The problem is not the frameworks
Real governance is enforceable
- Policies exist, but no gates enforce them.
- Standards written, but no kill switch deployed.
- Risk registers maintained, but no operational ownership assigned.
- Review boards convened, but no consequences attached.
AI systems need to be inventoried like systems
- Which models run in production.
- Which data flows through them.
- Which outputs reach customers or employees.
- Which actions the system can execute.
- Who answers when it fails.
Prompt injection changed everything
- Can untrusted input hijack system behaviour?
- Can the model reach tools or APIs it shouldn't?
- Can a compromised session leak data or trigger actions?
- Can we trace and stop damage fast?
Zero trust extends to AI agents
- Authenticated — identity verified.
- Authorised with least privilege — tightly scoped.
- Logged comprehensively — every action visible.
- Contained by default — blast radius limited.
What good governance looks like
- Live AI inventory, auto-updating from pipelines.
- Named owners per system, personally accountable.
- Automated gates for high-risk deployments.
- Routine red teaming, adversarial testing.
- Logging, monitoring, rollback that works.
- AI-specific incident playbooks.
Speed is the forgotten security property
Stop rewarding theatre
- Block a bad deployment.
- Catch bad output.
- Shut down a rogue agent.
I've spent years at the intersection of product security, compliance, and shipping AI tools. Governance isn't a document problem. It's engineering and organisational design. If you're struggling with the control mapping piece — figuring out where ISO 27001, NIST CSF, and AI-specific requirements overlap — that's what I built vik.so to solve. The ISO 27001 Navigator and NIST CSF Navigator help you work through controls with AI that actually understands the standards.
What does yours enforce today — not what's written, what's real?
