Operating GRC at AI Speed · Episode 5
April 26, 2026
Policies should follow controls, not the other way around
Most governance writing describes a single direction: policy defines what should be true, standards narrow it, procedures operationalize it, and controls prove it. That’s clean and useful, but for companies shipping AI products on weekly cadences, it’s only half of what’s actually happening.
In practice, the controls I work on often emerge from product reality first: a retention rule in infrastructure, a redaction path in the inference stack, an authorization check added after a pen test. Policy catches up later. The reverse happens too: policy exists, implementation lags behind. Both directions run at once. The useful question isn’t which direction is right; it’s which direction is dominant in your organization right now, and how to set up a healthy loop between them.
Policy and controls are where governance, engineering, and enterprise sales all meet. From what I’ve seen across AI-native security programs, the teams that close enterprise deals reliably are the ones running both directions on purpose, not a one-way cascade from policy to code.
Top-down dominant: strong narrative, thin evidence
Symptoms. The policy library is current. Control evidence is stale or scattered. Enterprise buyers and auditors get confident narratives that wobble when someone asks to see enforcement in production.
Where the gap shows up. Document reviews pass; implementation reviews surface gaps. The story on paper is ahead of the story in production.
Direction of travel. Policy → intended control → implementation (often delayed).
What helps. Coding-agent or scanner-assisted inventories, continuous evidence collection, and policy language that tracks what actually shipped, not what the team hopes will ship next quarter.
Bottom-up dominant: strong systems, weak external story
Symptoms. Technical controls are real. Policy coverage is thin or inconsistent. Different teams answer questionnaires differently. Institutional memory lives in Slack threads and merged PRs.
Where the gap shows up. The organization is often safer than it can prove. Deals stall when trust collateral doesn’t match what’s already running in production. The fix here is presentation, not engineering.
Direction of travel. Implementation → implicit control → policy (catches up).
What helps. Scheduled reconciliation against technical inventories, and a single owner for what the company claims externally.
The two-way loop: what “mature” looks like
Mature AI-native GRC doesn’t pick a single arrow. It runs a loop:
- Product and engineering reality changes.
- Technical control inventory updates (ideally agent- or scanner-assisted).
- Policy, standards, and external claims update to match what’s actually true, or narrow until they do.
- New requirements arrive from sales, audits, and vendors.
- Engineering closes the next gap, and the loop turns again.
Update policy based on controls when implementation leads. Update controls based on policy when commitments lead: new certification scope, new enterprise clause, new regulatory obligation.
The mature pattern is running both directions on purpose, on a cadence, instead of waiting for one direction to catch up to the other on its own.
The table below is a quick diagnostic.
| Signal | Likely dominant mode | First fix |
|---|---|---|
| Policies refreshed annually; product ships weekly | Top-down on paper, bottom-up in reality | Inventory + reconcile |
| Questionnaire answers differ by team | Bottom-up | Single external claims owner |
| Audit findings cite “not operating effectively” | Top-down narrative gap | Evidence paths per control |
| Security review surprises despite “good” policies | Bottom-up implementation without external sync | Trust collateral refresh |
A one-hour workshop exercise
You don’t need a transformation program to learn which mode you’re in.
- Pick five controls your largest customers asked about last quarter.
- For each, document where it lives in code or infrastructure, where it lives in policy, and how it appears in questionnaire answers.
- Mark whether implementation or policy came first.
- Agree on one reconciliation action per control.
Most AI-native companies are bottom-up before they intentionally install the loop. That isn’t a failure. It’s a normal stage of growth, and a strong starting position. The goal is to install the loop on your own schedule, not the one a customer audit hands you.
How this series fits together
Traditional GRC assumed controls and policies moved at human pace. AI-native companies move faster than that, and the operating model is changing in our favor. Redlines track maturity. Vendor contracts give you a free roadmap. Coding agents keep an inventory of reality. AI-assisted prep stress-tests narratives before auditors do. The two-way loop ties those pieces together.
Operating GRC at AI speed isn’t about doing old process faster. It’s about running governance that matches how AI products and enterprise buyers actually move, so policy and production describe the same company.
Previous: Audit prep in the age of AI · Series index
Series
Related
Newsletter
Email when I publish.
Share on LinkedIn · Pushback? LinkedIn is fine.