Why AI Governance Starts With Curating What You Trust
Curia AI | AI Governance Advisory | Insights & Perspectives
One of the things that concerns me most about the current AI debate isn’t the technology.
It’s the quality of the information ecosystem surrounding it.
Every day, thousands of articles are published explaining AI governance, responsible AI, AI strategy or AI ethics. Many are thoughtful and valuable. Many are not. Increasingly, we are seeing AI-generated content built on previous AI-generated content, often repeating the same assertions, the same definitions and the same misconceptions until they begin to acquire the appearance of authority simply through repetition.
That should concern all of us.
It certainly concerned me while contributing to the forthcoming DMA Practical AI Glossary as part of the DMA AI Council and Governance Committee.
The obvious temptation would have been to ask an AI to define every term, polish the language and produce something that looked convincing.
Instead, I deliberately took the opposite approach.
Governance started long before the writing
Before drafting definitions, I spent months identifying and following people and organisations whose thinking consistently demonstrated substance rather than volume. Regulators, academics, privacy professionals, standards bodies, AI assurance practitioners, leading researchers and governance specialists, along with experienced practitioners working at the difficult intersection of technology, law, data and human rights.
As I encountered genuinely valuable ideas, distinctions and terminology, I deliberately captured and curated them, not as immutable truth, but as a growing body of trusted reference material that could be challenged, refined and revisited over time.
The objective wasn’t to make AI smarter.
It was to make my own interactions with AI more intellectually disciplined.
Curating what you trust
One of my growing concerns is that many organisations are unknowingly building AI workflows on top of information they have never consciously evaluated.
The result is often confidence without provenance.
For me, AI governance starts much earlier than model selection, policy documents or risk registers. It starts with a much simpler question. What have you decided is worth trusting?
That applies equally to people, publications, frameworks, regulators, standards bodies and AI outputs themselves. Every organisation is building its own constitutional memory, whether consciously or accidentally. The difference is that some curate it deliberately, while others inherit it by default.
AI became part of the challenge process
Throughout the glossary project, AI was used extensively, but not as an authority. It was used to challenge assumptions, identify omissions, suggest alternative wording, highlight ambiguity and repeatedly play devil’s advocate. Different systems were deliberately asked to disagree with each other, and while consensus was useful, disagreement was often even more valuable.
The objective was never to have AI validate itself. The objective was to expose every important definition to multiple forms of scrutiny before publication.
Alongside that came practitioner judgement, regulatory sense-checking, peer review by members of the DMA AI Council and Governance Committee, review by the DMA legal team, and transparent documentation of the methodology itself. The final publication reflects all of those layers, not the output of any single model.
Human judgement remained accountable
Perhaps the most important principle was also the simplest. Every inclusion, every omission, every definition, every editorial decision and every compromise remained a human responsibility. AI suggested, and humans remained accountable.
The bigger lesson
For me, the biggest lesson from this project has nothing to do with prompt engineering or large language models. It is that good AI governance begins with consciously curating what you trust. The quality of an AI system is influenced not only by the sophistication of its underlying model, but by the quality of the information ecosystem, governance process and human judgement that surrounds it.
That feels like a much more durable lesson than any particular technology, and perhaps it is the one we should be talking about more.