AI Governance: Why One-Time Approval Is No Longer Enough
CyberKainos. Reading time: 6 mins
“Firms don’t need new rules to govern AI properly. They need to apply the rules they already have, consistently, to systems that behave differently from traditional software”.
This is advice that has been shared by Nick Prescot, CEO at CyberKainos to more than a few clients over the past few months.
AI is embedded right across just about any business function you care to mention; marketing, data analysis, customer communications, inventory management, logistics, research, compliance monitoring, and HR. It is no longer a pilot or an innovation initiative, it is core infrastructure. This doesn’t mean the old regulatory frameworks need to be thrown away, but it does mean organisations needs to evolve to a more ‘always-on’ approach
What regulators are now expecting when it comes to AI governance
Many regulators have been deliberate in in their positioning: there are no AI-specific rules, and there are unlikely to be any soon. What there is, instead, is a clear and repeated expectation that existing regulatory frameworks such as the Consumer Duty, the Senior Managers and Certification Regime (SMCR), the Systems and Controls sourcebook, and the operational resilience framework already apply to AI. Firms don’t need new rules to govern AI properly. They need to apply the rules they already have, consistently, to systems that behave differently from traditional software.
Firms are expected to nominate a named accountable individual for AI governance, maintain audit trails of model performance, and demonstrate that AI decisions can be explained to customers, to the board, and to supervisors if asked. The FCA as a case in point, has also been explicit that it will not pre-approve AI models. Supervisory engagement and periodic thematic reviews will be how compliance is assessed in practice.
In May 2026, the Bank of England, FCA, and HM Treasury issued a joint statement on frontier AI and cyber resilience, reinforcing expectations around governance, vulnerability management, and incident response. The statement places particular emphasis on firms’ ability to identify and remediate AI-related risks quickly and at scale a standard that is very difficult to meet if your governance model consists of a one-time risk assessment conducted before deployment.
The Problem with One-Time Approval
The approval-and-file model made sense for traditional software. A system is configured once, tested against defined parameters, approved, and monitored for operational performance. If nothing changes, the risk profile is stable.
A machine learning model however, trained on historical data will behave differently as the environment shifts. Customer demographics change. Market conditions change. The distribution of inputs changes. A model that was accurate, fair, and well-calibrated at approval may, quite rapidly, become less accurate, biased, or unreliable, all without any deliberate changes being made to it. This is model drift, and is a predictable characteristic of AI systems, not an edge case.
Generative AI introduces additional dynamics. Large language models used for customer communications, document analysis, or compliance support don’t just drift. They can produce outputs that are inconsistent, factually incorrect, or contextually inappropriate in ways that are difficult to detect through standard monitoring. The failure modes are qualitatively different from those of traditional software, and they require qualitatively different oversight.
What Continuous AI Governance Actually Looks Like in Firms Getting it Right
Firms that are getting this right aren’t treating AI governance as a one-time gate. They are treating it as an ongoing operational discipline, with defined responsibilities, regular review cycles, and escalation processes that function in real time.
Accountable ownership from day one. They name an individual accountable for each material AI system that doesn’t end at approval. It means ongoing visibility of how the system is performing, awareness of any material changes to inputs or outputs, and a clear escalation path if something goes wrong. Regulators will look at whether accountability chains hold up when AI decisions cause harm, not just whether they were documented at the point of deployment.
Ongoing model monitoring. This means they are tracking not just operational metrics like uptime, latency, and error rates, but outcome metrics too: whether the model is producing decisions that are consistent with its intended purpose, fair across different customer segments, and within the bounds of the firm’s risk appetite. For credit models, that means monitoring for demographic disparities. For communications tools, it means sampling and reviewing outputs. For fraud models, it means tracking false positive and false negative rates as the fraud environment evolves.
Defined review triggers. Model governance frameworks should specify conditions under which a full re-review of an AI system is required, not just a scheduled annual review, but event-driven triggers. Material changes to input data, significant shifts in output distribution, changes to the regulatory environment, or incidents involving the model should all prompt escalation and, where appropriate, suspension pending review. Leading firms are already doing this.
Third-party AI oversight. Overwhelmingly, organisations deploy AI through third-party platforms and SaaS tools rather than building models in-house. The governance obligation doesn’t diminish because the model sits outside the firm. The more mature firms we speak to apply the same due diligence, ongoing oversight, and contractual protections to externally-sourced AI as to any other outsourced function.
Board-level visibility. AI risk needs to be a standing item in governance reporting, not something that surfaces only when there’s a problem. Boards need a clear, regular view of which AI systems are in production, what they are used for, how they are performing against defined outcome metrics, and what the escalation history looks like. That visibility is what allows boards to discharge their oversight responsibilities credibly, and it’s what regulators will be looking for if a supervisory review is triggered.
The EU AI Act: An Additional Layer for Some Firms
From August 2026, the EU AI Act’s requirements for high-risk AI systems apply across the EU. UK firms with operations or customers in EU member states face compliance with both existing frameworks and the EU AI Act’s often more prescriptive requirements.
The AI Act does not apply directly to UK-only operations, but firms running dual compliance programmes will find that aligning to the EU standard provides a useful baseline for UK governance as well. The principle is consistent across both frameworks: AI that makes decisions affecting people requires documented, auditable, and ongoing human oversight, not a one-time gate.
How CyberKainos Can Help
At CyberKainos, we help our clients build AI governance frameworks that are fit for the regulatory environment of 2026, not the approval processes designed for a pre-AI world.
Whether you need to map your current AI inventory and assess it against a clear framework or internal expectations, our team brings the regulatory expertise and practical experience to close the gap between where your governance is now and where it needs to be.
AI governance that stops at approval is governance that stops too soon. Visit CyberKainos.com to find out how we can help you build the oversight framework your AI programme actually needs