AI Governance & Continuity Research

AI Governance Has All the Pieces. The Research Says They Are Still Disconnected.

A systematic review of AI accountability research identifies disciplinary disconnection across provenance, oversight, governance, documentation, traceability, and related controls. GovKM interprets this as evidence for a larger problem: trustworthy AI depends on preserving the relationships among controls, not merely implementing each control separately.
Connected governance architecture representing provenance, oversight, documentation, traceability, and accountability controls joined into one institutional continuity path.
Expand image

AI governance does not suffer from a shortage of controls.

The field already discusses provenance, documentation, traceability, human oversight, organizational governance, security, accountability, model evaluation, and auditability. Each addresses a legitimate part of the problem.

A systematic review published in August 2026 provides an important signal about what remains unresolved. The LAAF review examined 122 primary studies and 12 regulatory and standards documents across provenance, application logic, human oversight, organizational governance, documentation, and traceability. Among the persistent gaps identified by the authors was disciplinary disconnection.

That finding matters because institutions do not act in disciplines. They act through relationships among them.

The Controls Are Real

Provenance can establish origin and transformation. Human oversight can preserve judgment and escalation. Documentation can preserve declared design and procedure. Traceability can expose execution history. Organizational governance can assign responsibility and policy. Security controls can constrain access and action.

None of these disciplines is unnecessary.

The problem appears when an institution assumes that the presence of each control means the complete institutional trajectory is governed.

A source can have excellent provenance and still be the wrong evidence. Evidence can be valid while the actor lacks authority. A human can approve an action without seeing the context necessary for meaningful review. An audit trail can capture every event without preserving why the action was justified. A record can remain intact while the conditions governing its future reuse disappear.

The Institution Depends on the Handoffs

GovKM represents the institutional path through the Continuity Topology:

Source → Evidence → Authority → Context → Decision → Action → Record → Institutional Memory → Future Reuse.

Established governance disciplines tend to concentrate on particular portions of this topology. Provenance strengthens Source relationships. Evidence management qualifies claims. Governance establishes Authority. Human oversight influences Decision. Security constrains Action. Records and audit systems capture operational evidence. Knowledge management supports Institutional Memory and Future Reuse.

The institutional outcome, however, depends on the handoffs.

Can provenance establish which source became evidence? Can the institution show which authority permitted that evidence to influence the decision? Did current context travel into the decision? Did the authorized decision become the actual action? Does the record prove what really happened? Can future users recover enough lineage to determine whether the prior result remains valid?

Those relationships are where many failures occur.

Disconnected Governance Produces Local Success and System Failure

This helps explain a recurring pattern across recent AI incidents and research. Individual controls can work locally while the complete trajectory fails.

The correct document is retrieved, but the wrong version governs. The correct permission is used for the wrong purpose. A safety check succeeds and the later action ignores it. An agent action occurs while the supervisory record is delayed. A memory retains useful information but loses its trust state. A human approval exists without enough evidence to demonstrate meaningful oversight.

Each component can look reasonable in isolation.

The system-level failure appears only when the relationships are reconstructed.

This is why averages of local control performance can overstate institutional reliability. Continuity is compositional. The whole trajectory is only as trustworthy as the relationships connecting its parts.

Continuity Is Not a Replacement Discipline

The appropriate conclusion is not that provenance, AI governance, records management, knowledge management, security, or human oversight have failed as disciplines.

The opposite is closer to the truth: they are increasingly sophisticated at solving their own portions of the problem.

Organizational Continuity addresses what happens between them.

It asks whether the relationships necessary to carry meaning, authority, evidence, context, and accountability across disciplinary and system boundaries remain explicit and reconstructable.

That makes continuity an integrating architecture rather than a competing specialty.

Why AI Makes the Disconnection More Consequential

Human organizations have historically compensated for disconnected controls through tacit understanding. Experienced personnel know which policy is current, which database is authoritative, which exception applies, which office owns a decision, and which old record should not be treated as precedent.

AI systems make those implicit relationships more consequential because they operate at greater speed, across more repositories, and with less access to unrecorded institutional nuance.

If governance remains distributed across separate disciplines without machine-readable relationships among them, AI can combine individually valid artifacts into an institutionally invalid conclusion.

The answer may be sourced. The action may be permitted. The record may be complete. The outcome can still lack continuity.

External Research Is Converging on the Relationship Problem

The LAAF review should not be read as validation of GovKM's complete Continuity Topology. It uses its own accountability architecture and terminology.

Its significance for GovKM is narrower and more useful: an independent synthesis of the AI-accountability literature identifies disciplinary disconnection as an unresolved problem alongside weak human-oversight specification, limited empirical evaluation, and lack of common accountability metrics.

That is external evidence that the field's challenge is increasingly architectural.

The components of trustworthy AI are becoming clearer. The difficult question is how they remain connected through actual institutional work.

The GovKM Proposition

The disciplines manage essential elements. Continuity governs the relationships among those elements.

That proposition does not diminish existing governance practices. It gives them a shared institutional trajectory.

As AI moves deeper into consequential operations, organizations will need to know not merely whether provenance, oversight, governance, documentation, security, and records controls exist. They will need to establish whether those controls remain continuously connected from the originating source through the resulting action, record, institutional memory, and future reuse.

That is the difference between possessing a collection of controls and preserving institutional continuity.

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.