Learn

How AI works, and how to govern it

Short, sourced answers to the questions that come up when an organization starts putting AI to work. Each page answers one question and stands on its own. The figures are marked where they are our arithmetic rather than a published measurement.

How AI works

What the word covers, what a model is made of, and why running AI costs more than building it.

  1. 01When people say "AI," what are they talking about?At least six different technologies, with different costs, risks, and rules. Three independent questions sort them: did a person write the rule or did a machine learn it, does it score something or produce something, and does it advise a person or act on its own.
  2. 02Which AI systems can have their logic audited, and which cannot?Rule-based systems, yes: a person wrote the logic down, so you can read the rule that produced a result. Learned systems, no. There is no written reasoning to read, only behavior to measure and test.
  3. 03Is it predicting something, or making something?Predictive AI scores something that already exists, and the real answer eventually arrives to check it against. Generative AI produces something new, where there is usually no answer to check. That one difference sets how each is tested, what it runs on, and where its return can be measured.
  4. 04Does the AI advise a person, or act on its own?Advisory AI produces an output and a person decides before anything happens. Agentic AI acts, and nobody stands between its decision and the effect. Most real deployments sit between the two, and where a system sits decides who answers for what it does.
  5. 05What is a model weight, and what is a transformer?A weight is a number that survived training. A model is billions of them, arranged in layers, and together they decide how an input becomes an output. Nobody, including the people who trained the model, can point at one weight and say what it is for.
  6. 06What is the difference between training and inference?Training finds a model's weights, once, over weeks or months. Inference uses those weights to answer a request, every time anyone asks, for as long as the model is deployed. Over a model's life, inference is the larger and the permanent load.
  7. 07Does all AI need a hyperscale data center?No. Training frontier models does. Most deployed AI runs on ordinary hardware, and much of what runs on frontier models does not need to: one study estimates that routing each task to the smallest model that does it well would cut global AI energy use by 27.8%.
  8. 08What is the difference between open weights and open source?Open weights means a model's trained numbers are published, so anyone can download, run, and adapt it. Open source, in the traditional sense, also publishes the code and often the training data. Nearly every model marketed as open is open weights only.

Judging AI governance

Five questions that work on any AI system, vendor, or internal project, and what a good answer sounds like.

  1. 09How do you tell real AI governance from theater?Ask five questions, in order: where the data goes, who built the model, whether the controls are enforced while the system runs, what you can see while it runs, and whether you can prove afterwards who did what. The third is the one almost everyone fails.
  2. 10Where does your data go when people use AI?It should go to a named destination, for a named retention period, with a clear statement on training use and a contract term behind all three. If nobody can say where it goes, nobody drew the boundary, and there is nothing to enforce later.
  3. 11Who built the AI model, and on what?A named model from a named provider. Almost nobody trains their own frontier model, so most AI products are built on someone else's, and whoever buys one inherits that provider's training data, terms, and update schedule along with it.
  4. 12Are your AI controls enforced, or just written down?Usually written down. A policy document says what people are supposed to do; an enforced control stops what should not happen whether or not anyone remembers the policy. This is the question that separates AI governance from theater, and most systems fail it.
  5. 13What can you see while your AI is running?Live usage, cost, and rule triggers, on a screen your own people can open without asking the vendor. A quarterly report is the past, described by the party being evaluated. Observability is live, and independent of them.
  6. 14Can you prove afterwards who did what with AI?Only with a complete, tamper-resistant record that ties every interaction to an identified person or agent, kept long enough to matter. The question decides what you have after something goes wrong, which is the only moment anyone asks it in earnest.

Control and its limits

Where a rule can be enforced, what no rule can guarantee, and who answers when an AI system acts.

  1. 15What does AI enforcement at runtime actually look like?One point that every AI request passes through on its way to a model, where rules are applied before a response reaches anyone. Four things become possible there: inspection, enforcement, observation, and attribution. Because the point sits apart from the applications, its rules are configuration.
  2. 16What can and cannot be guaranteed about an AI system?You can guarantee the space of allowed actions: a system can be built so it is capable only of what a defined set permits. You can never prove that a perception is correct. That holds for every system that acts on perception, people included.
  3. 17What can an AI governance layer not do?It bounds what a system may do and records what it did. It cannot verify that a model's perception of the world was correct, it cannot govern traffic that never passes through it, and it does not address how a model was trained.
  4. 18Who is liable when an AI system causes harm, or an agent acts?The people and organizations behind the system. California now says so in statute: a party that developed, modified, or used an AI system cannot defend itself by saying the system caused the harm on its own. With agents, the hard part is a record showing who stood behind the action.
  5. 19Can one AI system comply with several regulatory regimes at once?Yes, where the rules live at one control point as configuration. Where every application carries its own copy of the rules in code, each difference between regimes means rebuilding applications. The deciding factor is where enforcement sits.

Reference

The terms that carry weight, and the AI statistics that do not survive a trip to their source.

  1. 20Which AI statistics should you stop repeating?Four widely repeated figures fail when traced to a primary source: inference as 80 to 90% of AI energy, 71% local opposition to data centers, a 150 kW rack, and 95% of generative AI pilots producing no profit. Each has a version that holds, or nothing that does.
  2. 21AI glossary: the terms that carry weightA short list of the AI terms that carry the most weight in governance and cost decisions, each defined in plain English and linked to the page that goes deeper.