Welcome

Passionately curious about Data, Databases and Systems Complexity. Data is ubiquitous, the database universe is dichotomous (structured and unstructured), expanding and complex. Find my Database Research at SQLToolkit.co.uk . Microsoft Data Platform MVP

"The important thing is not to stop questioning. Curiosity has its own reason for existing" Einstein



Tuesday, 8 September 2026

The Hierarchy of AI Oversight

Organisations frequently treat Responsible AI, AI Governance, and Data Governance as synonymous concepts. In practice, they represent three distinct, interdependent structural tiers. Treating them as interchangeable obscures how AI systems are built, verified, and operationalised within an enterprise.

A useful way to conceptualise this structure is through a three-part stack:

  •  Responsible AI defines organizational intent and boundaries.
  •  AI Governance establishes operational execution and control mechanisms.
  •  Data Governance manages the underlying assets and pipeline inputs.
When any single tier is neglected, the entire oversight framework becomes ineffective.

Responsible AI: Establishing Strategic Intent

Responsible AI sits at the top of the stack as an explicit declaration of intent. It articulates an organisation's risk tolerance, core values, and societal commitments regarding automated systems.
This layer does not detail specific technical configurations or workflow steps. Instead, it defines the overarching ethical perimeter, addressing core themes such as non-discrimination, explainability, safety, and accountability.

Key questions addressed at this layer include:
  •  What operational boundaries define acceptable versus unacceptable AI deployments?
  •  What specific harms must system designs actively prevent?
  •  What baseline commitments are required for external stakeholders and regulatory bodies?
While Responsible AI acts as the strategic compass, policy statements alone do not alter system behavior. Without operational enforcement, policy declarations remain purely symbolic. Operationalising these policies requires the secondary layer: AI Governance.

AI Governance: Implementing Operational Control

AI Governance provides the operational apparatus required to enforce Responsible AI policies. It consists of the decision rights, verification protocols, audit trails, and risk taxonomies that manage an AI model across its complete lifecycle.

This tier shifts abstract commitments into concrete engineering and management workflows. It covers model validation standards, change management, automated drift detection, and post-deployment monitoring. Systems like the GRAICE framework operate within this domain to standardise evaluation criteria.

Key questions addressed at this layer include:
  • Which roles hold approval authority at distinct stages of model development?
  • What quantitative evidence is required prior to production deployment?
  • How are performance degradation, bias drift, and unexpected edge cases detected and remediated?
  • What specific conditions trigger a mandatory model recall or pause?
AI Governance ensures that models operate within defined parameters over time. However, governance controls cannot ensure model integrity if the underlying inputs are flawed. Control frameworks require verifiable data inputs, which depends entirely on the foundational layer.

Data Governance: Securing the System Inputs

Data Governance manages the quality, legal basis, security, and lineage of the data fed into machine learning pipelines. Because statistical models reflect the characteristics of their training data, AI performance is constrained by the quality of its underlying data architecture.

Without robust data management, model output becomes inherently unpredictable. Issues such as unverified data sources, unrecorded pipeline transformations, or demographic skew directly compromise model outputs regardless of how stringent the AI control checks are.

Key questions addressed at this layer include:
  •  What is the precise lineage and chain of custody for training and validation datasets?
  •  Do clear usage rights, legal bases, and consent frameworks exist for the ingested data?
  •  Is the dataset representative, accurate, and properly versioned?
  •  How are data access controls and privacy-preserving techniques maintained through the pipeline?
Strong Data Governance provides the verifiable evidence base that AI Governance relies on. Without it, validation processes lack technical substance
.
Structural Pitfalls of Top-Down Implementation

A common failure mode occurs when organisations implement oversight from the top down. Leadership teams often publish high-level ethical guidelines and establish oversight committees before building the necessary operational controls or securing data infrastructure.

This top-down approach creates several operational vulnerabilities:
  •  Oversight committees evaluate systems without reliable technical lineage or performance data.
  •  Data quality defects and unverified assumptions are identified late in production rather than during ingestion.
  •  Ambiguity surrounds technical accountability when failures occur.
  • Defining ethical principles without establishing underlying governance frameworks leads to superficial compliance—where policy commitments exist on paper but cannot be verified or enforced at the engineering level.
Building a Cohesive Oversight Framework

Establishing an effective oversight framework requires starting from foundational technical controls and building upwards:
  • Establish Data Integrity: Secure data lineage, document legal rights, enforce validation checks, and maintain clear data stewardship across all pipelines.
  • Deploy Control Architectures: Implement repeatable stage-gate approvals, continuous testing protocols, risk logging, and lifecycle monitoring.
  • Align Operational Controls with Policy Boundaries: Connect technical metrics and threshold alerts directly to high-level organizational principles and regulatory requirements.
Aligning these three disciplines transforms AI oversight from a collection of isolated policies into an integrated operational capability.

Thursday, 3 September 2026

Governance Capabilities for High-Risk AI in the EU AI Act

Much of the discussion around the EU AI Act focuses on obligations, classifications, and compliance deadlines. While those are important, they can also obscure a more interesting point. The Act is not simply creating another regulatory checklist. It is describing the governance capabilities organisations need if they want to develop, deploy, and operate AI safely and responsibly at scale.




This becomes particularly clear when looking at Articles 8-15. Rather than a collection of disconnected requirements, these articles describe a connected operating model. They bring together governance, risk management, data quality, transparency, human oversight, documentation, and security into a framework that supports trustworthy AI throughout its lifecycle.

The infographic accompanying this article visualises those capabilities as a connected system rather than a sequence of isolated controls. Before exploring each capability, it is worth understanding where Articles 8-15 sit within the broader structure of the AI Act.

The Risk-Based Foundation of the EU AI Act

The EU AI Act adopts a risk-based approach to regulation. Rather than treating every AI system equally, it classifies systems according to the level of risk they present.

At the top of the pyramid are applications considered to represent an unacceptable risk. These uses are prohibited because they are considered incompatible with European values and fundamental rights. Below this sit High-Risk AI Systems, which are subject to the most extensive governance requirements. Beneath these are Limited Risk and Minimal Risk systems, where obligations are significantly lighter.

This distinction is important because Articles 8-15 are primarily concerned with the governance capabilities required for High-Risk AI Systems. They define what organisations must have in place to demonstrate that these systems are designed, operated, and monitored appropriately.

Governance and Accountability

Effective AI governance starts with accountability.

Although Article 8 focuses on compliance with the requirements applicable to high-risk systems, this is closely linked to the Quality Management System requirements described later in Article 17. Together, they establish the expectation that organisations must have clear governance structures, defined responsibilities, documented processes, and mechanisms for continuous improvement.

This is often where governance discussions become overly procedural. In practice, what matters is whether accountability exists. Who owns decisions? Who approves risk acceptance? Who monitors outcomes? Who intervenes when issues arise?

Organisations that treat governance as a collection of policies frequently struggle to answer these questions. Those that build governance into their operating model tend to have far greater confidence in how AI is being used and controlled.

Risk Management

One of the most significant requirements within the AI Act is the expectation that risk management is continuous.

Article 9 requires organisations to establish, implement, document, and maintain a risk management system throughout the entire lifecycle of a high-risk AI system. This is not a one-off assessment performed during development. Risks must be identified, evaluated, mitigated, monitored, and reassessed over time.

This reflects a broader reality of AI. Models evolve, data changes, user behaviour shifts, and operating environments become more complex. The risks associated with an AI system today may not be identical to those that emerge six months from now.

A mature governance programme therefore treats risk management as an ongoing capability rather than a project activity.

Data Governance

No governance framework can compensate for poor-quality data.

Article 10 recognises this by placing significant emphasis on the quality and governance of training, validation, and testing datasets. Organisations must consider data provenance, representativeness, relevance, completeness, and bias mitigation.

Many AI governance conversations focus heavily on models while paying less attention to the data that underpins them. Yet data remains one of the strongest determinants of whether an AI system will behave as intended.

This requirement is also one of the clearest areas where tools such as Microsoft Purview can support governance objectives. Data lineage, metadata management, business glossaries, and data quality capabilities provide organisations with the visibility needed to understand where data originates, how it moves, and whether it can be trusted for AI use cases.

Data governance is not a separate discipline sitting alongside AI governance. It is one of its foundational components.

Documentation and Evidence

Good governance depends upon evidence.

Articles 11 and 12 establish the requirements for technical documentation and record keeping. Organisations must maintain sufficient documentation to demonstrate conformity with regulatory obligations and provide evidence regarding how the system operates.

Technical documentation includes information such as system design, intended purpose, performance characteristics, testing activities, and risk assessments. Record keeping focuses on logs, traceability, and the ability to reconstruct events when needed.

This may appear administrative at first glance, but it plays a critical role in building accountability. When questions arise about an AI system's behaviour, organisations need more than assumptions or recollections. They need evidence. Documentation transforms governance from intention into demonstration.

Transparency and Explainability

A system cannot be governed effectively if nobody understands how it should be used.

Article 13 requires high-risk AI systems to be sufficiently transparent so that deployers can interpret outputs and use the system appropriately. Users must be provided with information about intended use, limitations, and operational considerations.

Transparency is often reduced to explainability discussions, but it extends beyond technical explanations of model behaviour. It also encompasses user guidance, operational context, and clarity regarding what the system should and should not be used for.

Many governance failures occur not because the AI was technically flawed but because people misunderstood its outputs or relied upon it in inappropriate ways. Transparency helps prevent those misunderstandings.

Human Oversight

One of the most important themes within the AI Act is the continuing role of human judgement.

Article 14 requires organisations to design systems that enable appropriate human oversight. This includes mechanisms for review, escalation, intervention, and, where necessary, stopping or overriding the system.

The phrase "human in the loop" is often used when discussing AI oversight, but the Act's expectations are broader than that. Effective oversight requires authority, competence, and accountability, not merely human presence. People need to be able to challenge outcomes, recognise anomalies, and take action when circumstances demand it. Governance remains a human responsibility, even when decisions are increasingly supported by AI.

Accuracy, Robustness and Security

The final capability area focuses on operational resilience.

Article 15 requires high-risk AI systems to achieve appropriate levels of accuracy, robustness, and cybersecurity throughout their operational life. Organisations must consider not only normal operating conditions but also errors, failures, misuse, and malicious attacks.

This reflects an important shift in thinking. Governance is not solely about policies and controls. It is also about operational performance.

An AI system that cannot remain reliable, secure, and resilient under real-world conditions cannot ultimately be considered trustworthy.

Governance is more than Compliance

When viewed together, Articles 8-15 reveal something that is often missed in discussions about the EU AI Act. The regulation is not describing a set of independent controls. It is describing a connected governance system.

Risk management relies on trustworthy data. Transparency depends on documentation. Oversight requires accountability. Security depends upon effective governance. Each capability supports the others.

This is why organisations should resist the temptation to approach the AI Act as a compliance exercise alone. The most successful governance programmes will be those that use these requirements to establish sustainable operating models that support responsible AI adoption at scale.

Ultimately, the organisations that thrive in the AI era are unlikely to be those with the longest policy documents. They will be those that can demonstrate consistent, repeatable, and accountable governance across their AI estate. That is the broader message embedded within Articles 8-15, and it is arguably far more significant than compliance alone.

Cambridge Report on Database Research and what it means for the future of Data Governance

The Cambridge Report on Database Research, convened on October 19-20, 2023, in Cambridge, MA, discussed the state of the database research field, its recent accomplishments, ongoing challenges, and future directions for research and community engagement. 


Every five years, some of the world's leading database researchers come together to reflect on the state of data management and identify the challenges that will shape the next generation of technology. The latest Cambridge Report on Database Research does exactly that, exploring everything from cloud infrastructure and AI to data systems, machine learning, and governance. While it is not a governance report in the traditional sense, it offers some important clues about how governance will need to evolve over the coming decade.

The most striking observation is that governance is becoming inseparable from the platforms that manage data. The report describes a future where data systems are increasingly autonomous, with automated provisioning, self-managing infrastructure, adaptive optimisation, and intelligent control planes. As these capabilities mature, many of the technical tasks traditionally associated with governance, such as metadata collection, lineage discovery, classification, and monitoring, will become increasingly automated.

For governance professionals, this represents a significant shift in focus. The challenge will no longer be capturing metadata or maintaining catalogues. Technology will increasingly perform those activities automatically. Instead, organisations will need to determine who is accountable, what policies should govern the use of information, and how trust is maintained across an increasingly complex data and AI landscape. The report also highlights the growing importance of data quality. Future AI models, adaptive systems, and cloud platforms depend on access to trusted, well-managed information. Researchers point to the need for better mechanisms to collect, benchmark, validate, and monitor data at scale. This suggests a future in which data quality becomes a continuously monitored capability rather than a periodic assessment exercise. Many organisations still approach data quality through project-based remediation programmes. However, the direction of travel is towards automated detection, AI-assisted monitoring, and real-time observability. Governance teams will increasingly define quality expectations, ownership responsibilities, and remediation processes, while platforms identify issues and measure compliance against agreed standards.

Perhaps the biggest governance implication comes from the report's focus on AI. Researchers describe a world where traditional databases are no longer the only source of knowledge. Future systems will need to manage documents, images, videos, unstructured content, and AI-generated outputs alongside structured business data. They even envision the ability to query large collections of documents and multimedia content in much the same way that organisations query databases today. This changes the scope of governance dramatically. Governance can no longer focus solely on data warehouses, data lakes, and business intelligence platforms. It must expand to cover enterprise knowledge, collaboration content, AI-generated information, and the growing number of systems that sit between data and decision-making. The report is particularly clear on the need to improve trust in AI-generated outputs. Reducing hallucinations, validating responses, improving retrieval mechanisms, and establishing provenance are all identified as important areas for future innovation. Databases and data management technologies are viewed as a critical part of solving these challenges.

For governance leaders, this is perhaps the most important signal of all. Historically, governance has focused on data ownership, standards, policies, and compliance. In an AI-enabled organisation, the questions become much broader. Where did this answer come from? Which sources were used? Can the result be traced back to trusted information? Who is accountable if the answer is incorrect? These are governance questions as much as they are technical ones. Viewed through this lens, governance starts to look less like an administrative function and more like an assurance discipline. The future governance team may spend less time maintaining catalogues and more time providing confidence in how data, knowledge, and AI are used across the organisation.

What emerges from the Cambridge Report is not a vision of governance disappearing into technology. Quite the opposite. As automation removes manual governance activities, the importance of human accountability, oversight, assurance, and decision-making increases. The technology may become smarter, but organisations will still need clear ownership models, governance operating structures, and mechanisms to establish trust. This aligns with a trend that many organisations are already beginning to recognise. Data governance and AI governance are unlikely to remain separate disciplines for long. Instead, they are converging into a broader information governance operating model that spans data, knowledge, accountability, oversight, assurance, and responsible use.

The technologies will change. Automation will increase. AI will become embedded in everyday business processes. But the fundamental objective of governance remains the same: ensuring that people can trust the information they use to make decisions. The Cambridge Report suggests that this objective may become even more important as intelligent systems become a standard part of the enterprise technology landscape.

My key takeaway is the future of governance is not more policies, more committees, or bigger catalogues. It is creating an operating model that provides confidence in data and AI at scale, while allowing increasingly automated platforms to handle much of the underlying governance workload.