Abstract artwork of layered translucent planes settling into alignment

LLM governance while the rules are still moving

The EU just shuffled its AI Act deadlines again. How to write governance that survives regulatory drift instead of chasing it.

If your governance program was calibrated to the EU AI Act's original timeline, you have already rewritten it once this year. The May 2026 omnibus agreement deferred the marquee high-risk obligations from August 2026 to December 2027, while chatbot transparency duties still land in August 2026 and content-labeling slips only four months. Regulators are negotiating with their own deadlines. Yours should be sturdier than theirs.

The trick is to write governance around invariants: the handful of duties that every plausible version of every plausible regulation will contain. Know what AI systems you run and what data they touch (the inventory again; it is always the inventory). Be able to explain what a system does in plain language. Keep a human accountable for every consequential automated decision. Log enough to reconstruct what happened. Tell people when they are talking to a machine.

Notice what that list does not contain: anything you would regret doing even if all regulation evaporated tomorrow. That is the test of a good invariant.

the two-tier trick

Write a short constitution (the invariants, a page, reviewed yearly) and thin compliance annexes per regulation that map invariants to specific articles. When Brussels moves a deadline, you update an annex, not your company's understanding of itself. The teams that suffer regulatory whiplash are the ones whose entire program was a compliance checklist for one law's one version.

what belongs in the constitution

The invariants that survive every regulatory rewrite are the ones you would want anyway, which is rather the point. An inventory of every model-backed feature with a named owner. A risk tier per use case, decided by what the feature can do to a person, not by which law currently names it. Human accountability for consequential outputs, written into role descriptions rather than pinned to a poster. Data provenance you can answer questions about: what went into the model, under which terms, exportable when someone asks. And an incident path that treats "the model did something strange" as a reportable event with an owner, not a Slack anecdote. Ten years of AI regulation from three continents will bend around those five without breaking them, because regulators keep asking for the same five things in different fonts.

the annex discipline

Each annex is deliberately boring: a two-column table, invariant on the left, the specific article it satisfies on the right, dated, owned by the person watching that regulation. When an auditor or a customer's procurement team asks how you comply with whatever passed most recently, the answer is the relevant annex, produced in minutes. The alternative we keep finding in audits is a 60-page "AI Governance Framework" written for a law as it stood two amendments ago, unowned, contradicted by practice, and cited by nobody except the consultancy that sold it. A page that is true beats a binder that was true. Write the page, staff the watcher, and let the annexes absorb the churn.

The constitution-and-annex structure has one more virtue worth naming: it survives your own reorganizations, which arrive more often than regulations do. Committees dissolve, programs get renamed, the person who owned "AI governance" moves on, and a binder-based program dies with its binder. Five invariants with named owners in role descriptions persist through the shuffle, because they are attached to jobs rather than initiatives.

And keep a person, not a committee, watching the official timeline. Committees read updates quarterly. Deadlines move faster than that, in both directions, as this spring cheerfully demonstrated.