What happens when an AI agent looks for an API key and deletes a production database, when it wasn’t supposed to?
As quality professionals, governance wasn’t a topic that particularly interested us. Most organizations have glaring gaps in governance that were ignored thus far. In this episode with Brijesh Deb, Vitaly and Anupam dig deeper into governance and conclude how with AI, these governance gaps become too big to ignore. What’s more? Fixing that gap is a perfect opportunity for quality professionals to establish greater relevance in the era of AI-powered software development.
Brijesh offered a 7-point framework to think about AI Governance:
1. Work intent & context: Is the AI still doing the work we think it is doing, for the users and conditions we actually have now?
2. Autonomy boundaries: What can it decide or do without intervention, and is that autonomy still justified?
3. Memory & state: What persists, what can become stale or hidden, and can people inspect and correct it?
4. Permissions & tools: Does access reflect the task, or has authority accumulated because it was convenient?
5. Evidence & evaluation: Does the strength of evidence match the consequence of being wrong?
6. Human review: Can a person realistically detect and stop a harmful action, or is a human merely present on paper?
7. Monitoring & learning: Are we evaluating the living workflow and changing controls when reality moves?
He aims to take his inquiry further into building an evidence to decision loop: a basis to collect the right kind of evidence so that stakeholders can make informed decisions with regard to software, where AI is involved.
Links:
- Discussion Thread: https://github.com/BeyondQuality/beyondquality/discussions/43
- Vitaly’s AI governance research artifact: https://github.com/BeyondQuality/beyondquality/blob/main/research/quality-governance/quality-governance.md
- Brijesh LinkedIn: https://www.linkedin.com/in/debbrijesh/
- PocketOS incident: https://www.fastcompany.com/91533544/cursor-claude-ai-agent-deleted-software-company-pocket-os-database-jer-crane