Skip to content

The Great Convergence

Why Everyone Is Suddenly Talking About AI Governance

By Douglas P. Galullo

Something important is happening in artificial intelligence.

People who rarely read each other's work – security engineers, compliance officers, agent developers, model risk teams, auditors, operations leaders – have started describing the same underlying problem in different vocabularies.

Security teams talk about permissions. Auditors talk about traceability. Compliance officers talk about accountability. Developers talk about agent boundaries. Operations leaders talk about control.

Different disciplines. Different vocabularies. One underlying problem.

In the months since I wrote about AI's responsibility problem, I've watched this convergence take shape from inside an operational environment rather than a research lab. A security engineer worries about what happens when an autonomous agent keeps a permission it no longer needs. A compliance officer worries about whether a decision can be reconstructed eighteen months later, when a regulator asks for it. An agent developer worries about scope creep – a system built to draft a recommendation quietly acquiring the ability to act on it. A model risk team worries about explainability. An operations leader worries about whether anyone still knows who is accountable when three systems and two vendors have all touched the same piece of work.

These sound like five different conversations. They aren't. They are five people standing in different rooms of the same building, each describing the room they can see.

Why Now

It's worth asking why this convergence is happening now rather than five years ago, when AI was already reshaping customer service, fraud detection, and content generation. My best answer is that AI has crossed a threshold. It has moved from producing outputs someone reviews before anything happens to participating directly in the sequence of events that leads to something happening. A recommendation is different from an action. A drafted summary is different from a filed report. A suggested trade is different from an executed one. As AI systems move along that spectrum – into procurement decisions, underwriting judgments, code deployment, medical triage support, financial reconciliation – the old comfort of "a human will catch anything wrong" gets thinner every quarter.

Each discipline is responding to a piece of that shift. Data governance teams are trying to keep the inputs trustworthy. Security teams are trying to keep the permissions bounded. Compliance teams are trying to keep the paper trail intact. Agent developers are trying to keep the scope of autonomous action defined. Auditors are trying to keep the chain from mandate to outcome reconstructable. None of these groups set out to solve "AI governance" as a unified problem; each set out to solve the piece that sits inside its own job description. That's not a failure of vision. Narrow, well-funded, sellable solutions get built faster than sweeping ones, and in a fast-moving field, speed matters. The credit for the current wave of monitoring tools, permission frameworks, and compliance products belongs to the people solving those specific problems well.

But step back far enough to see all the rooms at once, and a single sentence describes what is happening in each of them: AI is becoming operational faster than the organizations deploying it are developing the systems required to govern it.

The Widening Gap

That gap between capability and control doesn't announce itself. It grows quietly, one convenient shortcut at a time, and the risks it creates share a common shape.

It shows first in authority. A system is granted permission to analyze a contract; within a few review cycles it is drafting the redlines; not long after, someone realizes no one ever formally decided it should also send them. The boundary wasn't violated in one dramatic step. It eroded through a series of individually reasonable extensions, none of which anyone would have approved if asked directly.

It shows next in evidence. A model's output begins as one input among several a person weighs before deciding. Under deadline pressure, it becomes the default answer, and the sources that would let someone check it – the original document, the specific data point, the reasoning chain – quietly stop being preserved. What remains is a conclusion, detached from anything that could support or challenge it. When the next decision builds on that conclusion, and the one after that builds on the second, small errors compound in a way no one can trace back to where they began.

It shows in the work itself. A piece of analysis now commonly passes through more than one AI system before a human sees it – one pulls data, another summarizes, a third drafts language from the summary. Each handoff is efficient. Together they can produce a result that no single person, and often no single log file, can fully explain after the fact. An activity log records that something happened. It rarely records whether it was authorized, whether the evidence behind it was sound, whether anyone challenged it, or who accepted responsibility for it.

And it shows in oversight, which has a way of becoming ceremonial when the volume of AI-assisted work outpaces the time available to review it. A name on an approval doesn't mean someone meaningfully evaluated what they approved – sometimes it means they clicked through a queue. Responsibility goes diffuse in the same way. When a recommendation comes from a model, trained by a vendor, deployed by an internal team, and acted on by an employee, "who is responsible if this is wrong" stops having an obvious answer. Everyone touched it. No one owns it.

None of this makes AI the villain. The danger isn't intelligence; it's powerful capability operating inside a responsibility structure that hasn't matured at the same pace. A sharp tool in a well-run shop is an asset. The same tool without guardrails, training, or accountability for its use is a liability, no matter how well it's made. That distinction matters, because it tells you where the fix has to happen: not in slowing the tool down, but in building the structure around it.

What Responsibility Infrastructure Has to Do

I don't think this gets solved with a policy document in a shared drive, a compliance checklist filled out after the work is finished, or a dashboard someone glances at once a week. Those things have their place, but they sit outside the work. What's needed has to live inside it – part of how the work actually gets done, not a report generated about it afterward.

That means starting before anything is produced. Every meaningful piece of AI-assisted work should begin with a clearly stated mission and a clearly identified human or institution granting the authority to pursue it. Capability and permission have to be treated as separate questions: that a system can do something is not the same as it being allowed to, and the systems performing the work should operate inside roles with defined boundaries rather than open-ended latitude.

From there, evidence has to survive the process rather than dissolve into it. Original sources need to be preserved in a form someone can return to. Claims need to stay visibly connected to whatever supports them, and known limitations or unresolved conflicts in the underlying information need to be recorded rather than smoothed over in the name of a clean answer. Somewhere in the process there has to be room for deliberate challenge – a point where a suggestion is actually tested rather than passed forward on momentum – and a clear line distinguishing a suggestion from a proposal, a proposal from a decision, and a decision from an authorized action. Consequential work needs a human approval that means something, and the dissent, exceptions, and changes along the way need to be preserved rather than quietly overwritten by the final version.

The result should be an unbroken chain from the original mandate to the final action – one that can be replayed, audited, reported on, and learned from. And all of it has to scale with consequence. A low-risk internal summary doesn't need the scrutiny of a decision that affects a customer's finances or a patient's care. Infrastructure that treats every task with maximum ceremony will be bypassed the moment it slows people down, which defeats the purpose. Done well, governance reduces friction instead of adding it: preserved context means less rework, clear authority means fewer stalled decisions, and a trustworthy record means review takes minutes instead of days.

How We Will Know

Success here isn't a better-looking output. It's the ability to answer a short set of questions, clearly and on demand, about any piece of consequential AI-assisted work:

Who authorized it? What was the AI actually permitted to do? Which systems participated, and in what order? What evidence supported the conclusion, and what were its known limits? Who challenged the recommendation, if anyone? What decision was made, and who approved it? Who accepted responsibility for the outcome? And months later, can the entire sequence – from mandate to action – be reconstructed by someone who wasn't in the room?

These are not rhetorical questions, and governability is not a branding claim. An organization that can answer them calmly and specifically has something worth calling governed. One that can only gesture at a general policy or point to an activity log does not – regardless of how sophisticated its models are.

Doghouse, One Attempt Among Many

I've spent more than thirty years in operational environments – seventeen in commercial printing and production work, where a missed step in a workflow shows up as a physical, costly mistake rather than an abstraction; eight as a police officer, where evidence, conflicting accounts, and who is authorized to do what are not academic questions but the difference between a case that holds up and one that doesn't. That background is why I notice process, authority, and evidence before I notice anything else, and it's the lens through which I've been studying how AI-assisted work actually breaks down in practice – and what holds it together when it doesn't.

Out of that study, my company, Dog House Ventures, has been building Doghouse: an experimental governed operating environment designed to test whether the responsibility infrastructure described above can be embedded directly into AI-assisted work rather than bolted on afterward. The approach follows a simple sequence – mission, evidence, AI work, challenge, human decision, authorized action, audit, learning – with each stage producing a record that feeds the next.

I want to be direct about what this is and isn't. Doghouse has not solved AI accountability, and it may not be the final form this kind of infrastructure takes. It is one working attempt, still being tested, to make AI-assisted processes visible, governable, traceable, and defensible after the fact. Most governance frameworks describe the controls an organization should have. What we're exploring is whether those controls can become part of the live process through which work is assigned, reviewed, approved, executed, preserved, and audited – not a report about the work, but the work itself, structured so it can answer the questions above.

I'm not certain integration is the right bet. It may be harder to explain to a buyer than a single-purpose tool with a clear pitch. It may try to cover too much ground and lose the sharpness that makes narrower products easy to adopt. It still has to prove that organizations actually want a connected operational layer rather than a collection of best-in-class specialist tools stitched together on their own terms. Those are open questions, and I'd rather say so plainly than pretend otherwise.

Where This Goes

The race to build more capable AI will continue. It should. Human progress has always depended on better tools. But every major technological leap eventually required new operating principles, new institutions, and new forms of accountability.

AI will be no different.

The question is not whether AI becomes more capable.

The question is whether our responsibility infrastructure can mature quickly enough to govern that capability.

At Dog House Ventures, that is the question we are trying to answer.

Douglas P. Galullo is the founder of Dog House Ventures and has more than 30 years of experience across operations, law enforcement, business ownership, and production systems.