OPERATIONAL ASPECTS OF AI GOVERNANCE
R&C: How has the conversation around artificial intelligence (AI) governance changed in recent years?
Justus: The introduction of generative artificial intelligence (genAI) triggered more focused conversations about AI risk and governance. Governance professionals grappled with how genAI differed from other AI technologies that had been around for decades and why those differences necessitated new governance functions. Seemingly simple tasks like defining ‘AI’ in routine agreements became a puzzle. Over time, AI fluency increased while persisting as a central focus of legal and business commentary. It became common for organisations to have an AI policy, AI training for employees, a suite of AI tools available for use and an AI committee overseeing it all. Today’s more mature conversations focus on AI architectural and deployment decisions such as ‘build versus buy’, budget projections, on-prem solutions, data permissions, guardrails, agentic workflows and actionable governance.
Kem: The most visible change around AI governance is who participates. In higher education, compliance, IT, legal and academic leadership are increasingly involved in AI platform design because most initiatives incorporate AI in some form through transaction analysis, compliance reviews or records processing. That shift has reframed the conversation. A few years ago, the focus was whether to adopt AI at all, emphasising principles such as fairness, transparency and explainability. Today the questions are operational. How does data enter the system? Who reviews outputs before decisions are made? How is that documented? Boards expect evidence that human oversight occurred, and regulators look for the same during examinations. AI governance has moved from defining principles to proving that policies work in daily operations.
