Skip to content
London AI Research™ Contact

Research area / AI Governance

Governance that can be observed, evidenced, and improved.

We study how AI governance becomes an operating system: inventories, decision rights, controls, evidence, testing, monitoring, incident response, assurance, and executive accountability.

Modern institutional research environment
GOVERNANCE / CONTROL / EVIDENCEPolicy becomes useful when it can be operationalized.

From policy to operating control.

Effective governance connects institutional accountability to the technical and operational systems where AI is selected, configured, deployed, monitored, and changed.

InventoryClassifyOwnAssessControlEvidenceApproveMonitorRespondReview

Control architecture

A governance system for real deployment.

We organize governance around control points that can be owned, evidenced, tested, and improved.

01

Accountability

Named owners, decision rights, escalation paths, approval thresholds, and board-level oversight.

02

Risk classification

Consistent methods to determine impact, criticality, data sensitivity, autonomy, and control depth.

03

Evidence

Durable proof that required reviews, tests, approvals, monitoring, and remediation actually occurred.

04

Runtime control

Identity, authorization, monitoring, action boundaries, human intervention, and revocation for AI systems and agents.

05

Assurance

Independent review of whether governance mechanisms are designed effectively and operating as intended.

06

Change

Versioned controls and reassessment as models, workflows, data, regulations, and system capabilities evolve.

Agentic AI

Govern the action, not only the output.

As AI systems gain tools, memory, credentials, and authority, governance must extend into runtime behavior. Institutions need to know what an agent was allowed to do, what it actually did, which resources it touched, and who remained accountable.

Explore AI identity research

Governance evidence

Controls should leave a trace.

Governance becomes operational when an institution can show what was reviewed, by whom, against which criteria, with what result, and what changed afterward.

Evidence chain

01

Design evidence

Policies, control objectives, risk methods, ownership, thresholds, technical patterns, and approval criteria.

02

Operating evidence

Test results, approvals, logs, monitoring, exceptions, human interventions, incidents, and remediation.

03

Assurance evidence

Independent challenge, findings, residual-risk decisions, reassessment, and version history.