Describes an architecture to improve AI governance, ensuring regulatory compliance through operational evidence.
Organizations preparing for AI regulation often treat readiness as a paperwork exercise: policies get drafted, registers get filled, and the resulting binder gets presented as compliance. Audit practice in adjacent regulated domains suggests this framing collapses at the first serious question: show me that this control operated on this system in this period. This paper describes an architecture for AI governance built around that question. Its central object is the control, an owned, recurring activity that satisfies a regulatory requirement and leaves evidence behind. Requirements link to controls, controls link to their instances of execution, and instances link to evidence with full lineage. The measure of governance shifts from document presence to control coverage and operating effectiveness. I propose the term control intelligence for this layer: applicability determination, control design, control effectiveness, and drift signals treated as one connected data model. Current tooling tends to hold these pieces in separate modules. Two operational metrics follow from this: Governance Friction, the share of machine-suggested mappings that require human review, and its inverse, Automation Rate. The design grew out of six specification iterations for a planned software platform. Its concepts apply equally to manual governance programs.
No takes yet. Share an insight, caveat, or question.
Hanna Vasiukova (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: