Risk Management Blog | Riskware - Enterprise Risk Management Software

Governing systems that learn: why adaptive governance matters now

Written by Riskology | 28/07/26 01:36

As artificial intelligence becomes more embedded in operational and strategic decision-making, governance can no longer be treated as a fixed framework reviewed at set intervals. Intelligent systems change over time. They learn, interact with new data, influence decisions in real time and can behave differently as context shifts. That means the governance surrounding them must also evolve.

In Governing systems that learn: Practical experiences in the adaptive risk management of intelligent systems, James Kavanagh makes a compelling case that static governance will not be enough in an AI-driven future.

His reflections on active governance, the gap between intent and systems, and the importance of seeing from both the “balcony” and the “dancefloor” point to a broader shift in how organisations need to think about oversight. Governance is no longer just about defining principles and documenting controls. It must be capable of responding to systems that change, influence decisions at speed and operate in environments where context can shift quickly.

Why static governance is falling behind

Traditional governance models are often designed for environments where change is comparatively slow. Policies are written, controls are defined, responsibilities are assigned and review cycles are scheduled. That structure remains important, but it is increasingly insufficient for systems that adapt, generate outputs at speed and operate across changing business and regulatory conditions.

Video: James Kavanagh on what Static Governance looks like at the RMIA Conference this year.

In this setting, governance cannot be limited to documenting intent. It must also account for how that intent is translated into models, workflows, decisions and outcomes. The gap between what an organisation says it wants and what a system actually does is where risk can quietly emerge.

For risk leaders, this creates a practical challenge. It is no longer enough to ask whether a governance framework exists. The more important question is whether governance is active enough to observe, interpret and respond as systems evolve.

The gap between intent and systems

One of the most valuable ideas in Kavanagh’s work is the focus on the distance between intent and implementation. Organisations may establish principles for fairness, accountability, transparency and oversight, but those principles only matter if they are reflected in system design, usage, monitoring and decision pathways.

This is where adaptive governance becomes essential. It is not governance with less structure. It is governance with stronger feedback loops.

Adaptive governance requires organisations to continually test whether stated objectives are still visible in operational reality. It means checking whether controls remain effective as systems are updated, whether escalation pathways are working, whether emerging behaviours are understood and whether decision-makers still have the context they need.

For organisations managing AI-related risk, this shifts governance from a periodic assurance activity to an ongoing discipline. It becomes a practical way to maintain alignment between policy, performance and accountability.

Seeing from the balcony and the dancefloor

Kavanagh’s use of the “balcony” and the “dancefloor” provides a useful way to think about modern governance.

The balcony is the strategic view. It is where leaders consider intent, risk appetite, regulatory obligations, ethical standards and long-term consequences. From the balcony, organisations can step back, recognise patterns and ask whether the system is moving in the right direction.

The dancefloor is where activity is actually happening. It is where intelligent systems are being used, decisions are being influenced, exceptions are surfacing and operational pressures shape behaviour in real time. From the dancefloor, governance becomes practical. It is tested by people, process, timing and context.

Strong governance needs both perspectives. Without the balcony, organisations risk reacting to issues without a clear framework or direction. Without the dancefloor, governance may look sound on paper while failing in practice.

Adaptive governance connects these two views. It ensures strategic intent is informed by operational reality and that operational decisions remain aligned with broader governance objectives.

What adaptive governance looks like in practice

For many organisations, adaptive governance will require a shift in mindset as much as a shift in process. It means moving beyond static control libraries and annual review cycles toward governance models that are more responsive, visible and data-driven.

In practice, that may include:

  • clearer ownership for AI-related risks across governance, technology, compliance and operational teams
  • real-time monitoring of system behaviour, exceptions and emerging risk indicators
  • defined review points when models, data inputs or decision thresholds change
  • stronger audit-ready records around why decisions were made, what actions were taken and how oversight was applied
  • escalation pathways that support timely intervention when system behaviour diverges from intent
  • regular feedback between leadership, risk teams and frontline users so governance remains grounded in lived operational conditions

This is where governance becomes more than a compliance exercise. It becomes part of how organisations build resilience, maintain trust and make better decisions under changing conditions.

Why this matters for risk leaders now

The relevance of adaptive governance extends well beyond AI specialists. Risk managers, governance leaders, compliance professionals and executives all have a role to play in shaping how intelligent systems are governed.

As AI becomes more present across operations, service delivery, safety, analysis and decision support, the consequences of weak governance become more material. Small misalignments can scale quickly. Unclear accountability can slow response. Limited visibility can make it harder to distinguish acceptable variation from emerging risk.

By contrast, organisations that adopt adaptive governance are better positioned to respond with confidence. They can identify drift earlier, connect decisions to evidence more clearly and maintain stronger oversight without losing agility.

This aligns closely with the direction of modern risk leadership. Risk management is no longer confined to retrospective reporting or isolated control activities. It is increasingly expected to inform decisions in real time, support resilience and help organisations respond to uncertainty with clarity.

Governance must evolve with the systems it guides

Kavanagh’s central insight is timely and practical. In a future shaped by intelligent systems, governance cannot remain static while the systems it oversees continue to learn, change and influence decisions at speed. It must evolve alongside them.

For organisations looking to strengthen governance in this environment, the priority is not to replace sound principles. It is to make those principles operational, observable and responsive in practice.

That is the real promise of adaptive governance: not governance that is lighter, but governance that is more effective, more connected to reality and better equipped for the pace of change ahead.

James Kavanagh of AI Career Pro brings more than 25 years of hands-on governance experience across process safety, cybersecurity, cloud infrastructure, and AI.

His leadership roles at Microsoft and Amazon Web Services included security assurance for government platforms, international regulatory oversight, and the creation of AWS’s Responsible AI Assurance function. That depth of experience gives real weight to his perspective on adaptive governance as a practical, evidence-based approach to building trust in intelligent systems.

Visit aicareer.pro/blog for more detail on the practice of adaptive AI governance.