Accountability
Named owners, decision rights, escalation paths, approval thresholds, and board-level oversight.
Research area / AI Governance
We study how AI governance becomes an operating system: inventories, decision rights, controls, evidence, testing, monitoring, incident response, assurance, and executive accountability.
Effective governance connects institutional accountability to the technical and operational systems where AI is selected, configured, deployed, monitored, and changed.
Control architecture
We organize governance around control points that can be owned, evidenced, tested, and improved.
Named owners, decision rights, escalation paths, approval thresholds, and board-level oversight.
Consistent methods to determine impact, criticality, data sensitivity, autonomy, and control depth.
Durable proof that required reviews, tests, approvals, monitoring, and remediation actually occurred.
Identity, authorization, monitoring, action boundaries, human intervention, and revocation for AI systems and agents.
Independent review of whether governance mechanisms are designed effectively and operating as intended.
Versioned controls and reassessment as models, workflows, data, regulations, and system capabilities evolve.
Agentic AI
As AI systems gain tools, memory, credentials, and authority, governance must extend into runtime behavior. Institutions need to know what an agent was allowed to do, what it actually did, which resources it touched, and who remained accountable.
Explore AI identity researchGovernance evidence
Governance becomes operational when an institution can show what was reviewed, by whom, against which criteria, with what result, and what changed afterward.
Evidence chain
Policies, control objectives, risk methods, ownership, thresholds, technical patterns, and approval criteria.
Test results, approvals, logs, monitoring, exceptions, human interventions, incidents, and remediation.
Independent challenge, findings, residual-risk decisions, reassessment, and version history.