The AI Control Gap
Why approving a model is not approving an action
AI no longer only produces text — it reads mailboxes, joins records across systems, prepares transactions and triggers actions, which makes a model's output a business event. Most organisations now control which model may be used. Far fewer can demonstrate, for one specific action, who authorised it, on whose behalf, under which mandate and policy version, and whether the thing approved is the thing that executed. This paper argues that access is not authority, and sets out what an executable control layer would have to do.
Covers- Shadow Execution: how the risk outgrew the Shadow AI framing
- Impact tiers and provenance assurance — the two control variables the other documents reuse
- What this architecture does not solve, stated before the case for it
- Where the EU AI Act, NIS2 and the BSI Act, DORA, the GDPR and the Cyber Resilience Act converge on the same technical objectives