Guardians of the AI Galaxy: The Development of Dynamic Governance
- By Winston Thomas
- April 21, 2025

As AI models evolve at machine speed, companies are discovering that annual validation cycles are about as useful as a paper umbrella in a hurricane.
“AI models are like any other model, except more so,” says David Asermely, global lead for model risk and AI governance at SAS Institute. Speaking at the sidelines of SAS’s recent media conference in Bangkok, he notes that “They require validation, documentation, ongoing monitoring, but they require more of it and more frequent versions of it.”
This deceptively simple observation reveals the central paradox facing companies today: AI's greatest strength — its adaptive nature — is also what makes it most difficult to govern.
The volume challenge
Imagine being on a small validation team tasked with monitoring dozens of large language models, each requiring testing of thousands of prompts and guardrails. Traditional governance structures, with their manual processes and annual validation cycles, simply can’t keep pace.
“The volume of work required to validate and monitor these models is something that doesn't really fit today with what organizations have,” Asermely explains. “When setting aside to make a business decision around ‘I’m going to use AI,’ part of that investment includes the infrastructure to make sure they’re working well.”
This infrastructure investment isn’t optional — it’s critical. Without robust governance mechanisms, companies risk not just regulatory penalties but potentially catastrophic consequences from models that drift, hallucinate, or leak sensitive information.
Fighting fire with fire
Perhaps the most intriguing solution emerging in governance circles involves using AI systems to monitor other AI systems — what Asermely colorfully describes as "fighting fire with fire."

“If you have to validate thousands of prompts for hundreds of models and do this daily, you need an automated tool to do it,” he says. “Imagine you have a separate AI that is constantly testing the responses from your primary large language model.”
This approach introduces what governance experts like Asermely call “judge LLMs” — specialized models trained specifically to evaluate and audit other AI systems. But this creates a potential circular dependency: what happens when the judge itself needs judging?
Humans in the loop
The solution to this circular dependency lies in what governance specialists call “humans in the loop” — expert human validators who spot-check the judge models themselves.
“You still need your human validators to spot check what I call the judge LLM,” Asermely emphasizes. “When the human identifies that the judge made a mistake, that then gets fed back to improve the judge. What you’re doing over time is imparting to the judge LLM expertise from your human validators.”
This hybrid approach creates a virtuous cycle where human expertise gets distilled and amplified through AI systems, allowing validation to scale while maintaining crucial human oversight.
Democracy in AI governance
Some companies are taking a step even further, implementing what amounts to a democratic system of AI governance with multiple independent judge models.
“Instead of having one judge, what if you had five separate judges?” Asermely proposes. “A response comes in, four of them say it’s good and one says it’s bad. The human would look at that and say, ‘Are the four wrong? Or is that one wrong?’”
This multi-judge approach adds additional resilience to governance frameworks, allowing for the detection of edge cases and nuanced failures that might slip past a single evaluation model.
The regulatory advantage
While many organizations view regulations like the E.U. AI Act as obstacles, Asermely sees them as accelerators for responsible innovation.
“The European Union Act and similar things help your organization move forward with AI,” he argues. “One of the important things it does is it says, ‘Hey, this is prohibited AI. Don’t even bother building it.’ It also classifies AI that are minimal risk or limited risk — stuff you can make mistakes with today.”
This risk-tiered approach allows companies to focus their governance resources where they matter most while experimenting freely in lower-risk domains, creating learning opportunities without existential threats.
The literacy imperative
Perhaps the most overlooked aspect of AI governance is what regulators call “AI literacy” — the establishment of a common language and understanding across organizational hierarchies.
“AI literacy, to me, means a common language that can be used across an organization,” Asermely explains. “Everyone from the interns to the board of directors to a regulator should be able to look at it and say, ‘I understand this model, what it’s doing, and if there’s a problem, it’s easily identified.’”
As companies navigate the complex terrain between theoretical frameworks and practical implementation, this literacy component may ultimately determine which governance approaches succeed and which fail. Without a shared understanding of what AI systems are doing and the risks they pose, even the most sophisticated governance frameworks will collapse under their complexity.
Image credit: iStockphoto/Malchev
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.