{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Civic Tech Chat","title":"AI Governance: Who's Accountable When the Machine Decides?","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/be79d734\"></iframe>","width":"100%","height":180,"duration":1450,"description":"AI tools have quietly moved out of isolated dev environments and into the middle of how real work gets done. That shift is genuinely exciting, and it brings a fresh set of risks worth sitting with. In this solo episode, Ryan works through what it takes to govern AI well, all of it anchored on one idea he keeps coming back to: a human has to stay accountable for the decisions that matter. He gets into why AI strains the governance habits IT already leans on, how to weigh centralized, decentralized, and hybrid approaches against your own risk tolerance, what ISO 42001 and the NIST AI RMF actually ask of you, and where the law is heading. He closes with a practical playbook for pulling shadow AI into the open while keeping the room for creativity that made folks reach for these tools in the first place.\nIn this episodeWhy AI puts pressure on the governance habits IT already has, from non-determinism to data drift and concept drift, and the blind spots those quietly createSplitting your governance model (who holds the decision rights) from your operating model (how the work actually gets run)The three big archetypes: the fortress-style centralized model, the fast and messy decentralized model, and the hybrid in between, plus how to match one to your risk tolerance and threat modelA few examples from Ryan's own teams — engineers getting their bearings in old repos in about twenty minutes instead of a full day, designers prototyping fast enough to have a richer discovery conversationWhat ISO 42001 and the NIST AI Risk Management Framework actually require, including named human owners and a real kill switchThe principle the whole episode hangs on: an AI tool can't be the one held accountable, since a machine isn't a legal or moral agentWhere regulation is going, including EU GDPR Article 22, California's coming CCPA automated-decision rules, EU NIS2, and a White House executive order on AI and national securityThe frontier-developer laws worth knowing about even if...","thumbnail_url":"https://img.transistorcdn.com/wf_lJPgK0tAZyd_v9MM4M5qxoeBjMpgnK_rf7CJfEqI/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9kZTVi/NDY3OWQ2NTk4NzVl/ZjI3OTY3ZTExODRi/NzE3MC5qcGc.webp","thumbnail_width":300,"thumbnail_height":300}