The design layer for AI governance.

Every regulation, standard and client contract you answer to, resolved onto one set of controls — so you can see what is covered, what actually runs, and what is missing.

Free workspace. No card.

Built by AI Career Pro, who have trained over a thousand AI governance practitioners.

EU AI Act

ISO/IEC 42001

Client MSA

Three instrumentsEach asking for its own things, in its own order.

The problem

Everyone owns a piece. Nobody owns the join.

Legal reads the obligation. Engineering builds the system. Risk keeps the register. Each does its part in a different tool — and the space between them, where a requirement becomes a control and a control becomes something that actually runs, belongs to no one.

That join is where governance quietly stops working.

Nowhere to see the whole

Requirements sit in one tool, registers in another, control tracking in a third. Everyone can describe their slice. Nobody can draw the system.

Built for a moment that has passed

Regulations move. Systems move. Governance designed around a single snapshot starts failing the day after it is signed off.

Controls with nothing behind them

Frameworks tell you what to control. They rarely tell you how. A control with nothing running behind it is a sentence in a policy.

The chain

From a clause on a page to a process that runs.

An artefact with nothing extracted from it is a document. An expectation with no control is a wish. A control with no mechanism is a sentence in a policy.

Artefacti

EU AI Act, Article 9

The document that governs you — a regulation, a standard, a client contract.

Expectationii

“Establish, implement, document and maintain a risk management system.”

The individual clause, pulled out and classified by what it actually demands of you.

Controliii

Risk Assessment

One control, answering the same expectation across three separate frameworks. This is where the work stops multiplying.

Mechanismiv

Risk Classification Process

Inputs, outputs, owner, tooling, metrics. The part that actually happens.

Running

Add a fourth artefact next year and most of it lands on controls you already built. The second framework costs a fraction of the first.

Nexus

Map what governs you.

Bring in every artefact you answer to, map its clauses onto a single control set, and watch coverage build across all of them at once.

Explore Nexus

BoardEU AI Act × Control set

2 editing

ARTEFACTCONTROLSMECHANISMSREGULATIONEU AI Act23 expectations extractedArt. 9(1)Risk management systemArt. 10(2)Data and data governanceArt. 14Human oversight+ 20 more expectationsCONTROLRisk assessment2 clauses · 3 artefactsCONTROLData governance1 clause · 2 artefactsCONTROLHuman oversight1 clause · 1 artefactRisk Classification ProcessRunning · owner namedDataset Review BoardRunning · owner namedNothing yetNo mechanism behind this controlPriya

Then read it as coverage.

The same board, turned on its side: every expectation you have taken on, against every control you have designed.

Expectation

Risk assessment

Data governance

Documentation

Logging

Human oversight

Incident response

State

EU AI Act

Art. 9(1)Risk management system

Implemented

Art. 10(2)Data and data governance

Implemented

Art. 11Technical documentation

Covered

Art. 12Record-keeping

Implemented

Art. 14Human oversight

Covered

ISO/IEC 42001

6.1.2AI risk assessment

Implemented

8.3AI system impact assessment

Covered

Client MSA

Sch. 3 §4Incident notification within 24h

Gap

Sch. 3 §7Audit rights and evidence

Covered

GapNothing mapped to it yet

CoveredA control is mapped

ImplementedA mechanism runs it

No undefined middle.

Bring in an artefact

Drop in a regulation, standard or client contract as a PDF. You get back a structured clause tree, with each leaf classified by what it demands.

Map it to controls

Point every clause at your control set. When three frameworks want the same risk assessment, that is one control with three mappings — not three workstreams.

Read the crosswalk

Every expectation resolves to one of three states. Nothing is allowed to sit in an undefined middle.

Work it together

Legal knows the obligation, engineering knows what is feasible. Shared boards, live cursors, and the argument happening on the artefact itself.

Mechanic

Design the mechanism behind the control.

A policy line says what should happen. A mechanism says what consumes what, who owns it, how you measure it, and whether it is working right now.

Explore Mechanic

output → inputMECHANISMIncident Intake6 of 7 functioningReports raised / weekOwner · Priya N.MECHANISMRisk Classification4 of 7 functioningClassified within SLA / weekOwner · Sam O.MECHANISMBoard Escalation1 of 7 functioningEscalations heard / monthNo owner namedBROKEN

Mechanism

Risk Classification Process

4 of 7 functioning

Inputs
What sets it off, and what it consumes
Functioning
Outputs
What it produces, and who receives it
Functioning
Objective
The controls it claims to satisfy
Partial
Scope
Which AI systems it applies to
Functioning
Tooling
The tools, and the ordered playbook
Partial
Metrics
Leading and lagging, with targets
Absent
Ownership
A named person, not a function
Functioning

If you cannot name who owns it and how you would know it stopped working, it is not a mechanism yet.

Scored separately, so a missing owner cannot hide behind a well-written scope.

Health, part by part

Each of the seven scores on its own. A mechanism with no owner and no metrics reads as critical, instead of being averaged into a comfortable number.

Chains

Wire one mechanism’s output into another’s input. When a link breaks, you can see everything downstream of it.

Branches

Fork a mechanism, redesign it in isolation, open it for review. The diff warns which chain connections a merge would break.

Live metrics

Push measurements in over the API, upload a CSV, or type them in. The same numbers drive the health badges and your dashboards.

The method

Adaptive governance.

Governance that senses change, catches emerging harm early, responds quickly, and improves its own controls as it goes.

Cruise, HireVue and South Wales Police all had governance structures. Each was designed around a snapshot, and then the ground moved underneath it.

Good intentions never work. You need good mechanisms to make anything happen.

Jeff Bezos

Founder

James Kavanagh

Formerly leader of the Responsible AI team at AWS. The method came out of watching governance work, and fail, at scale — and it is the same method a thousand practitioners have now been trained on. Read the full approach

Seven principles we teach and build around

Design-first
Safety is a property that emerges from how a system is built. It cannot be bolted on afterwards.
Mechanisms
Defined inputs, real tooling, a named owner, and a loop that improves it over time.
Safety culture
People report problems only when they trust the system to treat them fairly.
Balcony and dance floor
See the whole system from above, and understand how it behaves where the work is actually done.
Vertical connectivity
Bad news has to travel upward fast. In most organisations it is softened at every layer.
Technical and adaptive
Some problems have an expert answer. Others need behaviour to change. Misdiagnose which is which and you lose years.
Approachable
Governance cannot live inside a specialist function. It has to reach the people creating the risk.

The Academy

The school that teaches this is inside it.

AI Career Pro delivers its courses through Balcony — so you learn the method in the same place you will use it, next to the boards you are going to apply it to. See the Academy

Courses
The full AI Career Pro curriculum, including AIGP exam preparation and the Practitioner Program — the same programme a thousand practitioners have already come through.
Open now
Skills
Short and fully interactive. Watch the method, practise it, defend your work to an AI playing your CEO, and finish with a capstone you could use on Monday.
New
Exams
Full practice papers for the certifications, sat against the clock — or opened in study mode, marked question by question with the reasoning.
Open now

Who it is for

Wherever you are starting from.

Governance and responsible AI leadsyou already know what needs to happen. You need somewhere to design it, show it, and prove it runs.

Consultants and advisorsa separate workspace per client, a curated control framework to start from, and a method you can hand over at the end.

Given AI governance on top of your day jobnobody trained you for this. Start in the Academy, then build your first board while the method is still fresh.

Moving into the fieldcareer changers, students and engineers, on the same curriculum a thousand practitioners have already taken.

Start with one board.

Pick a regulation you are actually subject to, map it, and see what comes back.