Why govern AI at all?

Lesson 1 of 6 in Why AI Needs Governance: A Taxonomy of Harms and Risks.

Software has caused harm for as long as software has existed, and we did not build a global governance apparatus for spreadsheets. So why AI? Four properties, stacked together, changed the calculation.

Scale. An algorithm makes the same class of decision millions of times. A biased loan officer damages dozens of applicants a year; a biased loan model damages every applicant in its path, identically, at machine speed. When the Dutch tax authority’s risk model went wrong, it did not misjudge a family — it misjudged roughly 26,000 families with a single flawed logic.

Opacity. The affected person usually cannot see the decision logic — often cannot see that an algorithm was involved at all. You cannot argue with a reason you were never given. Traditional accountability assumes a decision-maker who can be questioned; AI quietly removes that person.

Speed — the pacing problem. Capability moves in months; legislation moves in years. ChatGPT reached 100 million users in about two months; the EU AI Act took over three years from proposal to entry into force and phases in over years more. Governance is permanently catching up, which is why so much of this field runs on standards, frameworks, and organisational practice rather than statute alone.

Power asymmetry. The people building frontier systems number in the thousands; the people affected number in the billions. Builders hold the information, the compute, and the choice; affected people hold the consequences. Governance exists to rebalance that ledger — to give the people on the receiving end rights, and the people at the controls duties.

To work in this field you also need its vocabulary, and the three words people use interchangeably in conversation mean different things in risk work:

  • A hazard is a source of potential harm — the property that could hurt someone. An inaccurate face-recognition model is a hazard.
  • Harm is the realised damage — a wrongful arrest, a denied benefit, a leaked medical record.
  • risk is the bridge between them: the likelihood of the harm occurring combined with its severity if it does. Risk = how likely × how bad.

This is why frameworks say “risk-based”: you cannot eliminate every hazard, so you rank by likelihood × severity and spend your controls where the product is largest. It is also why harm to whom matters — the field distinguishes individual harms (one person denied a loan), group harms (a community over-policed), and societal harms (an information ecosystem degraded for everyone). Different scopes demand different remedies: individual redress cannot fix a societal harm.

One honest caveat: the field argues, loudly, about the balance between documented present harms (bias, privacy, safety failures happening now) and speculative future risks (loss of control over very capable systems). You will meet both camps. A working governance professional does not need to pick a side — the taxonomy you are about to learn covers both, and real risk registers contain both.

Key terms: risk, hazard, harm, pacing problem, toeslagenaffaire

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.