▲ 2 r/AISystemsEngineering+1 crossposts

Is AI governance actually working in your organisation?

I’ve been looking into AI governance for the last few months and, to be honest, I’m trying to understand what this actually looks like inside real companies — not what the frameworks say it should look like.

I’d really like to hear from people who are actually dealing with AI governance, risk, compliance, security, privacy or data governance day to day.

A few things I’m really curious about:

How does your organisation actually keep track of all the AI systems being used across the business?

How do you work out which systems are high-risk and what controls need to apply?

Where does all the evidence actually live — policies, assessments, approvals, vendor documentation, testing, audit trails, etc.?

What are you still managing through spreadsheets, emails, SharePoint, Jira or a collection of different tools?

When an AI system changes, how do you know that the risk/compliance assessment needs to be looked at again?

What’s the most painful or time-consuming part of AI governance for you at the moment?

If you already use an AI governance or GRC platform, what does it still not do particularly well?

And probably the question I’m most interested in:

If you could make one part of AI governance disappear tomorrow, what would it be?

I’m not trying to sell anything here. I’m trying to understand where the genuinely difficult problems are before deciding what is actually worth building.
So if you’re doing this in the real world, I’d genuinely appreciate the brutally honest version.

Even if the answer is:

“Our process is a complete fucking mess.”

That’s useful to know.

I’m particularly interested in what’s happening in smaller and mid-sized organisations that don’t have massive AI governance teams and endless budgets.

Would really appreciate hearing how people are actually dealing with this.

reddit.com
u/Hefty_Mongoose691 — 2 days ago
▲ 0 r/CIO

Is AI governance actually working in your organisation?

I’ve been looking into AI governance for the last few months and, to be honest, I’m trying to understand what this actually looks like inside real companies — not what the frameworks say it should look like.
I’d really like to hear from people who are actually dealing with AI governance, risk, compliance, security, privacy or data governance day to day.

A few things I’m really curious about:

How does your organisation actually keep track of all the AI systems being used across the business?

How do you work out which systems are high-risk and what controls need to apply?

Where does all the evidence actually live — policies, assessments, approvals, vendor documentation, testing, audit trails, etc.?

What are you still managing through spreadsheets, emails, SharePoint, Jira or a collection of different tools?

When an AI system changes, how do you know that the risk/compliance assessment needs to be looked at again?

What’s the most painful or time-consuming part of AI governance for you at the moment?

If you already use an AI governance or GRC platform, what does it still not do particularly well?

And probably the question I’m most interested in:

If you could make one part of AI governance disappear tomorrow, what would it be?

I’m not trying to sell anything here. I’m trying to understand where the genuinely difficult problems are before deciding what is actually worth building.
So if you’re doing this in the real world, I’d genuinely appreciate the brutally honest version.

Even if the answer is:

“Our process is a complete mess.”

That’s useful to know.

I’m particularly interested in what’s happening in smaller and mid-sized organisations that don’t have massive AI governance teams and endless budgets.
Would really appreciate hearing how people are actually dealing with this.

reddit.com
u/Hefty_Mongoose691 — 2 days ago
▲ 1 r/AIgovernance+1 crossposts

Is AI governance actually working in your organisation?

I’ve been looking into AI governance for the last few months and, to be honest, I’m trying to understand what this actually looks like inside real companies — not what the frameworks say it should look like.

I’d really like to hear from people who are actually dealing with AI governance, risk, compliance, security, privacy or data governance day to day.

A few things I’m really curious about:

How does your organisation actually keep track of all the AI systems being used across the business?

How do you work out which systems are high-risk and what controls need to apply?

Where does all the evidence actually live — policies, assessments, approvals, vendor documentation, testing, audit trails, etc.?

What are you still managing through spreadsheets, emails, SharePoint, Jira or a collection of different tools?

When an AI system changes, how do you know that the risk/compliance assessment needs to be looked at again?

What’s the most painful or time-consuming part of AI governance for you at the moment?

If you already use an AI governance or GRC platform, what does it still not do particularly well?

And probably the question I’m most interested in:

If you could make one part of AI governance disappear tomorrow, what would it be?

I’m not trying to sell anything here. I’m trying to understand where the genuinely difficult problems are before deciding what is actually worth building.
So if you’re doing this in the real world, I’d genuinely appreciate the brutally honest version.

Even if the answer is:

“Our process is a complete fucking mess.”

That’s useful to know.

I’m particularly interested in what’s happening in smaller and mid-sized organisations that don’t have massive AI governance teams and endless budgets.
Would really appreciate hearing how people are actually dealing with this.

reddit.com
u/Hefty_Mongoose691 — 2 days ago