&D, and GRC judgment →

AI governance and non-determinism: what GRC teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

AI governance debt is now a board-level risk: organisations are still writing controls for deterministic systems while deploying AI that behaves probabilistically. That gap creates a governance debt problem because review processes, approvals, and audit evidence all assume repeatability. The result is a control environment that looks complete on paper but fails under real operational variance. Practitioners should treat this as a governance design issue, not a documentation issue.

A question worth separating out:

Q: How do organisations know whether AI governance is actually working?

A: AI governance is working when teams can prove that data access, identity permissions, and runtime controls line up with policy in practice. A useful test is whether the organisation can answer who accessed what, through which identity, and whether any out-of-policy movement was blocked or detected in time.

👉 Read our full editorial: AI governance is becoming a GRC problem, not just a rules problem



   
ReplyQuote
Share: