By Raj Brar, Founder of Argus AI Labs
In the 1990s, I started working with diagnostic mapping as vehicles were becoming computer systems on wheels.
I ran three automotive centres. At different stages, I had engineering teams that grew from five people to fifteen. The work was never only about replacing a part. We had to understand the system: what the sensors were reporting, how one component affected another, what the diagnostic equipment could see, and what evidence justified the repair.
Then the technology matured.
The informal methods that worked when systems were simpler were no longer enough. Diagnostics became more structured. Software became inseparable from the machine. Training, documentation, tooling, and accountability had to catch up.
I have watched the same pattern repeat across mobile technology, crypto, data infrastructure, and now artificial intelligence.
Every major technology begins with a period of experimentation. People build quickly. The rules are incomplete. The market rewards speed, and the consequences remain distant enough to ignore.
Then the technology moves into real operations.
It touches hiring, healthcare, finance, infrastructure, intellectual property, and customer decisions. What began as experimentation becomes dependency. At that point, “move fast” stops being a complete operating philosophy.
That is where enterprise AI is now.
AI is leaving the experimentation phase
The phrase “Wild West” can make the current moment sound lawless. It is more accurate to say the rules are arriving unevenly.
Europe has created binding obligations through the EU AI Act. The law applies progressively, with different provisions and enforcement dates for prohibited practices, general-purpose AI, transparency, and high-risk systems. It can also affect companies outside Europe when they place systems in the EU market or when system outputs are used there.
The United States has taken a different route. There is still no single federal statute equivalent to the EU AI Act. Instead, organizations face a combination of federal procurement and agency policies, sector-specific law, state activity, contractual requirements, and voluntary technical frameworks. The current federal direction emphasizes innovation and a less fragmented national policy, but that does not remove the operating risks enterprises must manage.
China is developing its own governance model around security, content, lifecycle ethics, and tiered risk control.
The jurisdictions differ. The direction does not.
AI is moving from a market where governance could be treated as an internal policy discussion to one where organizations increasingly need to show how their systems are controlled.
Three systems are converging—but they are not the same thing
Enterprise conversations increasingly bring together the EU AI Act, the NIST AI Risk Management Framework, and ISO/IEC 42001.
They overlap, but they do different jobs.
The EU AI Act creates legal obligations based on the role an organization plays and the risk of the system. It asks questions about prohibited uses, transparency, risk management, data governance, documentation, human oversight, accuracy, cybersecurity, and post-market monitoring.
The NIST AI RMF provides a voluntary risk-management method. Its four functions—Govern, Map, Measure, and Manage—give technical and operational teams a way to identify context, assess risk, evaluate behavior, assign responsibility, and respond over the lifecycle.
ISO/IEC 42001 provides the management-system structure. It establishes requirements for an organization to implement, maintain, and continually improve an artificial intelligence management system. Unlike NIST AI RMF, it is designed for certification.
One is a legal regime. One is a risk framework. One is a certifiable management-system standard.
Treating them as three unrelated compliance projects creates duplicate work and disconnected evidence. Treating them as interchangeable creates false confidence.
The better approach is to build one operating system for AI governance that can support all three.
Paper governance will not control a live system
A policy can state that employees must not paste sensitive information into an unapproved model. That does not tell leadership whether it happened yesterday.
A risk register can state that a model may hallucinate. That does not show which evaluation failed, what evidence the model used, or whether a human reviewed the output.
A vendor contract can assign responsibility. That does not automatically provide lineage across models, datasets, retrieval layers, prompts, tools, and downstream actions.
This is the gap many enterprises are about to discover.
They have governance documents, but not a governed system.
Operational governance requires controls that exist inside the workflow:
- an inventory of AI systems and their intended uses;
- clear ownership across provider, deployer, vendor, and internal teams;
- approved data boundaries and traceable datasets;
- evaluation records tied to a model and use case;
- identity, permission, and access controls;
- logs that show what happened and when;
- human review at the decisions that require it;
- incident and exception paths;
- change control for models, prompts, fine-tuning, and intended purpose;
- evidence that can be produced for leadership, procurement, auditors, or regulators.
The question is no longer whether a company has an AI policy.
The question is whether the company can prove how its AI behaves.
Builders need to understand when their role changes
This becomes especially important when an enterprise does more than purchase a finished tool.
Consider what happens when a company fine-tunes a model on its own data, places its brand on a system, changes the intended purpose, connects it to internal decision workflows, or gives it authority to act through other software.
The company may believe it is simply a customer using a vendor product. Its real technical and legal responsibilities may be more complicated.
This is why governance cannot be handed to legal or compliance after the architecture is complete. The decisions that create risk are often engineering and product decisions:
- Which dataset was used?
- What was the legal and operational basis for using it?
- What changed during fine-tuning?
- Which outputs can trigger an action?
- Where is human intervention required?
- What does the system log?
- Can the organization reconstruct a decision six months later?
- What happens when a model, vendor, or intended use changes?
If these questions are answered only at audit time, the architecture has already made the important decisions.
Governance will become part of enterprise procurement
I do not believe every company will adopt the same framework in the same way. I do believe enterprise buyers will ask for more evidence.
They will want to know how data is controlled, how models are evaluated, how incidents are handled, and who is accountable. A slide deck will be less persuasive than an operating record. A broad promise of “responsible AI” will be less useful than evidence tied to a real system.
This changes governance from a defensive cost into a commercial capability.
An organization that can answer these questions clearly can move through procurement with less uncertainty. It can have a more serious conversation with regulated buyers. It can distinguish between a controlled system and an impressive demonstration.
ISO/IEC 42001 certification may become valuable evidence of a functioning management system. NIST AI RMF can strengthen the technical work beneath it. EU AI Act readiness can shape how the system is classified, documented, monitored, and brought to market.
None of these substitutes for the others. None guarantees that a system is safe. Together, implemented honestly, they create a stronger operating foundation.
The next generation of builders will build for evidence
The lesson I carried from automotive diagnostics was not about cars. It was about systems.
When the machine becomes more complex, instinct alone stops scaling. You need instrumentation. You need a method. You need to know what changed, what failed, and what evidence supports the next decision.
Enterprise AI is crossing that line now.
The winners will still move quickly. But they will build systems whose data, decisions, risks, and controls can be examined. They will treat governance as part of the product architecture—not paperwork added after deployment.
The Wild West does not end because innovation stops.
It ends because the technology becomes important enough that serious builders learn to prove what they built.
Raj Brar is the founder of Argus AI Labs, where the work focuses on enterprise AI systems, data intelligence, knowledge architecture, and operational governance.






