Manifesto: AI Governance as a control plane, not a PDF policy

Governance that can’t be bypassed technically is not a document — it’s a control plane. Every model call physically passes through PII masking, access control, guardrails, and audit.

There are two ways to do AI governance. The first is to write a policy. A forty-page document: responsible AI principles, a committee, a role matrix, a requirement to "use AI ethically." It gets signed, filed in SharePoint, and revisited at the next audit. The second way is to build governance into the request path: every model call is physically unable to bypass PII masking, access control, guardrails, limits, and audit, because they stand in the way of the packet, not in the developer's head.

This is about the second way. The thesis is simple and blunt: governance that can't be bypassed technically is not a document — it's a control plane.

Continue reading “Manifesto: AI Governance as a control plane, not a PDF policy”