<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Governance Under Scale on Andrew Hunter — Systems Architect &amp; Builder</title>
    <link>https://andrewphunter.com/series/governance-under-scale/</link>
    <description>Recent content in Governance Under Scale on Andrew Hunter — Systems Architect &amp; Builder</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 24 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://andrewphunter.com/series/governance-under-scale/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Governance Under Scale — Part IV: Model Selection, NAIC, and the Crosswalk</title>
      <link>https://andrewphunter.com/writing/naic-and-the-crosswalk/</link>
      <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://andrewphunter.com/writing/naic-and-the-crosswalk/</guid>
      <description>&lt;p&gt;Every framework that now governs enterprise AI asks the same question, and none of them ask it of the model. NAIC, NIST, ISO, the EU, and the bank regulators want to know whether the system is under control: what it can touch, what it can do, who is accountable, and how you would stop it. The model sits inside that system as a component whose behavior you can shape but never guarantee.&lt;/p&gt;&#xA;&lt;p&gt;This is the argument the first three parts made from first principles, now arriving from five directions at once: a governed system built around a model you cannot govern directly.&lt;/p&gt;&#xA;&lt;hr&gt;</description>
    </item>
    <item>
      <title>Governance Under Scale — Part III: Revocation and the Reachable Decision Surface</title>
      <link>https://andrewphunter.com/writing/revocation-and-the-reachable-decision-surface/</link>
      <pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://andrewphunter.com/writing/revocation-and-the-reachable-decision-surface/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://andrewphunter.com/writing/monitoring-is-not-control/&#34;&gt;Part II&lt;/a&gt; separated visibility from control. A system can observe its own drift, make its behavior legible, and surface deviation across time and risk class, and still not be governed, because it cannot change its authority in response. It is instrumented, not controlled.&lt;/p&gt;&#xA;&lt;p&gt;That leaves one place for governance to live: the capacity to change what the system is permitted to do.&lt;/p&gt;&#xA;&lt;p&gt;Most current AI governance aims somewhere else. It treats control as a behavior problem: make the model produce safer outputs, fold policy into training, reinforce acceptable responses, condition the system toward the posture the institution wants. Better behavior is worth having, but it is not governance. Training, monitoring, and reinforcement change how a system behaves. None of them change what it is permitted to do next, and at scale that is the distinction that matters.&lt;/p&gt;&#xA;&lt;hr&gt;</description>
    </item>
    <item>
      <title>Governance Under Scale — Part II: Monitoring Is Not Control</title>
      <link>https://andrewphunter.com/writing/monitoring-is-not-control/</link>
      <pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://andrewphunter.com/writing/monitoring-is-not-control/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://andrewphunter.com/writing/human-override-is-not-governance/&#34;&gt;Part I&lt;/a&gt; established that human override is not an external safeguard. It operates inside the system, as a delegation surface through which authority expands when it is not explicitly constrained. Correction at the level of the instance becomes, over time, a mechanism by which authority grows.&lt;/p&gt;&#xA;&lt;p&gt;The institution that discovers this reaches for the obvious fix: make the system legible. Instrument decisions, surface deviations, trace patterns across time and risk class. Monitoring frameworks, evaluation pipelines, audit trails, and reporting layers go in, and they quietly take on a second role. They stop being instruments of visibility and start standing in for governance.&lt;/p&gt;&#xA;&lt;p&gt;They cannot. Visibility does not constrain authority. A system can be fully observable, legible at every layer, and still operate within the same set of permitted actions. Observed that thoroughly, monitoring does not constrain the system. It describes it.&lt;/p&gt;&#xA;&lt;hr&gt;</description>
    </item>
    <item>
      <title>Governance Under Scale — Part I: Human Override Is Not Governance</title>
      <link>https://andrewphunter.com/writing/human-override-is-not-governance/</link>
      <pubDate>Mon, 02 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://andrewphunter.com/writing/human-override-is-not-governance/</guid>
      <description>&lt;p&gt;In most enterprise AI deployments, “human in the loop” is treated as a safety guarantee. Put a reviewer in front of a probabilistic system and its output is assumed to become accountable: the model may err, but the human will catch it.&lt;/p&gt;&#xA;&lt;p&gt;A human reviewer is not an independent control plane sitting outside the system. Reviewers operate inside the same delegation structure, under the same throughput pressure, incentives, partial information, and local optimization. At scale, human override is not a check on authority. It is another authority surface, one that expands scope, normalizes exceptions, and quietly redefines what the institution permits.&lt;/p&gt;&#xA;&lt;p&gt;Override is not governance. Mistaking it for governance is how authority expands while everyone believes it is being contained.&lt;/p&gt;&#xA;&lt;hr&gt;</description>
    </item>
  </channel>
</rss>
