Editor’s note: The following is a sponsored blog post from QA.
For years, organizations have been able to say they govern AI. Now, they will increasingly be expected to prove it.
Another significant phase of the EU AI Act recently took effect, introducing new transparency requirements while strengthening enforcement of obligations already in scope. This is more than another regulatory milestone. It marks the point where AI governance begins to move from policy to proof.
Transparency sounds simple. It isn’t.
Article 50 introduces transparency obligations including disclosure where people interact with AI, machine-readable marking of synthetic content, and requirements covering deepfakes and certain public-interest content. Sounds straightforward, but the implementation is not.
AI-generated content rarely remains where it was created. It is copied, edited, compressed, screenshotted and redistributed. It moves between platforms, with metadata lost in the ether. Human and machine-generated material increasingly become combined.
A label or machine-readable marker can provide transparency at the point of creation or publication. It can’t guarantee that transparency survives everything that happens afterwards. The Act itself recognizes this technical reality, requiring marking solutions to be effective and robust only as far as technically feasible. This doesn’t make Article 50 ineffective, but it does expose something much more important about AI regulation.
There is a considerable difference between defining a control and demonstrating that the control actually works.
The EU commission’s own approach reinforces the point. Its Transparency Code of Practice provides a mechanism to support compliance with Article 50, but adherence is not in itself conclusive evidence of compliance.
AI governance is becoming an evidence problem
Most organizations can produce AI policies, governance committees and responsible AI principles. Few can demonstrate their AI is actually under control. Much more challenging are the operational questions.
Which AI systems are in use?
Who owns them?
What data can they access?
Which models and suppliers sit underneath them?
What actions can they perform?
How are they monitored?
Can the organization demonstrate that the controls work?
Cybersecurity has already taught us this lesson: policies describe intent. Assurance demonstrates that controls exist, operate effectively and continue working as technology changes. AI is no different. Compliance is not the policy; compliance is the evidence that the policy is working. That auditable evidence layer will prove considerably harder to build than the governance layer sitting above it.
AI is moving from generating content to taking action
The challenge becomes harder because AI adoption is changing. Early concerns centered on hallucinations, sensitive data, generated code and unsanctioned AI use. Those risks haven’t gone away, but the next challenge is different.
AI is moving from generation towards agency. AI agents can interact with applications, access data, call APIs, execute code, use tools and complete multi-stage tasks with progressively less human intervention. A chatbot producing an incorrect answer creates one category of risk. An autonomous system with an identity and permissions creates another entirely.
Recent security evaluations involving advanced models have demonstrated how quickly that risk can become operational. In July, an OpenAI agent escaped its intended testing environment and went on to compromise external systems, including Hugging Face, executing thousands of autonomous actions over several days.
The lesson is not that AI has suddenly escaped human control. It’s that increasingly capable agents can exploit weak containment, exposed credentials and vulnerable infrastructure at machine speed. (See my article Managing Malevolent AI Agents).
AI assurance is rapidly becoming an identity, privilege and runtime control problem. The question isn’t ‘What can this AI generate? It’s ‘What is this AI authorized to do?’
This will matter more and more, as organizations deploy agents into software development, security operations, financial services, customer interactions and business processes.
The control problem gets harder
AI assurance cannot be a point-in-time exercise. The system audited and assessed six months ago may not be the system operating today. Models change, data changes and applications are updated. New tools are connected, with agents gaining permissions, all while the third-party providers update the models underneath enterprise services. The control may still exist on paper, while the risk it was designed to manage has changed underneath it.
Again, the cybersecurity profession has already learned this lesson. Passing a compliance assessment does not make a system secure. Neither does passing an AI compliance assessment. AI assurance will require continuous visibility, testing and auditable evidence. (See my article AI Assurance vs AI Governance).
Organizations will need meaningful AI inventories rather than spreadsheets produced for a compliance check. They will need to understand model and data provenance, AI supply-chain dependencies and where responsibility and control sits between provider and deployer.
Security teams will need to test and ‘red team’ AI-specific attack surfaces including prompt injection, data leakage, insecure tool use, machine identities, delegated authority and excessive agency.
Monitoring will need to capture not simply whether an AI service is available, but at an auditable level, what it is doing. And when something goes wrong, we should have enough evidence to reconstruct what happened.
None of this fits neatly inside a responsible AI policy. It requires operational capability.
Regulation exposes the skills problem underneath
With a passion for skills, you would expect me to call out how regulation is exposing another problem. Organizations cannot govern technology they do not understand. AI literacy obligations have applied under the EU AI Act since February 2025, requiring providers and deployers to take measures to support AI literacy among relevant people.
The Act does not prescribe a universal level of AI expertise. Nor should it. The capability required by a board member is very different from that required by an AI engineer, security architect or developer.
Turning AI literacy into another mandatory training program would miss the point. Executive boards need enough understanding to challenge AI strategy and own the risk. Risk and compliance teams need enough technical understanding to know whether controls are meaningful. Security professionals need to understand AI-specific attacks and defensive controls. Developers need secure AI engineering capability. Procurement teams need to understand AI supply-chain dependencies, etc.
And organizations deploying autonomous agents need people who understand what happens when machine identities receive permissions previously associated primarily with humans. This is not about turning every employee into an AI engineer. It’s about developing enough capability across the organization to make AI governance, and in turn AI assurance, meaningful.
Regulation can define the expected outcome. It cannot create the organizational capability required to deliver it.
From AI governance to AI assurance
The EU AI Act will not solve deepfakes. Transparency labels will not prevent misinformation. Governance frameworks will not prevent autonomous systems behaving unexpectedly.
Regulation will certainly not slow the underlying pace of AI development, but the latest phase of the AI Act signals something more important. The era in which organizations could describe their approach to responsible AI without demonstrating how it works is beginning to close. The next phase will be about evidence, knowing where AI exists and understanding what it can access, as well as controlling what it is authorized to do and demonstrating that the controls work.
That is AI assurance.
As AI moves from generating content to taking action, the organizations that can prove their AI remains under control will have more than regulatory compliance. They’ll have a competitive advantage.