top of page

When AI Governance Moves From Principle to Practice

Sep 24
7 min read

Updated: Sep 25

What a cross-sector conversation surfaced about the conditions needed to govern advanced AI in practice


HUMAN EDGE INSIGHT | SEPTEMBER 2026



Governance frameworks are necessarily built around principles, responsibilities, and thresholds. The harder questions often emerge when those ideas have to operate across institutions, technical systems, and people with very different responsibilities.

 

That was one of the clearest themes to emerge from an August 27th Human Edge Roundtable in Boston, hosted by SG+I and Morrison & Forester in partnership with Anthropic, which focused on Governing Advanced AI With Transparency, Safety, and Public Trust.

 

The discussion used Anthropic's Advanced AI Framework (AAIF) as a starting point and brought together perspectives spanning frontier AI, government, independent evaluation and research, cybersecurity, enterprise technology, biosecurity, public health, social sciences, civil liberties, law, compliance, and the Massachusetts AI ecosystem. The purpose was not to reach consensus on the framework, but to examine what happens when governance principles encounter the practical realities of implementation.

 

As the conversation developed, many of the questions moved beyond the developer itself. Independent evaluation depended on who was qualified to conduct it and under what conditions. Transparency depended on who needed information and what they were expected to do with it. Preparedness raised questions about where specialized capability resides and how government can access it. And accountability became more complicated when responsibility crossed institutional boundaries.

 

Taken together, those discussions pointed toward a broader question: What needs to exist around a governance framework for it to work as intended?

 

Independent evaluation in practice

 

Independent evaluation generated some of the most substantive discussion of the afternoon. There was relatively little debate about its importance. The more difficult questions concerned what a credible evaluation actually requires: who is qualified to conduct it? What access they need? How much time meaningful evaluation takes? And how independence is maintained as demand for evaluation grows?

 

Those questions became more complicated as different disciplines came into view. A person qualified to assess cyber risk may not have the expertise needed to interpret a biological capability, just as technical evaluation alone may not capture every question surrounding model behavior or its consequences. What emerged was less a universal definition of the “qualified evaluator” than a recognition that qualification may depend on the risk being evaluated. In some cases, credible evaluation may require teams that combine technical and domain expertise rather than a single evaluator profile.

 

There was also a very practical discussion about time. A pre-release evaluation period may sound substantial, but that same period can include defining scope, determining what should be tested, establishing access and procedures, conducting the assessment, interpreting findings, and preparing reporting. The distinction between notice time and usable evaluation time matters. If much of the infrastructure has to be assembled after the clock starts, the actual time available for substantive evaluation can be considerably shorter.

 

That suggests that some elements of evaluation readiness may need to exist before an evaluation begins: established relationships, methodologies, access protocols, clearer ways of defining scope, and people with the appropriate expertise.

 

Capacity introduces another consideration. If independent evaluation becomes a more established part of advanced AI governance, demand for qualified evaluators is likely to grow with it. Expanding that capacity could address an important constraint, but a larger evaluator ecosystem also brings questions about funding, accreditation, liability, commercial incentives, evaluator selection, conflicts, and independence.

 

The challenge, then, is not simply building more evaluation capacity. It is developing that capacity in ways that preserve the credibility independent evaluation is intended to provide.

 

Where governance gets complicated

 

Another theme emerged when the discussion moved beyond the developer and into the institutions surrounding the technology.

 

Consider an enterprise using an advanced model developed by one company but accessed through another technology provider. The developer may have its own governance commitments. The provider may have another set of controls. The enterprise may have internal policies, contractual requirements, monitoring, compliance obligations, and risk-management practices of its own.

 

How those layers interact is not always obvious.

 

Versions of the same issue appeared elsewhere in the discussion: between developers and independent evaluators, evaluators and domain specialists, private technical capability and public authority, and federal and state government.

 

What was interesting was that the problem was not necessarily an absence of governance. Each institution may have clearly defined responsibilities and controls of its own. Ambiguity can emerge at the point where information, authority, or responsibility moves from one institution to another.

 

Transparency illustrates the same challenge.

 

Different actors need different information for different purposes. The public may need information to support accountability. Independent evaluators may require deeper technical access. Enterprises need enough information to understand and manage their own risks. Government institutions may need sensitive information to prepare for or respond to potential threats. At the same time, some information may need to remain protected because broader disclosure could introduce security or misuse concerns.

 

Seen this way, transparency is not simply a question of how much information is disclosed. It is also about how information moves: who needs it, what they need to know, what protections are appropriate, and what the recipient is expected to do with it.

 

That last point became particularly important. Disclosure and actionability are not the same thing. An institution can receive information—and even have responsibility for acting on it—without necessarily possessing the technical expertise, resources, authority, or operating speed required to respond effectively.

 

The practical question is therefore not only whether information is available, but whether it reaches the right institution in a form that enables meaningful action.

 

Capability, preparedness, and the role of states

 

The conversation about societal resilience introduced a related distinction between authority and capability.

 

Government has responsibilities and authorities that appropriately belong to government. But many of the specialized capabilities that could be relevant to advanced AI risks reside elsewhere: in cybersecurity organizations, universities, research institutions, public-health organizations, critical-infrastructure operators, technology companies, and other parts of the ecosystem.

 

At the same time, organizations that could experience AI-enabled risks may have little advanced AI expertise of their own. A municipality, water system, hospital, or other public institution does not need to be developing frontier AI to find itself affected by increasingly capable systems.

 

That makes preparedness partly a question of how institutions access expertise they do not possess internally. It also makes relationships important. If specialized capability will need to move across institutional boundaries during an incident, building those relationships for the first time during a crisis is unlikely to be sufficient.

 

The Massachusetts setting made this particularly interesting. The Commonwealth and broader region bring together universities, cybersecurity, life sciences and biosecurity, enterprise technology, law, civil liberties, government, national-security research, AI companies, and a broader technology ecosystem. That concentration does not, by itself, point toward a particular regulatory approach or call for a new institution.

 

It does suggest another way to think about the state's role.

 

Some challenges will require policy. Others may depend on the capacity to evaluate, implement, coordinate, prepare, or respond effectively under authorities that already exist. Distinguishing between those problems matters, particularly when technology is moving more quickly than traditional institutional processes.

 

Massachusetts may therefore have something to contribute not only as a policymaking environment, but as a place where some of these implementation questions can be examined across institutions.

 

From principles to operating conditions

 

Looking across the discussion, a common thread begins to emerge.

 

Independent evaluation depends on more than the existence of an evaluation requirement. It depends on expertise, methodology, access, independence, institutional trust, funding, and enough usable time to do the work well.

 

Transparency depends not simply on disclosure, but on information reaching the appropriate people through workable channels and in a form they can interpret and act upon.

 

Accountability becomes more difficult when responsibility crosses institutional boundaries. Preparedness depends in part on connecting public authority with technical and domain capabilities that may sit elsewhere. State governance depends not only on the authority to make rules, but also on expertise, coordination, implementation capacity, and the ability to adapt.

 

The AAIF establishes governance expectations for advanced AI developers. What became clearer through the Roundtable was how much the effectiveness of those expectations may also depend on operating conditions outside the developer.

 

That does not mean a developer framework should attempt to solve every downstream institutional challenge. Many of those responsibilities appropriately sit elsewhere. But understanding the dependencies matters if governance principles are expected to function in practice.

 

The distinction feels particularly relevant now. In the weeks since the August Roundtable, questions surrounding independent evaluation have continued to move from principle toward implementation. As different approaches develop, questions of evaluator access, expertise, independence, institutional relationships, and accountability are becoming less hypothetical.

 

Rather than resolving the questions raised in Boston, those developments reinforce the value of continuing to examine them.

 

How should evaluator independence be preserved while providing enough access to understand increasingly capable systems? How should expertise vary with the risk being assessed? What responsibilities sit with the developer, evaluator, technology provider, enterprise, or government? And what institutional capacity needs to exist before an evaluation, disclosure, or incident requires action?

 

There may not be one institution capable of answering those questions on its own. That is part of what makes cross-sector examination useful.

 

What we're carrying forward

 

The August Roundtable did not produce a single answer, nor was that its purpose. Its value was in bringing different operating perspectives to the same governance questions and seeing where the assumptions, dependencies, and institutional boundaries became more visible.

 

That is also where we see an important role for Human Edge. Cross-sector dialogue can do more than collect perspectives. Done well, it can expose where responsibilities intersect, where capabilities are missing, and where an idea that appears straightforward from one institutional vantage point becomes more complicated when viewed from another.

 

As advanced AI governance continues to develop, Human Edge will continue creating opportunities to examine those questions across disciplines and sectors, connecting governance principles with the people, institutions, capabilities, and real-world conditions that ultimately determine how they work in practice.

 

About this Human Edge Insight

 

Governing Advanced AI With Transparency, Safety, and Public Trust was convened on August 27, 2026, in Boston by Strategic Growth & Innovation (SG+I) / Human Edge with Morrison Foerster. The discussion used Anthropic's Advanced AI Framework as a starting point for cross-sector examination of advanced AI governance.

 

The Roundtable was conducted off the record to support candid dialogue. This Insight reflects SG+I's synthesis of themes and questions emerging from the discussion and does not represent consensus among participants or the positions of any individual participant or organization.

 

Explore Human Edge Roundtables → here

Comments


Stay Connected

Ideas, insights, and updates from SG+I and Human Edge.

​

Follow the work emerging across Human Edge Studios, Roundtables, and SG+I's broader work around AI, leadership, workforce, and human impact.

  • LinkedIn

© 2026 Strategic Growth & Innovation, LLC. | Privacy Policy

Thanks for subscribing!

Email         info@strategicgrowthandinnovation.com

​Address     P.O. Box 870099, Milton, MA 02186

bottom of page