• Decrease Text SizeIncrease Text Size

Policy-as-Code for AI

Written policy governs people; executed policy governs systems. The gap between them is where most AI incidents live — a policy forbids sending customer identifiers to external services, and a integration does it anyway because nothing in the pipeline reads the policy. Policy-as-code closes the gap by making the rule an artefact the system evaluates: a classification that excludes a category from indexing, a condition that routes a request for human review, a limit that halts execution. The discipline it demands is precision, because a rule vague enough to be comfortable in a document cannot be executed.

Governance dictionaries in Centralpoint are records the business maintains, imported through Data Transfer and applied by Data Cleaner during ingestion. The organization's own regulatory vocabulary — its statutes, its categories, its terms — becomes the executing rule set, so the policy that governs the estate and the policy the AI enforces are the same artefact rather than two documents that drift apart.


{0}