In this episode of Impact of AI: Explored, Gerjon and James talk with Rob Fawcett (The Human CTO) about the “boring but necessary” side of AI: governance, assurance and compliance. Rob explains why most organizations already have the skills from GDPR, ISO and data protection work – they just forget that AI is another governance problem, not a completely new universe.
Topics we cover are the EU AI Act, the upcoming UK AI bill, and the real tension between moving fast with AI and staying compliant. Rob breaks down the three modes he sees in companies today: policy and forget, the waiting game, and speed vs compliance. He also argues IT – especially the service desk – is one of the most underused assets in AI governance.
We dive into agentic AI (agents talking to agents with no human in the loop), data classification and anonymization, and who’s ultimately responsible when AI agents go wrong – vendors or the business. Rob introduces the ARIA framework (AI Readiness, Impact, Assurance), which scores and prioritizes AI use cases so you don’t just make bad processes faster, and explains how even small teams can start with something as simple as a spreadsheet inventory of all AI tools in use.
Support the show