Responsible AI on a Moving Faultline
Broken by design and on purpose
Imagine approving an aircraft whose engines, flight controls and operating manual might all change next month. Even better, can you imagine building the plane mid-flight? Now imagine that the manufacturer can update the aircraft remotely. Regulators are continually issuing new guidance. The performance tests used to certify the aircraft are being rewritten. Sometimes the aircraft itself is withdrawn, replaced or superseded while it is already in flight.
Hair raising? I hope so.
Most organisations would conclude that traditional approval processes would be insufficient in such an environment. However, a lot of organisations govern artificial intelligence using existing tools and pace, expecting things to jolly along without too much trouble….. oh dear, oh dear.
Across industries, governance structures remain largely built around the idea that technology is a stable target. Risk assessments are completed, approvals obtained, controls documented and projects signed off before being deployed into production. These approaches worked reasonably well when technology changed incrementally. The big secret nowadays is they are struggling.
The challenge is that AI is not standing still. Models evolve in months rather than years. Benchmarks change. Regulatory obligations emerge. New safety concerns appear. Capabilities that seemed impossible six months ago become commonplace. Systems that appeared suitable when selected may later be eclipsed, restricted, reclassified or withdrawn entirely.
As a result, the central challenge facing Responsible AI is not simply ensuring systems are ethical, safe or compliant at a particular point in time. It is ensuring those qualities remain true as the surrounding environment continues to shift.
This is the governance fault line beneath modern AI adoption.
Governing a Moving Target
Responsible AI is often described as the process of ensuring AI systems are designed, developed and deployed safely and ethically. This is only half the story.
The definition tells us what we are trying to achieve. It tells us much less about how those objectives are maintained over time. When we look back at examples, governance has often been viewed as a decision point. A committee reviews evidence. Risks are assessed. Controls are agreed. A project receives approval. The underlying assumption is that the thing being approved will remain largely consistent after that decision is made. The pace and change of AI has challenged that assumption.
A model selected today may receive substantial updates next month. A benchmark considered robust this year may be regarded as inadequate next year. Regulatory expectations continue to evolve globally. Competitive pressures encourage rapid adoption of increasingly capable systems. Organisations find themselves governing not a fixed asset, but a constantly changing ecosystem. Point of authority needs to be pushed to point in time approach.
Instead of asking: “Did we approve this system?”
we need to ask:
“Are we still comfortable with this system today?”
Technology Has Been Here Before
While AI feels unprecedented, many of the underlying governance challenges are not. Throughout history, organisations have attempted to manage technologies that developed faster than existing institutions could comfortably accommodate. Scientific megaprojects, industrial revolutions, space programmes and large-scale public sector technology initiatives have all faced versions of the same problem.
How do you govern something when the destination is uncertain and the capabilities keep evolving? The challenge is not simply technological. It is organisational. As the technology moves quickly, we clash against the fact that governance mechanisms are designed to move more deliberatively. The tension between those two can create many of the failures associated with technological adoption. When governance becomes static while technology remains dynamic, organisations frequently discover that controls designed for yesterday’s risks are being applied to tomorrow’s systems.
The problem is not always that governance is absent. Sometimes governance exists in abundance. The problem is that it was designed to govern a version of reality that no longer exists. Think the big science of the past like the Manhattan Project, The Apollo programme, but also some more recent tech I’m going to share thoughts on examples in the near future.
The Three Pillars That Continue to Matter
If AI governance is about managing change, what should organisations focus on? One useful perspective I’ve found comes from project governance.
The Association for Project Management defines governance as the framework of authority and accountability that defines and controls outputs, outcomes and benefits.
Hidden within that definition are three concepts that appear consistently throughout successful governance approaches
Although these concepts are hardly new, they remain surprisingly relevant to modern AI governance. Across contemporary governance frameworks, regulations and industry guidance, these themes appear repeatedly. Whether reviewing government guidance, international standards or emerging regulation, the same questions emerge.
We’re asking who decides, who’s responsible, and how do we check it’s doing what it’s meant to ? Can I speak to the manager? The terminology may differ, but we keep asking the same underlying questions.
Why The Ground Continues To Shift
Traditional software generally behaves within fairly predictable parameters. AI systems increasingly exhibit behaviour that is probabilistic, adaptive and difficult to fully anticipate. At the same time, external factors continue to move as the models improve, benchmarks shift. We also have to contend with the new attack methods which can emerge in these new tools. We have also started to discover Regulators issue fresh requirements with surprising speed where needed.
The result is a governance environment where organisations cannot assume that previous decisions remain valid indefinitely. An AI risk assessment completed six months ago may still be useful. It may also be based on assumptions that no longer hold true. Governance becomes less about reaching a definitive answer and more about maintaining an ongoing process of challenge and reassessment.
Responsible AI has begun to learn these important lessons as governance is not a single event, but a regular discipline.
The Danger of Governance Theatre
One of the more uncomfortable realities exposed by recent AI debates is that governance can become performative. We’ve all been there, the organisations can create policies, great tomes of files which nice shiny front covers and boiler plate review schedules. the risk registers are maintained and tweaked on the start of the review cycle and good intentions arise. Every once in a while, an assurance report is produced and on paper (pun intended) everything seems to be functioning correctly. But what lies beneath? Blind luck and unknown chaos..
This occurs because controls often become focused on demonstrating compliance rather than testing whether outcomes remain acceptable. In other words, organisations become very good at proving they followed the process and much less effective at questioning whether the process itself remains appropriate.
The irony is, this isn’t how compliance is intended to be. You should be thinking about the what ifs as well what is currently the rules coverage.
This distinction between theatre and actually doing it matters. AI systems can be fully compliant with yesterday’s assumptions while simultaneously creating tomorrow’s problems. Governance that cannot adapt risks becoming administrative theatre: impressive documentation surrounding increasingly fragile assumptions.
From Approval to Assurance
If there is a single lesson emerging from modern AI governance, it is that approval is no longer enough. While traditional governance treated assurance as something that happened before deployment, AI will require assurance throughout the lifecycle.
The critical questions become:
Does authority still reside with the right people?
Is accountability still clear?
Do controls remain appropriate?
Have the assumptions behind previous decisions changed?
Are we governing today’s system, or the version that existed six months ago?
Those questions are not merely technical ones for the project delivery teams. They are governance questions which echo through an organisation. Responsible AI requires governance mechanisms capable of adapting as quickly as the technologies they seek to oversee.
Final Thoughts
I’ve heard some people say that responsible AI governance is presented as the search for perfect controls. Utter rubbish, it will fail (to some degree) every time. However, never let the perfect be the enemy of the good.,
In reality, perfect controls rarely exist, particularly at the frontier of technological development. The objective is not perfection, it’s about adaptability, reading the movements as they happen and keeping up to date where things begin to shift. Reshaping assumptions as you go and deliberately checking for assurance.
Those pillars I picked up earlier, Authority, accountability and controls remain as important today as they were in previous eras of technological change. What has changed is the speed with which those pillars must be reassessed. I’m going to investigate these in more depth in the future (watch this space).
If you take something away with you from this wandering piece of prose on Responsible AI, it’s this:
· Accept you might be standing in the rubble tomorrow.
· The big themes have probably happened before and you just haven’t been told about it.
· Be irresponsibly responsible and keep inquisitive. Test the tech and don’t let it tell you it’s all fine.




