Your Controls Are Perfect. They Are Applied to a Fiction.
The AI governance forum I am imagining is a good one. The use case is described in full. The risk tier is argued and assigned. The controls attach to real requirements: a human checkpoint here, an audit trail there, a review date in the calendar. The approval is minuted. Nobody cut a corner.
Now ask what every decision in that room was actually made about. Not the system. Nobody in a governance forum touches the system. Every decision was made about a description of the system: an entry in an inventory, a register row, a use case document.
Which means the whole apparatus rests on an assumption nobody minuted: that the description matches the thing that is running. If it does not, the minutes still read clean. The controls were correctly applied. They were applied to a fiction.
Every framework starts one step too late
This is not a gap in any particular framework. It sits underneath all of them. Take any AI governance regime in use today, an international standard, a national framework, an internal policy, and look at its first practical step. It begins from an inventory. A register of systems, a use case catalog, a model list. Every control that follows attaches to a described system. Risk tiers are assigned to descriptions. Approvals are granted to descriptions. Reviews are scheduled for descriptions.
And here is the part I cannot stop thinking about: the frameworks require that a register exists, and they are silent on whether it is true. The most consequential artifact in the entire governance stack, the one every other control depends on, is the least tested document in the building.
The register and the estate
Two words make the problem discussable. The estate is everything actually running: every model, agent, and AI capability doing work in your institution, whether or not anyone knows about it. The register is what the institution believes it operates. In a perfect world they are the same list. In every real institution I have seen or heard described, they are not, and the distance between them is not administrative untidiness. It is the exact space where ungoverned risk lives, because a capability outside the register is not ungoverned by accident. It sits outside the scope of every control the institution believes it has.
Institutions audit their financial books every year, line by line, against evidence. The register is the book of record for the AI estate, and in most institutions it is reconciled against the running estate by no one.
How the gap opens
Three ways, and each deserves its own piece, so today they get a sentence each. Systems change and their records do not: a retrain, a new integration, a vendor update, and the entry now describes last quarter. Systems appear and no record does: a team, a tool, a subscription, and the estate grows off the books. And records outlive their authors: the person who knew why the entry says what it says changes jobs, and the entry becomes an artifact nobody can vouch for.
None of this requires negligence. Most of it is produced by reasonable people moving at speed. That is what makes it dangerous. There is no villain to catch, only a gap that widens quietly.
The better the process, the more convincing the fiction
Here is the uncomfortable paradox. An assessment, whether internal audit, external review, or regulatory examination, checks that controls exist and were applied. A materially wrong register passes all of it. The tiering was done. The approvals were signed. The reviews happened on schedule. Every box checks, because the boxes test the process, and the process ran faithfully, on fiction.
Worse, institutional maturity is camouflage. The more disciplined the governance process, the more credible its outputs look, and the less anyone thinks to ask whether the inputs were true. A sloppy institution gets challenged. A well governed one gets believed.
What I have seen from both sides
I spent years inside the compliance function of a global systemically important bank, and I now run a small fleet of agents of my own. The two experiences agree on one thing. In the institution, the registers we governed from were assembled with care and aged without anyone watching. In my own fleet, one operator and no politics, my record of what is actually running has drifted from reality more than once in a single quarter, and I am the only person involved. Scale that honestly to an institution with hundreds of systems, dozens of teams, and normal turnover, and the question is not whether the register is wrong somewhere. It is where, by how much, and who would know.
The test you can run this week
Pick one entry in your AI inventory, any one, and ask two questions of it.
First: if this entry were wrong today, which control would fire? Not which meeting would eventually notice. Which control, on what schedule, compares this entry against the running system and raises its hand on a mismatch?
Second: who owns the accuracy of this register, as a role? Not who maintains the document. Who is accountable for the register being true?
If the answers are none and nobody, then every control downstream of that register is conditional, and the condition has never been examined. That is not a criticism of your governance function. It is the discovery that all its diligence rests on an untested assumption.
The position I hold, and the piece I am not writing today
You cannot govern what you cannot see, and what you do see, you can only govern to the accuracy of your seeing. Every framework assumes the register is true. In most institutions, nobody is assigned to test it. That is the open hole under AI governance as it is practiced today.
I have a view on what testing a register would actually take, and it is not another review meeting. That is for another piece. Today I want to know one thing. When you ran the two questions above in your head just now, what fired, and who owned it? If your institution has a real answer, I genuinely want to hear it, because I have been looking for one.