✒️ Foreword
There is something deeply uncomfortable about governing systems we do not fully understand.
For decades, risk management has been built around a fairly intuitive assumption: if something matters enough, someone should be able to explain how it works. We validate the model, inspect the process, assign responsibility, document the controls, and move on.
AI complicates that logic.
Increasingly, we are dealing with systems where the internal reasoning may be opaque, the outputs probabilistic, the behaviour capable of changing over time, and the underlying technology partly controlled by someone outside the organisation.
And yet the business still needs an answer.
So perhaps the governance question is shifting.
Instead of asking only, “Can we explain exactly why the system produced this result?”, we increasingly need to ask: “Can we demonstrate that the system behaves within acceptable boundaries?”
That means testing rather than assuming. Monitoring rather than periodically certifying. Designing contractual protections around things we cannot directly control. Building fallback mechanisms, escalation paths, audit trails and clear limits on autonomy.
In other words, uncertainty itself becomes something that has to be governed.
This does not mean explainability stops mattering. Quite the opposite. But we may need to accept that perfect understanding will often remain out of reach, while accountability cannot.
The organisations that manage AI well will not necessarily be those that understand every mechanism inside the machine.
They will be the ones that know what happens when the machine surprises them.
— Kuba
Curator, AIGL 📚
☀️Spotlight Resources
Contracting With AI Vendors: What Lawyers Should Negotiate Differently

What it is: Colin S. Levy’s 2026 practical guide for lawyers negotiating agreements with AI vendors, covering data use, liability, IP, performance standards, privacy, termination, regulation, and insurance.
Why it’s worth reading: The guide’s core argument is that AI contracts should not be treated like ordinary SaaS agreements. It walks through AI-specific risks such as vendors training on customer data, unclear ownership of generated outputs, model drift, hallucinations, discriminatory outputs, and dependence on subprocessors. Particularly useful are the side-by-side redlining examples showing typical vendor language alongside stronger customer protections—for example, prohibiting training on prompts and outputs, requiring advance notice of model changes, expanding indemnification, and ensuring deletion of embeddings and fine-tuned models after termination. It also includes practical negotiation tactics, fallback positions, and a quick-reference checklist for reviewing agreements.
Best for: In-house counsel, privacy teams, procurement professionals, legal operations teams, and lawyers reviewing or negotiating enterprise AI contracts.
AI Security Audit Checklist

What it is: Dr. Nath Alagbe’s AI Security Audit Checklist is a structured reference for IT auditors and AI security professionals, organizing AI security controls across ten domains and mapping them to frameworks including ISO/IEC 42001, NIST AI RMF, ISO/IEC 27002, OWASP guidance, SOC 2, GDPR, and NIST publications.
Why it’s worth reading: The useful part is its audit-ready format. Each control pairs an audit question with a validation method, the evidence an auditor should request, and the relevant standards or frameworks. The checklist covers much more than model security: governance, AI-specific risk assessments, training-data provenance, adversarial testing, access controls, MLOps pipelines, monitoring, incident response, third-party models, and regulatory mapping are all included. It is particularly practical if you need to turn broad AI governance requirements into concrete evidence requests and testable controls. AI Security Audit Checklist.pdfPDF
Best for: Internal auditors, security teams, AI governance leads, risk professionals, and organizations building an AI assurance or audit program.
Model Risk Management in the age of AI

What it is: A 2026 Moody’s white paper by Nils Grevenbrock, Zhengpu Zhao, and Nihil Patel examining how Model Risk Management (MRM) needs to change as financial institutions adopt machine learning, generative AI, and agentic systems.
Why it’s worth reading: The paper’s central argument is that traditional, periodic model validation is no longer enough for AI systems that are opaque, stochastic, dependent on external vendors, and potentially autonomous. Its comparison of three model generations—traditional models, machine learning, and AI systems—shows how increasing capability comes with decreasing transparency, determinism, and control. The authors propose continuous monitoring, behavioral testing, dynamic guardrails, human-in-the-loop oversight, version control, fallback models, and explicit escalation mechanisms. A Moody’s Early Warning System case study shows how these controls can work in practice across a pipeline combining LLMs, clustering algorithms, and conventional credit-risk models.
Best for: Model risk, AI governance, financial-services risk, validation, and compliance teams adapting existing MRM frameworks to GenAI and agentic systems.

The Mathematician Who Skipped The Explanation
Srinivasa Ramanujan filled notebooks with thousands of mathematical results, usually without showing how he got there.
Decades later, mathematicians spent careers reconstructing the missing proofs — and discovered that remarkably few of his results were actually wrong.
There’s an uncomfortable parallel with modern AI: we can observe the answer, test that it works, and still struggle to explain exactly what happened inside the machinery that produced it.
Ramanujan, of course, had one major advantage over a neural network.
When asked to explain himself, at least he was occasionally available for questions.