← All writing Essay 10

What regulators expect, and why most organisations aren't ready.

Regulators are not asking whether you have an AI governance policy. They already expect you do. They are asking whether it is real, and whether the evidence of that reality can be produced on demand.

Rajesh Srinivasan 06 / 2026 11 min read governance · regulatory

Regulators are not asking whether you have an AI governance policy. They already expect you do. They are asking whether it is real, and whether the evidence of that reality can be produced on demand.

Across jurisdictions, the regulatory posture on AI has shifted from observation to expectation. The EU AI Act supervisory authorities, the Financial Conduct Authority, the Reserve Bank of India, the Monetary Authority of Singapore, and data protection authorities enforcing GDPR Article 22 automated decision obligations are all, in different ways, asking the same question: not whether governance exists on paper, but whether it operates in practice.

The organisations that are not ready are not the ones that ignored the regulation. Most have policies, governance frameworks, and risk registers that reference all the right obligations. They are not ready because they confused having a policy with having a practice, and regulators have begun to distinguish between the two in ways that a well-written policy document cannot satisfy.

Strip the regulatory text down and the question every supervisor is really asking is the same one: did a human navigate, or did the agent drive unattended? The five expectations below are just that question, made auditable.

What Regulators Expect and Why Most Organisations Aren't Ready. Five regulators: EU AI Act, FCA, RBI, MAS, GDPR Article 22. Four messages: Expectations are operational not documentary; Five expectations most organisations miss; The policy trap (Policy ≠ Evidence); Meeting expectations as byproduct of good practice. The gap: Policies written, governance on paper, evidence missing — vs regulators expecting evidence on demand, accountability you can name, oversight you can prove.
Essay 10 · Visual summary, what regulators expect and why most organisations aren't ready

Who is expecting what, and why it applies to you.

The regulatory landscape for AI governance is not uniform. Different regulators have different jurisdictions, different trigger conditions, and different enforcement powers. But the expectations that are emerging across all of them are consistent in one important way: they are operational expectations, not documentary ones.

EU AI Act · Supervisory Authorities. FCA · Financial Conduct Authority. RBI · Reserve Bank of India. MAS · Monetary Authority of Singapore. GDPR Article 22 · Data Protection Authorities.

The EU AI Act creates supervisory authority inspection powers for AI systems across the risk classification spectrum, with the most significant obligations falling on high-risk systems operating in employment, credit, essential services, and law enforcement contexts. Financial regulators, FCA in the UK, RBI in India, MAS in Singapore, have each published guidance or consultation papers that apply AI governance expectations to regulated firms, regardless of whether those firms consider themselves AI companies. GDPR Article 22 creates enforceable rights around automated decision-making that most organisations serving EU individuals must now operationalise.

If your organisation deploys AI that influences decisions affecting individuals, in any of these jurisdictions, these expectations apply. The question is not whether they are relevant. It is whether your organisation can meet them when asked.

"The consistent expectation across jurisdictions is not a governance policy. It is evidence that governance operates: named accountability, audit trails, human oversight records, risk classification with reasoning."

Five expectations most organisations are not meeting.

These five expectations are not advanced or aspirational. They are the baseline that regulators now treat as standard. The organisations that cannot meet them on demand are not underprepared, they are operating on the assumption that governance documentation satisfies governance expectations. It does not.

Expectation 01, A named human accountable for a specific AI decision.

Regulators do not ask who is responsible for AI governance in general. They ask who is accountable for the specific decision a specific AI system made on a specific date, and whether that person can answer questions about it without re-running the model.

Most organisations. "Our AI governance team owns all AI decisions. Our Chief Data Officer has oversight responsibility."

What regulators expect. A named individual who reviewed and approved this specific output, can explain the reasoning, and can demonstrate it without the AI system.

Named accountability is not organisational accountability. A governance team is not a named accountable individual. The regulatory expectation is that a specific person can be identified, questioned, and can produce the evidence of their review, for any material AI decision, on demand.

Expectation 02, A documented audit trail for that decision.

The audit trail expectation is specific: not a general log of system activity, but a traceable record of what input the AI received, what output it produced, who reviewed that output, and whether and how it was approved before being acted upon. This record must exist in real time, not reconstructed after a regulatory inquiry.

Most organisations. System logs exist. Outputs are stored. Approval processes are described in the governance policy.

What regulators expect. A traceable record: input → AI output → named reviewer → approval decision → action taken. Produced in real time, not retrospectively.

Reconstruction is not evidence. An audit trail produced after a regulatory inquiry, assembled from emails, Slack messages, and system logs by a team working backwards, is not the evidence regulators expect. It is a reconstruction. The expectation is a trail that exists because the governance process created it at the time of the decision.

Expectation 03, Evidence of human oversight in practice, not in policy.

This is the expectation where the largest gap exists between what organisations have and what regulators expect. Most organisations have a human oversight policy. It describes the oversight process, names the responsible functions, and is reviewed annually. Regulators are not asking to see the policy. They are asking to see evidence that the process described in the policy actually operated.

Policy. Describes governance, what oversight should happen and who should do it.

Evidence. Proves governance, records showing oversight happened, when, by whom, and what it found.

Policy is not equal to evidence.

The organisations that fail on this expectation are not the ones without human oversight processes. They are the ones whose processes operate informally, conversations rather than records, approvals without documentation, review that happens but leaves no evidence that it happened. Regulators cannot verify informal processes. They can only verify evidence of processes.

Expectation 04, Risk classification for each AI system with documented reasoning.

The EU AI Act, GDPR Article 22, and financial regulator AI guidance all require, in different ways, that organisations have assessed the risk posed by their AI systems and documented the reasoning behind that assessment. The classification is not the expectation. The documented reasoning is.

Most organisations. "This system is low risk." Risk level stated. Reasoning not documented. Classification not revisited when scope changed.

What regulators expect. Risk class stated, reasoning documented (use case, impact on individuals, data sensitivity, reversibility), classification revisited when scope or context changes materially.

Risk classification without reasoning is not classification, it is a label. Regulators examining an organisation's AI risk posture will ask not just what risk class was assigned but why, who made that determination, and whether it was reviewed when the AI system's use case or context changed.

Expectation 05, Post-deployment monitoring with defined thresholds.

Deploying an AI system and moving on is not sufficient under any current regulatory framework that addresses AI governance. The expectation, explicit in the EU AI Act for high-risk systems and implicit in financial regulator guidance, is that AI systems are monitored after deployment against defined performance thresholds, with a documented process for what happens when those thresholds are breached.

Most organisations. Infrastructure monitored. Uptime tracked. AI output quality not monitored. No defined thresholds. No documented response process for AI performance degradation.

What regulators expect. Defined performance metrics for AI output quality. Threshold at which review is triggered. Documented process for response. Evidence that monitoring has operated since deployment.

Most organisations that have deployed AI have excellent infrastructure monitoring. They do not have AI output quality monitoring. The two are not the same. A system with 99.9% uptime may be producing degraded AI outputs throughout that uptime, and without a monitoring process designed to detect output quality, the degradation is invisible until a client or regulator finds it first.


The policy trap, and how organisations fall into it.

The gap between what most organisations have and what regulators expect is not primarily a resource gap or a knowledge gap. It is a category error. Most organisations have approached AI governance the way they have approached every other governance requirement: write a policy that describes the right practice, review it annually, and satisfy the requirement.

This approach worked for many governance frameworks because the frameworks themselves were designed to be met through documentation. An auditor reviewing GDPR compliance looks at a data processing register, a privacy policy, and consent records. These are documents, and producing documents that describe the right practice was sufficient to meet the expectation.

Most organisations have. Policies written. Governance on paper. AI governance framework documents, risk registers, oversight policies. Evidence missing.

Regulators expect. Evidence on demand. Accountability you can name. Oversight you can prove. Monitoring you can demonstrate has operated.

AI governance expectations are different in a specific way: regulators are asking for evidence of practice, not documentation of policy. The question "show me human oversight" cannot be answered with "we have a policy that requires it." It requires evidence that the oversight happened, a record, a named reviewer, a dated approval, a monitoring log.

Most organisations that believe they are meeting regulatory AI governance expectations have documentation that describes the practices regulators want to see. They do not have evidence that those practices operate. The organisations that discover this distinction during a regulatory inquiry, rather than before one, pay significantly more for the discovery.

Meeting expectations as a byproduct of good practice.

The organisations that will meet regulatory AI governance expectations without significant additional preparation share a common characteristic: they built governance into how they operate AI, not how they document that they operate AI.

When a named human is required to approve every material AI output before it is acted upon, and that approval is recorded, the accountability and audit trail expectations are met as a natural product of the process. When AI systems are risk-classified at project initiation with documented reasoning, and that classification is updated when scope changes, the risk classification expectation is met without additional work at the point of regulatory inquiry. When AI output quality is monitored continuously against defined thresholds, the monitoring expectation is met as a function of how the system operates, not as a separate compliance exercise.

This is the argument of Essay 08 in this library restated in regulatory terms: compliance is the side effect of governance done properly. Organisations that build genuine governance, the Navigator Framework phase gates, the named attestation requirements, the quantitative controls, meet regulatory expectations because the evidence exists as a product of their practice. They do not prepare for regulatory scrutiny. They are simply operating in a way that makes the evidence available when it is requested.

The Navigator evidence pack. A Navigator Framework implementation produces, as a natural byproduct of the five phase gates, exactly the evidence regulators expect: named human approval at each gate (accountability), gate attestation records (audit trail), sampling probe logs (human oversight evidence), risk classification per project (documented reasoning), and Gate 5 monitoring requirements (post-deployment oversight). The framework was not designed to satisfy regulators. It was designed to close the human oversight gap. Regulatory readiness is what that closure produces.

Read next
The independence problem.
Essay 11 →
All writing