AI Governance

Addressing AI Trust by Moving from the Frontier to the Ecosystem

Reflections on One Year at Credo AI

August 6, 2026
Author(s)
No items found.
Contributor(s)
No items found.

There is a Japanese art form called kintsugi, the practice of repairing broken pottery with gold. Rather than hiding the fractures, it makes them part of the object's history. But the gold is not a patch on a crack. It is the seam that holds one piece to another, and the vessel only holds water if every seam does its job in relation to the others.

Looking back on my first year at Credo AI, I keep returning to that image, usually because of how differently we tend to approach AI governance. We treat each new risk as an isolated crack to repair. Bias. Privacy. Security. Frontier capabilities. Agentic behavior. Each gets its own framework, its own working group, its own control.

What kind of trust could we build if we looked at the whole vessel instead, addressing each of these at the foundation, and in cohesion with one another? In my time as Global Policy Director, working with customers, policymakers, standards organizations, and engineers around the world, I've become convinced that this is the harder and more important challenge: not the individual fractures, but the structure that holds the entire system together.

A Quick  Look Back

Over our history as a company, Credo AI’s Policy team has always served a unique function as a bridge and translator. In many organizations, policy teams primarily monitor legislation, engage with policymakers, and advocate for sensible, regulatory outcomes. Those responsibilities remain essential, and they continue to be an important part of our work to build trust across the enterprise and public sector entities. But from its earliest days, Credo AI approached policy with a different objective: not simply understanding what regulations require, but translating what regulators are trying to accomplish into governance that organizations can operationalize. That distinction has reshaped how I think about policy itself.

Every regulation, standard, and framework ultimately reflects a broader objective: improving safety, strengthening accountability, increasing transparency, enabling human oversight, or reducing risk. The challenge is that legal obligations alone do not tell organizations how to operationalize those objectives across increasingly complex AI systems. They must be interpreted, validated, and translated into measurable governance practices.

Over the past year, I've come to appreciate that this translation layer is one of the most important, and least visible, challenges in AI governance. It is where principles become controls, standards become evidence requirements, documentation becomes structured governance artifacts, and increasingly, where policy intent can be interpreted as procedural obligations, programmatic governance, or runtime controls for AI systems.

That experience has also reinforced another lesson: trust cannot simply be asserted. It must be demonstrated. Meaningful governance depends on the ability to produce evidence that systems are behaving as intended, which in turn depends on measurement, shared methodologies, credible standards, and institutions capable of maintaining them. Without those foundations, even the most thoughtfully written policies remain difficult to implement consistently.

In many ways, this has become the question I return to most often. Not what does the regulation say? But how do we faithfully operationalize its intent in a way that is measurable, repeatable, and adaptable as AI continues to evolve?

With those questions in mind, here are three observations that have reshaped how I think about AI governance over the past year.

The Questions Have Matured

When I first joined Credo AI, many conversations centered on legislation. Organizations wanted to understand the EU AI Act, emerging state laws, executive orders, and standards. Today, the questions are more insightful and practical.

How should sector-specific obligations interact with horizontal AI regulation?

When should I determine an AI system is high risk because of the environment in which it is deployed versus the infrastructure, data, and access permissions it sits on (agents!)?

How will the obligations that supposedly fall on developers of the largest frontier models impact my work building systems on top of these models? What’s the real impact to my business for each of these marginal decisions?

These are no longer simply compliance questions.

They are architectural questions.

Increasingly, enterprises are not governing individual models. They are governing interconnected systems composed of foundation models, retrieval mechanisms, memory, identity services, harnesses, APIs, external tools, human reviewers, organizational policies, and increasingly autonomous agents.

The unit of governance is the AI system. The ultimate objective of policy is enabling the AI trust ecosystem.

Some of the Most Important Innovation Is Happening Outside Frontier AI Policy

One of the biggest surprises of this year has been discovering where some of the most meaningful innovation in AI governance is actually happening.

It is easy to assume that the future of AI governance will be determined primarily by AI-specific legislation or debates over frontier models. Those conversations are important, but many of the most practical advances are emerging elsewhere. Increasingly, I have found myself learning as much from healthcare regulators, insurance commissioners, financial supervisors, and other sector-specific governance communities as from AI policy itself.

That should not surprise us.

These institutions have spent decades governing complex, high-consequence systems where risk cannot be eliminated but must be continuously measured, managed, and documented. They understand evidence. They understand assurance. They understand accountability. Rather than asking abstract questions about whether AI should be regulated, they ask operational questions: What evidence is sufficient? Who owns responsibility? How should oversight evolve as systems change? What constitutes acceptable residual risk?

In many ways, these communities are already developing the governance patterns that AI will require. They recognize that risk is contextual, that accountability rarely resides with a single actor, and that effective oversight depends as much on implementation as on regulation. Their work reflects a broader shift away from governing AI as a standalone technology and toward governing AI as it exists within real-world systems.

That evolution has made me increasingly optimistic. Some of the most durable governance frameworks for AI may not come from creating entirely new institutions, but from adapting the expertise, supervisory models, and risk management disciplines that already exist in sectors where trust has always mattered most.

Policy-as-Code

One of the ideas I've found myself returning to most often this year is deceptively simple. Policy should not end when it is published. Historically, policy compliance has been treated as a static artifact. Legislatures pass laws. Regulators issue guidance. Organizations write internal policies. Compliance teams review documentation. Governance largely happens through periodic assessments against those artifacts.

That model is now increasingly insufficient for AI systems that reason, orchestrate other systems, invoke tools, adapt to context, and, in the case of agents, act with varying degrees of autonomy.

If AI governance is moving from governing models to governing systems, then policy itself must evolve alongside those systems. That means treating policy less as a document and more as an operational capability.

One of the most interesting questions we've wrestled with at Credo AI is not simply what a regulation requires, but what the regulator intended to accomplish. Those are often different questions. A regulation may require human oversight, accountability, documentation, or transparency, but implementing those objectives requires interpretation before implementation. That translation increasingly becomes the work of governance. Some regulatory intent is best operationalized through procedural controls: organizational policies, approval processes, escalation paths, or human review. Other requirements become programmatic controls embedded into governance workflows. Increasingly, some can become interpretable runtime controls that continuously guide how AI systems behave while they are operating.

This is what we increasingly mean when we talk about governance as code. Not replacing policy with software, but rather operationalizing policy intent in ways that are measurable, adaptive, and continuously enforceable.

Watching capabilities like Agent Governor emerge has reinforced my belief that this is where the field is heading. The interesting innovation is not simply that an AI system can monitor another AI system. It is that governance systems can begin interpreting regulatory intent, validating that interpretation against operational context, and applying the appropriate procedural, programmatic, or runtime controls as AI systems evolve.

That shift represents a broader transition from static compliance toward living governance, and I suspect it will become one of the defining characteristics of the next generation of AI policy.

Looking Ahead

Looking back on this year, I no longer believe the defining question of AI governance is whether we can write sufficiently comprehensive rules. Over the past year, we have seen thoughtful proposals from Congress and state legislatures on AI oversight, benchmarking, incident reporting, and governance.

The question now is whether we can build the institutions capable of interpreting, measuring, implementing, and continuously improving those rules as technology evolves.

That also requires broadening who informs them.

Over the past year, AI policy debates have naturally centered on a relatively small group of actors. Yet, the AI trust ecosystem is far broader. It includes enterprises deploying AI in high-consequence environments; healthcare, insurance, and financial regulators with decades of experience governing risk; standards organizations advancing measurement science; researchers developing assurance methodologies; state and local governments implementing policy; and the practitioners responsible for operationalizing governance every day.

If Washington wants to build durable AI governance, it must draw on the expertise of that entire ecosystem, not just the organizations developing the largest models. The future of AI leadership will be determined not only by who builds the most capable AI systems, but by whether we can build institutions and governance frameworks that earn trust across the broader ecosystem in which those systems are designed, deployed, and governed.

Policy-as-code will help operationalize regulatory intent. But it is institutions, standards, enterprises, regulators, researchers, and practitioners working together that make trust durable. If my first year at Credo AI has taught me anything, it is that the future of AI leadership will belong to the ecosystems that strengthen the connections between those pieces, because trust that endures starts at the foundation, not built by repairing individual cracks alone.

DISCLAIMER. The information we provide here is for informational purposes only and is not intended in any way to represent legal advice or a legal opinion that you can rely on. It is your sole responsibility to consult an attorney to resolve any legal issues related to this information.