Join our Newsletter — 33% off our NHI Course

AI governance across the U.S. and U.K. - what IAM teams miss

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: C1.ai says U.S. and U.K. AI governance diverges on culture, regulation, and security expectations, with the U.S. favouring faster deployment while the U.K. and Europe impose tighter scrutiny over data use, human judgment, and access governance. Birthright access is a poor fit when AI adoption, contractor exposure, and regional policy expectations change faster than static entitlement models.

Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “U.S. vs. U.K. Perspectives on AI and Security”.

Key questions

Q: How should security teams remove birthright access from AI-adjacent roles?

A: Start by identifying roles that can reach AI tools, contractor data, or regulated records, then remove automatic inheritance of those permissions.

Q: Why do standing contractor entitlements create more risk in multinational AI programmes?

A: Because they outlive the business case that justified them.

Q: What are the signs that AI governance controls are not keeping pace with adoption?

A: Common warning signs include unclear ownership for AI use cases, inconsistent approval processes, limited visibility into where sensitive data enters models, and weak evidence for audits or assessments.

Practitioner guidance

  • Replace birthright permissions for AI-adjacent roles Identify roles that touch AI tools, contractor data, or regulated personal information, and remove automatic inheritance of access.
  • Move contractor access into time-bound workflows Give third-party users access through approval-based, time-limited workflows rather than persistent accounts.
  • Map regional policy differences into identity rules Separate access logic for jurisdictions that treat human judgment, data sovereignty, and AI output disclosure differently.

Bottom line: The article frames AI governance as an access problem as much as a policy problem, especially where standing entitlements outlast the context that justified them.

What's in the full article

C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:

  • The first-hand conversation with Abraham Ingersoll and Alex Bovee on U.S. versus U.K. AI governance
  • The specific examples of contractor access and retailer disruption discussed in the article
  • The article's discussion of human judgment, data sovereignty, and AI policy expectations across regions
  • The cultural observations behind differing attitudes to AI adoption and risk tolerance

👉 Read C1.ai's analysis of U.S. and U.K. AI governance and access control →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Birthright access is the wrong inheritance model for AI governance. The article shows that U.S. and U.K. organisations are operating under different cultural and regulatory assumptions, yet many identity programmes still inherit access by default. That model fails when AI use changes faster than entitlement review cycles. Practitioner conclusion: access should be issued for the task, not assumed from role ancestry.

A question worth separating out:

Q: When should organisations prioritise just-in-time access over standing AWS permissions?

A: Prioritise just-in-time access when a role is needed only occasionally, when elevated privileges are high risk, or when engineers need admin rights only for a defined window such as an on-call rotation. It is also the better choice for incident response and outage work because access can be granted quickly and then revoked, reducing the time exposed credentials remain usable.

👉 Read our full editorial: U.S. and U.K. AI governance reveal the limits of birthright access


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.