Enterprise AI adoption is racing ahead of the governance frameworks meant to contain it, and the gap between what AI systems can do and what organisations can actually investigate is widening.
AI researcher Ryan Greenblatt, who led the transcript analysis of the OpenAI/Hugging Face hacking incident, said, “The difficulty of understanding incidents and overseeing AI agents appears to be growing faster than the rate at which more capable AIs help us with oversight and understanding.”
According to Theta Lake, traditional GRC tools such as SOC 2 and ISO 27001 were never built for this problem. They do not cover prompt injection, model drift or hallucinatory risk, nor do they offer any mechanism for capturing and investigating human-to-AI interactions, leaving firms exposed under frameworks including ISO/IEC 42001, the EU AI Act and the NIST AI Risk Management Framework.
A credible AI compliance solution rests on three pillars. The first is inventory and system discovery, aimed squarely at Shadow AI, the unauthorised use of public LLMs and embedded GenAI tools that bypasses existing data governance the moment an employee pastes in confidential information.
The second is data and model governance, covering training data lineage, prompt-layer DLP enforcement, and model explainability for regulated industries.
The third, and most frequently overlooked, is communications and interaction governance, often referred to as Digital Communications Governance and Archiving (DCGA), which addresses the actual prompts, responses and AI-driven conversations generated across a business daily.
The regulatory backdrop is far from uniform. ISO/IEC 42001 offers a certifiable AI Management System with third-party verification; NIST’s AI RMF provides a voluntary but widely referenced structure built around Govern, Map, Measure and Manage; and the EU AI Act imposes binding, risk-tiered obligations including conformity assessments and mandatory logging for high-risk systems.
Interaction governance is where most solutions fall short. Normalising fragmented prompt and response logs into a single reviewable format, routing incidents to the right stakeholder group, whether security, legal, HR or compliance, and continuously re-scanning archived interactions as new risk patterns emerge are all cited as non-negotiable capabilities. Theta Lake’s platform is positioned as addressing this specific pillar, providing interaction-layer collection and AI surveillance capabilities.
For procurement teams, a four-point checklist is proposed: automated Shadow AI discovery, ISO/IEC 42001 certification of the vendor itself, full-context investigation views of AI interactions, and DLP enforcement at the prompt layer. Any gap across these represents genuine compliance exposure.
Read the full Theta Lake post here.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





