AI Mediation Security

AI-Mediated Judgement Formation: The Governance Problem Hiding in Plain Sight

AI no longer only automates work. It shapes how people form judgements before decisions are made, and no existing control framework was designed for that.

Dean Kastelic4 min read

AI is no longer just helping organisations automate work. It is increasingly shaping how people interpret information, compare options, assess risk and form judgements before decisions are made.

The deeper shift

AI adoption is accelerating across industry. Boards are asking about model security, data protection, responsible use, and compliance. While these are important priorities, they are not the real shift now underway.

The deeper change is this: AI is no longer being used only to automate tasks or retrieve information. Automation has existed for decades. We don’t need AI to automate, and fast-moving agents are not where the biggest risk lies.

Where AI is increasingly being used is to help us form judgements.

And we are all doing it.

We ask AI tools to interpret emails, summarise obligations, compare options, prepare recommendations, challenge assumptions, draft risk positions, analyse contracts, assess vendors, frame board papers and even shape strategic choices. In many organisations, AI has quietly become the first stop between information and action.

Why this changes organisational risk

That changes the nature of organisational risk.

The issue is not simply whether an AI output is accurate. The issue is whether the process by which a decision is formed remains trustworthy when AI is part of the decision-making process. A model can influence which facts are considered, which risks are emphasised, which options appear reasonable, which trade-offs are surfaced, and how confident a user feels in a particular course of action.

AI does not merely support decisions. It increasingly mediates judgement formation.

For boards, executives and CFOs, this creates a governance problem that traditional cyber, risk and control frameworks were not designed to address. Existing controls assume that people exercise judgement and technology supports execution. AI changes that assumption. Technology is now participating upstream in the formation of judgement itself.

This matters even more in regulated environments, where accountability cannot be delegated to a model, an agent, or a workflow. Risk acceptance, materiality decisions, regulatory notifications, board attestations, control effectiveness conclusions and strategic trade-offs must remain anchored in named human accountability.

The governance question changes

The solution is not to prevent AI from supporting judgement, as that would be unrealistic and, in many cases, counterproductive. The challenge is to design governance, architecture and assurance mechanisms that preserve the integrity of judgement formation while still allowing organisations to benefit from AI-enabled speed, scale and insight.

This requires a shift in how we frame AI risk.

Instead of treating AI as a data problem, we need to ask how we preserve the trustworthiness, resilience and accountability of AI-mediated judgement formation within organisations.

When we frame the risk this way, the questions change:

Not only: Is the model secure? Not only: Is the data protected? But: Can the organisation still trust the way its judgements are being formed?

Answering that requires controls across several layers: trusted inputs, curated knowledge, model boundaries, agent orchestration, provenance, human decision rights, independence boundaries and independent assurance. It also requires clarity about which activities can be agent-led, which require a human in the loop, and which must remain human-retained because they involve accountability the system cannot hold.

Protecting the judgement layer

As AI becomes embedded across finance, risk, cyber, legal, procurement, operations and strategy, this distinction becomes critical. The organisations that succeed will not be those that simply deploy AI fastest. They will be those that can use AI at speed while preserving the quality, independence and defensibility of human judgement.

The next phase of AI governance is therefore not only about securing systems. It is about protecting the judgement layer.

This is the governance gap I am exploring through the idea of AI Mediation Security: preserving the integrity, resilience and accountability of AI-mediated judgement formation.

Key Takeaway

Existing controls assume people exercise judgement and technology supports execution. AI breaks that assumption by participating upstream in how judgement is formed.

Part two of this series, The Shadow in the Machine, takes up why classical data integrity controls miss this layer entirely.

Where this leads

Regulatory Preparedness

One framework for the 72-hour clock and beyond

Explore Regulatory Preparedness