GovCompass

AI in control

AI in control

Operate and prove

By Michel Venniker· Last verified August 2026

Having AI controls is not the same as being in control. A control that exists on paper is a design claim. Being in control means the control operates, produces evidence, and someone reviews that evidence and acts on it. This section is the execution layer of AI governance: the place where design has to become evidence, and where organizations move from documented AI controls to demonstrable control that a supervisor, auditor, or board can rely on.

Most AI governance programs stop at design. Policies are written, roles are assigned, a risk assessment is filed, and the program is declared in place. Then an auditor, a supervisor, or a customer asks a different question: show me that it works. That question is where design effectiveness ends and operating effectiveness begins, and it is the question this section exists to answer.

The distinction runs through everything here. Design effectiveness asks whether a control, as designed, would address the risk if it operated as intended. Operating effectiveness asks whether it did operate, throughout the period, and whether you can prove it. The first is assessed once. The second is earned continuously, through monitoring results, control test outcomes, incident records, and the demonstrable follow-up on each.

A control loop holds the section together: design, implement, operate, verify, report, improve. Every article here lands somewhere on that loop. Risk management defines what needs controlling. Certification and conformity assessment are moments where an outsider checks your claim. The audit trail is how you prove the period in between. The loop is also what separates this section from the governance section: there you learn what good AI governance is, here you learn how to demonstrate that yours operates.

Start here

Agentic AI in control

Agentic AI raises the stakes for every control in this section: process knowledge may live in probabilistic layers, but controls must live in deterministic ones. The governance section explains the condition; this section holds the control side, three pieces that follow one sequence: how an agent knows your business process (the architecture), the agentic AI risk assessment (what can go wrong because of it), and the control environment for agentic AI (where the controls belong and how you prove they held).