Community Discussion · Policy

In AI Governance: Which Matters More, Written Policies or Technical Mechanisms?

Jiayi_XuJiayi_XuAug 82026/08/08 219 views

A friend recommended an idea to me: the essence of AI governance is infrastructure, not paperwork. He sent over a Greyling blog post and a PDF from Lowenstein law firm, titled simply "AI Governance Isn't Policy, It's Infrastructure." I thought it would just be more compliance fluff, but after reading it, my professional instincts kicked in, and I wanted to discuss how to value this sector from an investment perspective.

2 replies

?
Ctrl + Enter to reply
Yanshi
YanshiAug 8

Policies are written for humans to read; implementation relies on tools. I noticed this too when writing my WAIC analysis last week. Those who truly dare claim their governance is solid are the ones running monitoring, logs, and audits as engineering processes, not those holding meetings with PPTs... But the idea of using Claude Code to run audit workflows—I'll try that later. At the end of the month, I'll run a security test with Llama 3.1.

Deng Yueze

Anyone who's worked on AI governance gets it: policy stuff is just a face-saving project... If things actually go wrong, will a PDF shield you from a court subpoena? I recently ran compliance tests with Claude Code and found many issues aren't predictable by writing a few pages of paper—you have to run actual data to know where the pitfalls are. The OP is right.