James Kavanagh led the program that earned Amazon Web Services the first ISO 42001 certification of any global cloud provider. Then he sat down with us and said it plainly: you can implement that standard end to end and still not move the safety or the security of the systems you actually operate.
Adding more standards does not fix it either.
That is not a cheap shot at ISO. It is a shot at what he calls static governance, the belief that you can hold a system still, check it once a year, and call the result assurance. James spent 25 years across Microsoft and Amazon in engineering, security and regulatory roles, including the AWS team whose job was to understand every law and regulation on earth, translate it backward into engineering, and get the engineers to answer back in assurance language.
Before any of that he was a chemical engineer designing plants and running operators through simulated disasters, which turns out to be the whole point.
His argument is that an AI system is not just complicated. It is complex, it has emergent behavior, and it is unbounded, and we are standing inside the box we keep trying to draw around it. He calls the alternative adaptive governance, and he says it works at ten people and at Amazon scale.
We pushed on the part that matters to this audience. If the standard is not the answer, what is. If your engineers are never going to read the impact assessment, what were we producing it for. And where exactly did cyber learn its lessons, given that the things we already knew keep getting relearned every five years.
KEY TAKEAWAYS
Adaptive governance, defined without the buzzwords: build governance that changes at the same rate as the system you are governing.
Complicated, complex, unbounded. Why the third one is what actually breaks the annual audit model.
Technical problems versus adaptive problems. An adaptive leadership frame you can use with your team on Monday.
The behavioral model that scales down to a ten person shop: encourage, coach, sanction, and why the default response to bad behavior should be that you designed the system wrong.
Three tiers of compliance behavior. Checkbox compliance, high integrity compliance, and a third tier that is worse than both.
Why engineers never read the 50 page impact assessment, and what breaks when the management system and the engineering never meet.
What actually made cyber more secure, and why it was not FedRAMP and it was not more prescriptive requirements.
The engineering design rule every safety discipline treats as rule zero, and where AI at global scale is currently violating it.
Straight career talk. AI governance is not a niche, it is not easy money, and right now the field has no experts.
FIND JAMES
LinkedIn: https://www.linkedin.com/in/jameskavanagh1/
AI Career Pro: https://governance.aicareer.pro
Doing AI Governance newsletter: https://blog.aicareer.pro
#AIGovernance #ISO42001 #GRCEngineering #AntiCheckbox #AdaptiveGovernance #AIRisk #AIGP #Compliance #CyberSecurity #ResponsibleAI