{"id":13924,"date":"2026-08-11T17:05:33","date_gmt":"2026-08-11T11:35:33","guid":{"rendered":"https:\/\/gapstars.net\/tech\/?post_type=resource&#038;p=13924"},"modified":"2026-08-20T16:34:50","modified_gmt":"2026-08-20T11:04:50","slug":"5-ways-to-stay-in-control-of-ai","status":"publish","type":"resource","link":"https:\/\/gapstars.net\/tech\/resource\/5-ways-to-stay-in-control-of-ai\/","title":{"rendered":"5 Ways to Stay in Control of AI | AI Governance for CTOs"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"13924\" class=\"elementor elementor-13924\" data-elementor-post-type=\"resource\">\n\t\t\t\t<div class=\"elementor-element elementor-element-801cf98 e-flex e-con-boxed e-con e-parent\" data-id=\"801cf98\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4797797 elementor-widget elementor-widget-text-editor\" data-id=\"4797797\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">AI is growing faster within every organization than anyone can map it. Most leaders have hardly any idea what people are using, building and vibe coding internally: some sales agents doing company research, a model screening CVs for new applicants, and coding tools secretly collecting a little too much data from repo\u2019s. What should make organisations uncomfortable is NOT knowing what happens, because: You can only govern what you can see.&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While setting up enterprise-grade AI governance is complex, you don\u2019t need to wait for the big program to get moving. There are 5 no-regret moves that will help you get grip and control of your AI internally. We\u2019ll dive deeper into this topic at the our <a href=\"https:\/\/gapstars.net\/tech\/cto-club\/\">CTO Club session<\/a> the 27th of August, 2026, together, but hey, why not share them upfront to get you going?<br><br><\/span><\/p>\n<h2><b>1. Classify by Risk&nbsp;<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Almost every AI policy, framework and law is risk-based. So start by setting up a workflow for each AI use case to evaluate your AI risk exposure by working through these impact questions:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">What&#8217;s the intended use?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Who is the intended user?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">How could it be misused and how to prevent that?<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">What is the impact on individuals or society (if it goes wrong)?<\/span><\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">To help you further with classification, you can fill in Deeploy&#8217;s 5-minute <\/span><a href=\"https:\/\/deeploy.ai\/eu-ai-act-hub\/self-assessment\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">risk self-assessment tool<\/span><span style=\"font-weight: 400;\"> or c<\/span><\/a><span style=\"font-weight: 400;\">heck the risk frameworks by <\/span><a href=\"https:\/\/airisk.mit.edu\/priorities\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">MIT FutureTech<\/span><\/a><span style=\"font-weight: 400;\"> or <\/span><a href=\"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3531146.3533088\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Google Deepmind<\/span><\/a><span style=\"font-weight: 400;\"> to help you classify the impact of your risks<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, the AI Act provides a list of high risk systems, and has criteria for limited risk. Define one to use for your registry (step 2) and control framework (step 3). Your sales agent might be low risk (depending on use and the type of data it uses), while your credit risk scoring agent is high risk right-away.<br><br><\/span><\/p>\n<h2><b>2. Setup an AI registry<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Nothing worse than not knowing what\u2019s running across the org. <\/span><a href=\"https:\/\/deeploy.ai\/eu-ai-act-hub\/articles\/ai-system-inventory-eu-ai-act-compliance\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Setting up an AI registry<\/span><\/a><span style=\"font-weight: 400;\">, listing all your internal AI and agents and AI brought by external vendors is the second step to get grip and control. Preferably, you connect such an AI registry with the most important AI platforms, like Claude, OpenAI or Bedrock, so that any new AI system is automatically added to the AI registry, without further work needed on your side. The AI register should at least contain:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Name of the use case<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Description<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk level<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Lifecycle stage: exploration -&gt; development -&gt; validation -&gt; production -&gt; retirement<br><br><\/span><\/span><\/span><\/li>\n<\/ul>\n<h2><b>3. Define a Control Framework<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Registering also means documenting certain steps. This can be done by defining a control framework, with the controls you\u2019d like to enable per use case. You could follow established ones, like <\/span><a href=\"https:\/\/www.iso.org\/standard\/42001\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">ISO 42001<\/span><\/a><span style=\"font-weight: 400;\">, <\/span><a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">NIST AI RMF<\/span><\/a><span style=\"font-weight: 400;\"> or the high risk articles of the AI Act, or define one yourself. Best is to make this dependent on lifecycle stage, risk level and your role (are you providing an AI system, or just deploying?)<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define a list of controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">When are these controls applicable? (Lifecycle, risk level, role\u2026)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Define when to validate again? ( Yearly, quarterly\u2026)<br><br><\/span><\/span><\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Showing a <\/span><a href=\"https:\/\/deeploy.ai\/white-paper-ai-governance-control-framework\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">working control framework<\/span><\/a><span style=\"font-weight: 400;\"> will prove that you are in control of the AI in your company while having a way to continuously improve for safety.<br><br><\/span><\/p>\n<h2><b>4. Evaluate, monitor and alert<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">You can document and register all you like, but without proper evaluations, monitoring, and alerts, you don&#8217;t know how your AI systems are actually behaving. What this looks like differs per type of AI system. Predictive models, generative AI applications, and agents each need a different approach. Consider the following practices:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Evaluations: <\/b><span style=\"font-weight: 400;\">For predictive AI, you can design evaluations close to traditional unit tests in software engineering: fixed inputs, expected outputs, clear pass\/fail. For generative and agentic use cases, designing effective evaluations is a different story. The starting point is a test set of realistic tasks, because without one there is nothing to evaluate against. From there, one of the most important choices is what your evals rely on: deterministic code, model-based evaluations (LLM-as-judge), humans, or a combination. Each comes with trade-offs. Code-based evals are cheap and reliable, but only cover outcomes you can check programmatically. LLM-as-judge scales to fuzzy criteria like tone or helpfulness, but the judge itself needs validation. Human evaluation is the most trustworthy option, but doesn&#8217;t scale. Check out<\/span><a href=\"https:\/\/www.anthropic.com\/engineering\/demystifying-evals-for-ai-agents\" target=\"_blank\" rel=\"noopener\"> <span style=\"font-weight: 400;\">this useful guide<\/span><\/a><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> from Anthropic for a detailed look at evals for agents.<br><br><\/span><\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Monitoring &amp; alerting: <\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">For predictive AI, monitoring and alerting can be standardised, for example by measuring performance and drift. For agentic use cases, effective monitoring is often achieved by tracing agentic interactions with users and their environment. For proactive alerting, you need to know what you are looking for. Examples are specific (high-risk) tool calls, unexpected tool-call sequences, guardrail triggers, task failure rates, human override rates, latency, and the number of tokens consumed, which is both a cost signal and a way to catch runaway loops. Evaluations shouldn&#8217;t stop at deployment either. By sampling production traffic through the same eval suite (online evals) and comparing the results against your offline benchmark, you can detect drift between how the system performed in testing and how it behaves in the real world. Under the EU AI Act, this kind of on-going post-market monitoring is an obligation for deployers, not just good practice.<br><br><\/span><\/span><\/span><\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">In all of this, the role of humans should not be underestimated, for two distinct reasons:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Accountability:<\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> responsibility for actions performed and decisions made ultimately lies with humans. Placing a human in the loop prevents accountability gaps, and for high-risk systems under the EU AI Act, effective human oversight (Article 14) is a legal requirement. This also connects back to documentation and registration: you can only demonstrate oversight if it is designed in and logged.\n<p><\/p>\n<p><\/p><\/span><\/span><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Quality:<\/b><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"> A human can only meaningfully assess a model&#8217;s output when given enough context. Think of (RAG) references for generated text, reasoning traces for agents, or better yet, explanations showing what was important for the model to get to a certain output. A human who approves outputs without context adds little oversight.<br><br><\/span><\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Finally, humans don&#8217;t scale. Decide deliberately where to place them: pre-action approval for high-risk, irreversible actions (payments, sending communications, changing records), and sampled post-hoc review for everything else. Both feed back into your evals and monitoring, since human corrections are a valuable signal.<br><br><\/span><\/p>\n<h2><b>5. Guardrailing&nbsp;<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">When alerting after the fact is not enough and the impact of specific instructions or model actions should be prevented, guardrailing is the control you are looking for. One of the most realistic risks users are exposed to is prompt injection, where malicious instructions reach the model through numerous sources: uploaded documents, retrieved web pages, or in coding agents even branch and commit names.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Guardrails can act on the input side (blocking or sanitising instructions before they reach the model), on the output side (filtering responses before they reach the user), and on actions (restricting which tools an agent can call and with which parameters). For selecting the right guardrail to prevent a specific user or model action, you can again choose between deterministic guardrails and model-based ones. Deterministic guardrails, such as regex filters, allowlists, and hard limits on tool parameters, are fast and predictable, but only catch what you anticipated. Model-based guardrails, such as classifiers for injection attempts or unsafe content, catch semantic variations, but add latency and can themselves be wrong in both directions. In practice you want layers: cheap deterministic checks first, model-based checks for what slips through, and, as described below, a human for what no automated check should decide alone.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Note that guardrails are systems too. Evaluate them before deployment and monitor how often they trigger in production, since both a silent guardrail and a constantly firing one are signals that something is off.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The end result of the steps above should give you the control you need in early stages. A registry, risk frameworks and the technical controls.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We can imagine that the steps above are something you\u2019re already doing to a certain extent in other tools, and that\u2019s all good. Tools like Deeploy sits right on top of AI systems, with built-in integrations to let AI register itself, while monitoring, alerting and guardrails come out of the box.<br><br><\/span><\/p>\n<h2><b>Join the conversation for more<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">If you are a tech leader, join us, on the 27th of August, 2026 together with Gapstars, to talk about keeping control of AI, building AI governance to scale AI responsibly.<br><\/span><span style=\"letter-spacing: -0.1px;\"><br>Reserve your seat here:<\/span><\/p>\n<p><a href=\"https:\/\/forms.gle\/XWwAdFNJuCEWVa4W7\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/forms.gle\/XWwAdFNJuCEWVa4W7<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7ff5425 e-flex e-con-boxed e-con e-parent\" data-id=\"7ff5425\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<a class=\"eael-wrapper-link-b1026c4 --eael-wrapper-link-tag\" href=\"https:\/\/forms.gle\/XWwAdFNJuCEWVa4W7\" target=\"_blank\" rel=\"noopener\"><\/a>\t\t<div data-eael-wrapper-link=\"eael-wrapper-link-b1026c4\" class=\"elementor-element elementor-element-b1026c4 elementor-widget elementor-widget-image\" data-id=\"b1026c4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"504\" src=\"https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/2-3-1024x645.png\" class=\"attachment-large size-large wp-image-13928\" alt=\"\" srcset=\"https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/2-3-1024x645.png 1024w, https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/2-3-300x189.png 300w, https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/2-3-768x484.png 768w, https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/2-3-1536x967.png 1536w, https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/2-3-1320x831.png 1320w, https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/2-3.png 1588w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-26aafbb e-flex e-con-boxed e-con e-parent\" data-id=\"26aafbb\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-01b60bf elementor-widget elementor-widget-html\" data-id=\"01b60bf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"gs-faq-section\">\n  <h2>FAQ<\/h2>\n\n  <div class=\"gs-faq-item\">\n    <button class=\"gs-faq-question\" aria-expanded=\"false\">\n      <span class=\"gs-faq-text\">How do you classify AI risk in an organization?<\/span>\n      <span class=\"gs-faq-icon\">+<\/span>\n    <\/button>\n    <div class=\"gs-faq-answer\">\n      <p>Start by evaluating each AI use case against four questions: what's the intended use, who's the intended user, how could it be misused, and what's the impact if it goes wrong. Most AI laws and frameworks, including the EU AI Act, are risk based, so this classification becomes the foundation for your registry and controls.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"gs-faq-item\">\n    <button class=\"gs-faq-question\" aria-expanded=\"false\">\n      <span class=\"gs-faq-text\">What should an AI registry include?<\/span>\n      <span class=\"gs-faq-icon\">+<\/span>\n    <\/button>\n    <div class=\"gs-faq-answer\">\n      <p>An AI registry should list every internal and vendor AI system with its use case name, description, owner, risk level, and lifecycle stage. Connecting it to platforms like Claude, OpenAI, or Bedrock lets new systems register automatically. Many teams find the bottleneck isn't the tooling but having someone dedicated to own and maintain it. Gapstars places specialized nearshore talent for exactly this kind of ongoing governance ownership.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"gs-faq-item\">\n    <button class=\"gs-faq-question\" aria-expanded=\"false\">\n      <span class=\"gs-faq-text\">What is the difference between deterministic and model based guardrails?<\/span>\n      <span class=\"gs-faq-icon\">+<\/span>\n    <\/button>\n    <div class=\"gs-faq-answer\">\n      <p>Deterministic guardrails, such as regex filters, allowlists, and hard parameter limits, are fast and predictable but only catch what you've explicitly anticipated. Model based guardrails, like classifiers for prompt injection, catch semantic variations but add latency and can be wrong in either direction. Most effective setups layer both, with humans reviewing what neither catches.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"gs-faq-item\">\n    <button class=\"gs-faq-question\" aria-expanded=\"false\">\n      <span class=\"gs-faq-text\">Why is human oversight still necessary in AI governance?<\/span>\n      <span class=\"gs-faq-icon\">+<\/span>\n    <\/button>\n    <div class=\"gs-faq-answer\">\n      <p>Accountability for AI decisions ultimately sits with humans, and for high risk systems under the EU AI Act, human oversight is a legal requirement, not optional. Oversight only works when people are given real context, such as reasoning traces, references, or explanations, otherwise approval becomes a rubber stamp rather than genuine review.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"gs-faq-item\">\n    <button class=\"gs-faq-question\" aria-expanded=\"false\">\n      <span class=\"gs-faq-text\">What is prompt injection and why does it matter for AI governance?<\/span>\n      <span class=\"gs-faq-icon\">+<\/span>\n    <\/button>\n    <div class=\"gs-faq-answer\">\n      <p>Prompt injection is when malicious instructions reach a model through indirect sources, such as uploaded documents, retrieved web pages, or even branch and commit names in coding agents, rather than directly from the user. It's one of the most realistic risks organizations face, which is why input and output guardrails matter alongside monitoring.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"gs-faq-item\">\n    <button class=\"gs-faq-question\" aria-expanded=\"false\">\n      <span class=\"gs-faq-text\">Who is the Gapstars CTO Club for?<\/span>\n      <span class=\"gs-faq-icon\">+<\/span>\n    <\/button>\n    <div class=\"gs-faq-answer\">\n      <p>The Gapstars CTO Club is a community of 150+ CTOs and senior tech leaders across the Benelux and UK, built for real peer exchange rather than surface level networking. It's aimed at tech leaders at software, SaaS, or agency based companies with 20 to 500 employees who want to discuss scaling engineering teams and AI governance with peers who've faced the same challenges.<\/p>\n    <\/div>\n  <\/div>\n\n  <div class=\"gs-faq-item\">\n    <button class=\"gs-faq-question\" aria-expanded=\"false\">\n      <span class=\"gs-faq-text\">Do you need a dedicated team to run AI governance, or can existing staff absorb it?<\/span>\n      <span class=\"gs-faq-icon\">+<\/span>\n    <\/button>\n    <div class=\"gs-faq-answer\">\n      <p>It depends on scale and risk exposure, but most organizations underestimate the ongoing workload. Registries need maintenance, evals need updating, and guardrails need monitoring for drift. Once you're past initial setup, it's common to bring in dedicated support rather than layering it onto engineers who already own product work. This is the kind of role Gapstars specializes in staffing, nearshore governance and AI ops talent for Benelux and UK tech teams.<\/p>\n    <\/div>\n  <\/div>\n<\/div>\n\n<style>\n.gs-faq-section {\n  margin: 40px 0;\n}\n\n.gs-faq-item {\n  border-top: 1px solid #e5e5e5;\n}\n\n.gs-faq-item:last-child {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.gs-faq-question,\n.gs-faq-question:hover,\n.gs-faq-question:focus,\n.gs-faq-question:active {\n  width: 100% !important;\n  text-align: left !important;\n  background: none !important;\n  background-color: transparent !important;\n  border: none !important;\n  padding: 28px 0 !important;\n  cursor: pointer !important;\n  display: flex !important;\n  align-items: center !important;\n  gap: 16px !important;\n  box-shadow: none !important;\n}\n\n.gs-faq-text,\n.gs-faq-question:hover .gs-faq-text {\n  flex: 1;\n  color: #1a1a1a !important;\n  font-size: 18px !important;\n  font-weight: 700 !important;\n  line-height: 1.4 !important;\n}\n\n.gs-faq-icon,\n.gs-faq-question:hover .gs-faq-icon {\n  flex-shrink: 0;\n  font-size: 21px;\n  font-weight: 700;\n  color: #e87a2e !important;\n  line-height: 1;\n  transition: transform 0.2s;\n}\n\n.gs-faq-question[aria-expanded=\"true\"] .gs-faq-icon {\n  transform: rotate(45deg);\n}\n\n.gs-faq-answer {\n  max-height: 0;\n  overflow: hidden;\n  transition: max-height 0.3s ease;\n}\n\n.gs-faq-answer p {\n  padding: 0 40px 28px 0;\n  margin: 0;\n  font-size: 16px;\n  line-height: 1.6;\n  color: #444;\n}\n<\/style>\n\n<script>\ndocument.querySelectorAll('.gs-faq-question').forEach(function(btn) {\n  btn.addEventListener('click', function() {\n    var expanded = btn.getAttribute('aria-expanded') === 'true';\n    var answer = btn.nextElementSibling;\n\n    \/\/ Close all other open questions first\n    document.querySelectorAll('.gs-faq-question').forEach(function(otherBtn) {\n      if (otherBtn !== btn) {\n        otherBtn.setAttribute('aria-expanded', 'false');\n        otherBtn.nextElementSibling.style.maxHeight = '0';\n      }\n    });\n\n    \/\/ Toggle the clicked one\n    btn.setAttribute('aria-expanded', !expanded);\n    answer.style.maxHeight = expanded ? '0' : answer.scrollHeight + 'px';\n  });\n});\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a926106 e-flex e-con-boxed e-con e-parent\" data-id=\"a926106\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-66be546 elementor-widget elementor-widget-html\" data-id=\"66be546\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@graph\": [\n    {\n      \"@type\": \"Article\",\n      \"headline\": \"5 Ways to Stay in Control of AI\",\n      \"description\": \"5 no-regret moves to stay in control of AI inside your org: classify risk, build a registry, guardrail, and more.\",\n      \"image\": \"https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2026\/08\/Screenshot-2026-08-11-at-16.03.54.png\",\n      \"datePublished\": \"2026-08-11\",\n      \"dateModified\": \"2026-08-12T14:41:02+05:30\",\n      \"author\": {\n        \"@type\": \"Organization\",\n        \"name\": \"Gapstars\"\n      },\n      \"publisher\": {\n        \"@type\": \"Organization\",\n        \"name\": \"Gapstars\",\n        \"logo\": {\n          \"@type\": \"ImageObject\",\n          \"url\": \"https:\/\/gapstars.net\/tech\/wp-content\/uploads\/2025\/08\/cropped-Gapstars-Logo-512x512-1-270x270.png\"\n        }\n      },\n      \"mainEntityOfPage\": {\n        \"@type\": \"WebPage\",\n        \"@id\": \"https:\/\/gapstars.net\/tech\/resource\/5-ways-to-stay-in-control-of-ai\/\"\n      }\n    },\n    {\n      \"@type\": \"FAQPage\",\n      \"mainEntity\": [\n        {\n          \"@type\": \"Question\",\n          \"name\": \"How do you classify AI risk in an organization?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Start by evaluating each AI use case against four questions: what's the intended use, who's the intended user, how could it be misused, and what's the impact if it goes wrong. Most AI laws and frameworks, including the EU AI Act, are risk based, so this classification becomes the foundation for your registry and controls.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What should an AI registry include?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"An AI registry should list every internal and vendor AI system with its use case name, description, owner, risk level, and lifecycle stage. Connecting it to platforms like Claude, OpenAI, or Bedrock lets new systems register automatically. Many teams find the bottleneck isn't the tooling but having someone dedicated to own and maintain it. Gapstars places specialized nearshore talent for exactly this kind of ongoing governance ownership.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What is the difference between deterministic and model based guardrails?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Deterministic guardrails, such as regex filters, allowlists, and hard parameter limits, are fast and predictable but only catch what you've explicitly anticipated. Model based guardrails, like classifiers for prompt injection, catch semantic variations but add latency and can be wrong in either direction. Most effective setups layer both, with humans reviewing what neither catches.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Why is human oversight still necessary in AI governance?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Accountability for AI decisions ultimately sits with humans, and for high risk systems under the EU AI Act, human oversight is a legal requirement, not optional. Oversight only works when people are given real context, such as reasoning traces, references, or explanations, otherwise approval becomes a rubber stamp rather than genuine review.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"What is prompt injection and why does it matter for AI governance?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"Prompt injection is when malicious instructions reach a model through indirect sources, such as uploaded documents, retrieved web pages, or even branch and commit names in coding agents, rather than directly from the user. It's one of the most realistic risks organizations face, which is why input and output guardrails matter alongside monitoring.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Who is the Gapstars CTO Club for?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"The Gapstars CTO Club is a community of 150+ CTOs and senior tech leaders across the Benelux and UK, built for real peer exchange rather than surface level networking. It's aimed at tech leaders at software, SaaS, or agency based companies with 20 to 500 employees who want to discuss scaling engineering teams and AI governance with peers who've faced the same challenges.\"\n          }\n        },\n        {\n          \"@type\": \"Question\",\n          \"name\": \"Do you need a dedicated team to run AI governance, or can existing staff absorb it?\",\n          \"acceptedAnswer\": {\n            \"@type\": \"Answer\",\n            \"text\": \"It depends on scale and risk exposure, but most organizations underestimate the ongoing workload. Registries need maintenance, evals need updating, and guardrails need monitoring for drift. Once you're past initial setup, it's common to bring in dedicated support rather than layering it onto engineers who already own product work. This is the kind of role Gapstars specializes in staffing, nearshore governance and AI ops talent for Benelux and UK tech teams.\"\n          }\n        }\n      ]\n    }\n  ]\n}\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>5 no-regret moves to stay in control of AI inside your org: classify risk, build a registry, guardrail, and more.<\/p>\n","protected":false},"featured_media":13927,"template":"","meta":{"_acf_changed":false,"content-type":""},"resource-category":[77],"class_list":["post-13924","resource","type-resource","status-publish","has-post-thumbnail","hentry","resource-category-blog"],"acf":[],"_links":{"self":[{"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/resource\/13924","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/types\/resource"}],"version-history":[{"count":25,"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/resource\/13924\/revisions"}],"predecessor-version":[{"id":14026,"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/resource\/13924\/revisions\/14026"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/media\/13927"}],"wp:attachment":[{"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/media?parent=13924"}],"wp:term":[{"taxonomy":"resource-category","embeddable":true,"href":"https:\/\/gapstars.net\/tech\/wp-json\/wp\/v2\/resource-category?post=13924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}