Skip to content
NakodaAI

The Dubai skyline at dusk from across the water, Burj Khalifa at its centre, the sky still orange behind it.

Sergei Gussev · CC BY 2.0

AI doesn't faillike software.It fails like a decision.

The governance layer for AI across your enterprise.

Visibility · Authority · Monitoring · Evidence

The decision was approved. The source wasn't verified.

A printed contract on a desk with a fountain pen resting across the signature lines.

Decision

The decision was approved.The source wasn't verified.

An AI system generated the recommendation. A human approved it. The source was never independently verified.

  1. AI OUTPUTFluent, confident, well-formatted.
  2. HUMAN REVIEWApproved in seconds.
  3. BUSINESS DECISIONApplied to a real person.
  4. ACCOUNTABILITYUnassigned.

Who owns the decision?

Customer data. Access granted.

Server racks in a data centre, drive bays lit blue and green.

Access

Customer data.Access granted.

Which AI systems can reach it, through which identity, with what authority, and under whose approval?

  1. DATAGiven for one stated purpose.
  2. IDENTITYWhat the system authenticates as.
  3. PERMISSIONGranted once. Reviewed when?
  4. AI SYSTEMModel, retrieval and tools.
  5. BUSINESS ACTIONWhat it can then do in the world.

Access is a governance question too.

Five roles. One shutdown key.

A trapped-key interlock on a steel switchgear door: a row of brass locks, one key in place with a tag hanging from it.

Accountability

Five roles.One shutdown key.

When an AI system acts autonomously, who can stop it?

  1. BUSINESS OWNER
  2. MODEL OWNER
  3. SYSTEM OWNER
  4. RISK OWNER
  5. INCIDENT COMMANDER
  6. KILL-SWITCH OWNER: UNRESOLVEDNo named holder. No credential. No tested path.

The model didn't crash. The world changed.

Sand dunes in the Rub' al Khali at low sun, the ridge line curving away into shadow.

Drift

The model didn't crash.The world changed.

The model may continue to run. The environment may not.

  1. APPROVEDAgainst the world as it was that day.
  2. DEPLOYEDInto one that does not hold still.
  3. ENVIRONMENT CHANGESInputs, users, conditions, expectations.
  4. MODEL STILL RUNSNothing has failed. Nothing has fired.
  5. RISK HAS CHANGEDIt is no longer the system that was approved.
  6. REASSESSOn a cycle, or never.

AI governance must continue after deployment.

You cannot govern what you cannot see.

A wall of diagnostic monitors in a control room, every screen showing a different reading.

Observability

You cannot governwhat you cannot see.

Monitoring tells you a system is running. Governance tells you whether it should be.

  1. DRIFT DETECTEDThe decision boundary has moved.
  2. OWNER UNASSIGNEDIn production, with no accountable role.
  3. SOURCE UNVERIFIEDRetrieval reaching an index nobody owns.
  4. ACCESS EXCEEDEDAn identity operating outside its approved scope.
  5. REVIEW OVERDUEA reassessment that has passed its date.

A status, not a score.

Your AI estate is larger than your AI inventory

An archive aisle. Shelves of identical document boxes run down both sides towards a lit doorway at the far end.

Where else does it exist?

One record. Deleted at source. Still resident in every system that ever copied it.

  • CRM
  • ERP
  • API
  • SAAS
  • AGENT
  • MODEL

Your AI estateis larger thanyour AI inventory.

  • BUILD
  • BUY
  • EMBED
  • USE
  • ENTERPRISE AI ESTATE
GOVERNANCE SYSTEM

The AI estate

The inventory is not the beginning.

It is the evidence that governance has begun.

AI gets built, bought, embedded and used. Mapping all four is where the work starts.

  • BUILD

    Developed in-house.

  • BUY

    Procured from a vendor.

  • EMBED

    Already inside your ERP, CRM and SaaS.

  • USE

    Staff tools, approved or not.

Governance of AI - we govern what AI can do

Governance of AI

We govern what AI can do.

Rules, owners, limits and proof. For every system, built or bought.

  1. GOVERN

    01

    • Policy
    • Risk
    • Authority
    • Oversight

    What is allowed, and who decides.

  2. OPERATE

    02

    • Discover
    • Assess
    • Approve
    • Monitor

    Found, approved by name, watched after launch.

  3. ASSURE

    03

    • Evidence
    • Incidents
    • Audit
    • Reassessment

    Proof a board or regulator can rely on.

Operate, across the lifecycle

  1. DISCOVER

  2. CLASSIFY

  3. ASSESS

  4. APPROVE

  5. CONTROL

  6. MONITOR

  7. ASSURE

  8. RETIRE

What is governed - the eight objects
  • AI SYSTEMS

    Where AI exists and what it does.

    The system record: purpose, owner, autonomy class, the decisions it influences, the systems it touches, its approval and its review date. A system in production that appears in no record is the first governance failure, and every other one follows from it.

  • MODELS

    What powers the system and how it changes.

    Registry entry, provenance, validation, version pinning and drift thresholds. A model version that moves underneath a live system moves the decision boundary with it, whether or not anyone approved the change.

  • AGENTS

    What can act autonomously, and with what authority.

    Identity, permission register, tool scope, transaction limits, approval thresholds and full tool-call telemetry. The moment a system can act rather than answer, its permissions become its risk surface.

  • DATA

    What information AI can access, process or generate.

    Classification, lawful basis, lineage, retention and a demonstrated deletion path - through the embedding pipeline and the vector store, not only through the warehouse. Personal data inside an AI system is still personal data.

  • VENDORS

    Who provides the technology, and where the dependency sits.

    Foundation model providers, SaaS with AI embedded, cloud services, outsourced development. Governance needs vendor, model, data, change and exit controls - including the right to be told when the model underneath you is replaced.

  • USERS

    Who uses AI, and under what conditions.

    Acceptable use, the boundary between assistance and delegation, training on where oversight is genuinely required, and a route by which someone can raise a concern about an output without it costing them anything.

  • DECISIONS

    What organisational outcomes AI can influence.

    The decision record: outcome, reason given, model version, retrieved context, reviewer. A decision that cannot be reconstructed cannot be defended, corrected or appealed.

  • CONTROLS

    How the organisation constrains, monitors and assures all of it.

    Control descriptions, test results, exceptions with expiry dates, and the evidence each control produces. A control described in a document and implemented nowhere is a claim, not a control.

A safe model is not a safe system.

Model risk and system risk are different objects. A model may be well-validated, appropriately scoped and entirely acceptable on its own. The AI system assembled around it may still be dangerous.

  • LLM
  • RAG
  • HR DATABASE
  • EMPLOYEE RECORDS
  • EMAIL
  • ERP API
  • = A HIGH-RISK AI SYSTEM
How risk is classified, and how much authority a system holds

Risk is not a property of the technology.

Classifying by technology type - "generative AI is high risk" - produces a register that is simultaneously too cautious and too permissive. Risk is a function of what a system decides, for whom, at what scale, and how easily the outcome can be undone.

  • IMPACT ON PEOPLE
  • DECISION AUTHORITY
  • AUTONOMY
  • DATA SENSITIVITY
  • SCALE
  • REVERSIBILITY
  • EXTERNAL EXPOSURE
  • REGULATORY EXPOSURE
  • SAFETY IMPACT
  • SECURITY IMPACT
  • FINANCIAL IMPACT
  • MODEL UNCERTAINTY
  • THIRD-PARTY DEPENDENCY

Every AI system has a maximum authority. Most organisations have never written theirs down.

  1. P0OBSERVECan read and interpret. Produces no recommendation and takes no action.
  2. P1RECOMMENDCan propose. Cannot prepare or execute anything.
  3. P2PREPARECan assemble an action for a human to review and issue.
  4. P3EXECUTE WITH APPROVALCan act, but only after an authorised human approves the specific action.
  5. P4BOUNDED AUTONOMYCan act unsupervised inside explicit, monitored and reversible limits.
  6. P5CONSEQUENTIAL AUTONOMYCan act unsupervised where consequences are material or irreversible. Exceptional, and heavily restricted.

An illustrative authority ladder. The levels are a governance instrument, not a product specification.

"Human in the loop" describes a seating plan, not a control.

A reviewer approving the nine hundredth confident recommendation of the week is not reviewing. Oversight is a control only where the human has the authority, the information and the time to reach a different answer - and where the arrangement is matched to how much the system has been permitted to decide.

  • AI PROVIDES INFORMATION → HUMAN DECIDES

    The system informs. The decision was never delegated.

  • AI RECOMMENDS → HUMAN REVIEWS → HUMAN DECIDES

    Review is only real where the reviewer has the time, information and standing to disagree.

  • AI DECIDES → HUMAN CAN INTERVENE

    Intervention requires detection, authority and a path that has been tested.

  • AI ACTS AUTONOMOUSLY → WITHIN BOUNDED AUTHORITY

    Limits, monitoring and reversibility carry the oversight the human presence no longer can.

Regulatory exposure - United Arab Emirates
  • UAE PDPL

    Federal law

    Personal data inside an AI system is still personal data. Embedding it, indexing it or fine-tuning on it does not change its status - it changes how hard it is to find.

    Can you trace one person's data backward through the machine?

  • Dubai AI Seal

    Certification programme

    Certification behaves as an access gate. Where a Dubai government entity requires a seal-holding supplier, governance stops being a values statement and becomes a commercial prerequisite.

    Could you evidence your governance to an external assessor this quarter?

  • DIFC Regulation 10

    Regulation

    Autonomy is treated as a governed property of the system. The more independently a system acts, the more explicit the human authority over it has to be.

    Who, by name, can take the system offline tonight?

  • ISO/IEC 42001

    Management standard

    A management-system standard: structure, roles, cycle and improvement. It is adopted as a cycle or it is pursued as an artefact, and the two produce very different organisations.

    Does your governance run on a cycle, or on a document?

Reviewed August 2026. Plain-language descriptions of publicly stated obligations and programme criteria, current as at the review date. Law, regulation and certification criteria change. Nothing here is legal advice, and scope depends on the entity, the jurisdiction and the specific system.

AI for governance - we use AI to make governance better

AI for governance

We use AI to make governance better.

Reviews, control mapping and evidence gathering are repetitive work. AI does them continuously.

The path a governance decision takes

  1. 01

    REGULATION

    Tracked as it changes.

  2. 02

    ANALYSIS

    At a scale no team sustains by hand.

  3. 03

    POLICY

    Checked against what applies.

  4. 04

    CONTROL

    Mapped, with the gaps named.

  5. 05

    EVIDENCE

    Gathered continuously.

  6. 06

    HUMAN DECISION

    A person decides, and answers for it.

AI supports the decision. A named person still makes it.

The AI we use is governed too.

It sits in the same inventory, with an owner and a review date.

Who can stop the machine? Agentic AI authority and intervention.

A red emergency stop button on a steel machine panel, the words EMERGENCY STOP engraved above it.

Flygklubben · CC BY-SA 4.0

Agentic AI

Who can stop the machine?

When AI acts instead of advising, someone has to be able to stop it.

What an agent runs through

  1. AI AGENT
  2. MODEL
  3. TOOL
  4. API
  5. ENTERPRISE SYSTEM
  6. BUSINESS ACTION

What has to be governed

  • IDENTITY

    Its own. Never a shared login.

  • PERMISSION

    Least privilege, reviewed regularly.

  • AUTHORITY

    Hard limits on what it may decide.

  • APPROVAL

    A person signs off above a threshold.

  • INTERVENTION

    One named holder. One tested path.

  • EVIDENCE

    Every action logged and kept.

  • STOP SYSTEM
  • ESCALATE
  • PRESERVE EVIDENCE

Each needs a named holder and a tested path, before an incident.

AI governance is not a document. It is a control plane.

Control plane

AI governanceis not a document.It is a control plane.

A policy states intent. A control plane applies it to every system, all the time.

  1. 01

    INVENTORY

    What exists.

  2. 02

    RISK

    What each system requires.

  3. 03

    ACCESS

    Who reaches which data.

  4. 04

    APPROVAL

    Who authorised it.

  5. 05

    MONITORING

    Governance state, not uptime.

  6. 06

    INCIDENT

    Detected through to closed.

  7. 07

    AUDIT

    The trail to reconstruct it.

How the operating model is structured

Governance fails as often from being too central as from being absent. The function that sets the rules must not be the function that builds and operates every system, or its challenge is worthless and its capacity is the bottleneck for the whole estate.

  • AI GOVERNANCE

    Policy · Standards · Risk requirements · Challenge · Approval · Oversight · Assurance

  • BUSINESS & TECHNOLOGY

    Build · Deploy · Operate · Change · Business outcome · Day-to-day decisions

  • INTERNAL AUDIT

    Independent assurance · Control testing · Reporting to the board

  1. BOARD

    Accepts, on the organisation's behalf, the risk that AI decisions carry.

  2. AI GOVERNANCE COMMITTEE

    Translates appetite into standing decisions, thresholds, mandates and approvals.

  3. AI GOVERNANCE FUNCTION

    Policy, standards, risk requirements, challenge, approval, oversight and assurance.

  4. BUSINESS · TECHNOLOGY · RISK · LEGAL · SECURITY · PRIVACY · DATA

    Build, deploy, operate, and remain accountable for the business outcome.

  5. AI SYSTEMS

    Where every layer above either becomes real or stops being true.

INTERNAL AUDIT → INDEPENDENT ASSURANCE

Reports independently of both governance and delivery. Assurance that runs through the people who designed the controls is not assurance.

Trust is not a claim. It is evidence.

Assurance

Trust is not a claim.It is evidence.

Every stage leaves a record. That is the difference between proving it and claiming it.

What the system leaves behind

  • AI INVENTORY
  • RISK ASSESSMENT
  • IMPACT ASSESSMENT
  • OWNER ASSIGNMENT
  • APPROVAL
  • TEST RESULTS
  • MONITORING
  • INCIDENT HISTORY
  • EXCEPTIONS
  • AUDIT TRAIL

Can you prove:

  1. 01WHAT EXISTS?
  2. 02WHO CONTROLS IT?
  3. 03WHY WAS IT APPROVED?
  4. 04WHAT HAPPENED?

Where to start

Engagement

Where to start

A gap assessment against UAE rules and the Dubai AI Seal. Three to four weeks. It ends in a list you can act on.

All nine engagements, in full

DESIGN

AI Governance Framework Design
The operating model: who decides, who is accountable, who holds the authority to stop a system, how systems are reviewed after deployment, and how governance itself is revised. Built around existing governance structures rather than imposed beside them. Delivered as the framework, a RACI for AI decisions, and an implementation plan.

DISCOVER

AI Estate Discovery & Inventory
Discovery across build, buy, embed and use - including AI already inside procured software and AI in use without approval. Produces the inventory, the vendor and dependency register, risk classification for what is found, and the ownership assignments that make the rest of the framework operable.

OPERATE

AI Risk Assessment & Classification
A risk model that reflects impact, authority, autonomy, data sensitivity, reversibility and regulatory exposure rather than technology type. Produces the classification scheme, the register mapped to controls with owners and review dates, and the monitoring arrangement that keeps it current.
Agentic AI Authority & Control Design
Identity, permission registers, tool scope, transaction limits, approval thresholds, intervention paths and telemetry for systems that act rather than answer - including the authority ladder that says how much each system is permitted to decide, and the named holder of every stop.
Data Governance & Lineage for AI
Classification, ownership, quality, lawful basis, retention and the traceable path from source record to decision - through the embedding pipeline and the vector store, not only through the warehouse. Where AI is already running without governance, the work starts with a lineage audit.

ASSURE

AI Incident Response & Tabletop Exercises
What constitutes a reportable AI incident, the escalation path from detection to closure, the severity matrix, the rota with names and standing authority, and the documentation the incident has to leave behind. Tested through a tabletop exercise before it is finalised, because an untested plan is an assumption.
Dubai AI Seal Readiness & Application Support
Assessment against the evaluation criteria for a target tier, the gap list that would prevent certification today, the work required to close it, and management of the submission itself. Organisations new to the programme begin with a readiness assessment.
UAE AI Regulatory Compliance Advisory
The obligations relevant to the entity and the systems it runs - PDPL, DIFC data protection, the UAE Cybersecurity Law, the National AI Strategy's principles, and the EU AI Act where international operations bring it into scope - mapped against current practice, with the gap analysis and remediation plan to bring the two into line.
AI Control Testing & Independent Assurance
Control descriptions turned into tested controls, with results, exceptions and expiry dates. Supports internal audit's independent assurance over the AI estate and produces the reporting a board can actually govern from.
The whole page, in plain terms
What is AI governance?
The architecture of accountability around AI: knowing what AI systems exist, what each is permitted to do, who owns it, what data it touches, why it was approved, how it is monitored after deployment, who can stop it, and what evidence remains afterwards. It is an operating system, not a policy document.
Why is AI governance different from ordinary IT governance?
Software fails loudly and stops. AI produces a fluent, confident, well-formatted answer that is wrong, and no monitor fires because from the system's point of view nothing failed. AI also decides, acts and changes behaviour after deployment, so governance has to continue after approval rather than ending at it.
What exactly is being governed?
Eight objects: AI systems, models, agents, data, vendors, users, decisions and controls. A model may be acceptable while the AI system assembled around it - retrieval, enterprise data, integrations and tool access - is not, so the unit of governance is the complete system.
Where does AI enter an enterprise?
Four ways: build, buy, embed and use. Embedded AI inside ERP, CRM and SaaS, and AI in direct use by employees, are usually the largest and least documented parts of the estate - which is why the estate is consistently larger than the inventory.
How is AI risk classified?
Multidimensionally: impact on people, decision authority, autonomy, data sensitivity, scale, reversibility, external exposure, regulatory exposure, safety, security, financial impact, model uncertainty and third-party dependency. Classifying by technology type alone produces a register that is both too cautious and too permissive.
How does governance work across the AI lifecycle?
Discover, classify, assess, approve, control, monitor, assure, retire. Each stage has an owner and a defined output. Approval is the fourth stage of eight, not the last one.
How is human accountability maintained?
Through explicitly assigned roles - business owner, model owner, system owner, risk owner, incident commander - each with a stated authority and a stated moment of invocation, and exactly one named holder of the authority to stop a system, with the credential already issued and the path tested.
How are AI agents governed?
By identity, permission register, tool scope, transaction limits, approval thresholds, controls on external communication, rollback where the action is reversible, full tool-call telemetry, a named kill-switch holder and an escalation rota. Every link from agent to model to tool to API to enterprise system to business action is a governance question.
How is third-party AI governed?
Through vendor, model, data, dependency, change and exit controls - including the right to be notified when the model underneath a procured service is replaced, and an exit path that does not depend on the vendor's cooperation.
How is AI continuously monitored?
With governance telemetry that is separate from operational telemetry: categorical signals such as drift detected, owner unassigned, source unverified, access exceeded, review overdue, incident open, control failed and exception active - each paging a named on-call role rather than a shared inbox.
What is the difference between governance of AI and AI for governance?
Governance of AI sets the rules by which AI is introduced, deployed, operated and retired. AI for governance uses AI to do governance work itself - regulatory intelligence, control mapping, evidence review, continuous monitoring. Accountability for governance decisions stays with the authorised human decision-maker, and the AI used by the governance function is itself inside the governance perimeter.
How can the organisation prove what happened?
Through the artefacts each lifecycle stage produces: inventory, risk assessment, impact assessment, owner assignment, approval, test results, monitoring records, incident history, exceptions and audit trail - retained long enough that a decision can still be reconstructed when it is challenged.

Know what exists. Know what it can do. Know who controls it. Know what happened.

The Dubai skyline at night, its lights reflected in still water.

Robert Bock · CC0

Know what exists.Know what it can do.Know who controls it.Know what happened.