The Loom · #1

AI can act now. A policy alone cannot keep up.

Adoption ran ahead of governance. Then AI started taking actions. The answer is an operating loop of six steps, and seven questions you should be able to answer today.

Published September 18, 2026 · written and approved by RiskWoven, sources checked when published

The AI governance loop: Discover, Classify, Control, Validate, Monitor, Evidence, with an arrow returning to the start, and a note that every change starts it again.

For most of the last two years, AI answered questions. A bad answer was a bad answer.

That era is ending. Today's systems search, analyse, recommend, write code and increasingly take action across connected systems. An agent can reach data, call tools and finish a multi-step task with little human involvement.

The risk equation moves with it. When AI only produced text, an error produced a poor answer. When AI can act, the same error can expose information, misuse access, trigger a transaction it should not have, or shape a business decision.

So the question changes. It used to be "can we trust the model?" It is now "can we control the system around the model?"

Why a policy is not enough

Plenty of organisations have an acceptable-use policy, an AI committee and an approval form. Those are foundations. They are not an operating model.

A policy cannot tell you:

  • which AI systems are running across the organisation
  • what information each one can reach
  • which decisions they influence
  • what tools an agent is allowed to activate
  • if the safeguards still work after a model or a vendor changes
  • who responds when something goes wrong

Governance means something once it is attached to real systems, named owners, documented controls, and monitoring that keeps running.

The loop

A governance programme works as a continuous loop, not a one-time approval.

  1. DISCOVER. Keep an inventory of AI systems, embedded features, vendors and agents built in-house. What is invisible cannot be governed.
  2. CLASSIFY. Judge each use case on purpose, affected people, data sensitivity, autonomy, legal exposure and impact. A meeting-summary assistant does not deserve the scrutiny of a system shaping a healthcare, employment, financial or security decision.
  3. CONTROL. Choose safeguards in proportion to the risk, and give each one an accountable owner: restricted data access, human approval points, identity boundaries, logging, output validation, vendor requirements, escalation.
  4. VALIDATE. Do not assume a control works because it appears in a design document. Test for security, privacy, bias, reliability, hallucination, prompt manipulation and unsafe tool use, before deployment and after it.
  5. MONITOR. Models are updated, data drifts, integrations spread, new weaknesses appear, and staff find uses nobody assessed. Watch performance, incidents, overrides, access patterns, complaints and material changes.
  6. EVIDENCE. Keep the reasoning. An audit-ready record shows what was assessed, how the risk was classified, which safeguards were chosen, who accepted the residual risk, and when it must be looked at again.

Seven questions to test yourself against

Whatever the size of the organisation, an adopter should be able to answer these:

  1. What AI systems are we using?
  2. What is each one used for?
  3. What could go wrong?
  4. What controls reduce those risks?
  5. Who is accountable?
  6. Can we show that the controls exist?
  7. What happens when something changes?

If several of those need a meeting before anyone can answer, the gap between adoption and governance is already open.

Where the published guidance agrees

The loop is not a RiskWoven invention. It is where the major frameworks already point.

Responsible AI is not a document. It is an operating capability.

Governance is not the brake

Good governance is often described as a brake on innovation. Poor governance is exactly that. Good governance does the opposite: it creates reusable decision paths. Low-risk cases move fast. High-risk systems get the deeper review. Teams know what evidence is required, who approves a deployment, and which safeguards have to stay in place.

The organisations that do well with AI will not be the ones that deploy everything without control, or the ones that block every new idea. They will be the ones that move quickly and can still explain what the system does, what information it uses, what actions it can take, what could go wrong, which controls reduce that risk, and who remains accountable.

AI has moved from experiment to execution. Governance has to make the same move.

Share on LinkedInRun the free 12-question scan
Post text to copy
AI governance cannot stop at a policy.

Adoption ran ahead of governance in most organisations. Now AI has started to act: it can reach data, call tools and finish multi-step work with little human involvement. The same error that used to produce a poor answer can now expose information or trigger something it should not.

Our new Loom issue puts the six-step loop together with the seven questions every adopter should be able to answer: Discover, Classify, Control, Validate, Monitor, Evidence.

Which step is hardest in your organisation?