All reports

KYE Governed Research Rail · Bulletin · Edition 2026-06

The Say-Do Gap in AI Governance: why stated controls fail their first incident — June 2026

seriesRoadmap to AI Governance formatBulletin sectorcross-sector audienceLegal Counsel cadenceMonthly Free edition

Ed25519-sealed · fingerprint 5a69e556b20cf896 · verify it yourself ↓

KYE Protocol governs actions and authorities, not outcomes, diagnoses, or results. This report synthesises public sources under the evidence / no-hallucination gate — every claim below is pinned to a cited source.

Executive tear-sheet

There is a measurable gap between what organisations say about their AI governance and what they can actually prove — and that gap is invisible until the first incident, when it becomes the whole case. Reporting on publicly available commentary, not legal or compliance advice: a "say-do gap" framing aimed at in-house legal teams sets out five claims organisations routinely make about AI controls and the awkward questions each invites. This brief relays that framing and, separately and clearly labelled, shows what closing each gap looks like when a control is engineered and replay-verifiable rather than asserted. It does not advise on the law or on any organisation's position. This edition is itself Ed25519-sealed and verifiable from public keys alone — a brief about un-evidenced governance that you can independently evidence.

Key findings

  • A stated control is not an enforced control. A policy that sits in a drawer, a review nobody logged, a rule that relies on trust — each reads as governance and behaves as a press release until it is tested.
  • The gap is in the evidence, not the intent. Organisations mean what they say; they cannot always show it after the fact. That is an authority-and-evidence problem, not a sincerity problem.
  • Regulators are now naming it. The FSB's June 2026 consultation says oversight must be meaningful, not nominal, and tells firms to go looking for rubber-stamping — humans who approve AI recommendations without modification.
  • The fix is the same in every row: make the control execute at the action boundary and leave a replay-verifiable record — so "do" and "prove" stop depending on trust.

From SAY to DO to PROVE

TL;DR The five say-do pairs below are the cited commentary's; the PROVE column is KYE Protocol™'s interpretation of what an engineered, evidenced control looks like — not legal advice.

The five say-do pairs below are the cited commentary's; the PROVE column is KYE Protocol™'s interpretation of what an engineered, evidenced control looks like — not legal advice.

  • SAY: "We have an AI use policy." DO: when was it last reviewed, who signed it, how many people have read it? A policy in a drawer governs nothing. PROVE: KYE Protocol™ compiles policy into a runtime decision the action must pass (<a href="/knowledge-graph.html">Action Admissibility™</a>) — a policy that executes at the boundary cannot sit in a drawer.
  • SAY: "Every AI output is reviewed by a human." DO: review is rarely defined, logged, or checked. PROVE: approvals run through governed modes (single / two-person / legal-gated / auto) and each approval emits an evidence event — oversight you can show, with rubber-stamping visible rather than hidden.
  • SAY: "Confidential data never goes into public tools." DO: shadow use is largely untracked. PROVE: data use is checked at the moment of use; a disallowed use becomes a refused, logged event, not an untracked one.
  • SAY: "Someone is accountable when AI gets it wrong." DO: accountability is named on paper, untested in practice. PROVE: the acting principal is named in the authority chain, and the decision replays deterministically — the first real error is reconstructable, not a guess (<a href="/authority-sourcing.html">Authority Sourcing™</a>).
  • SAY: "Our approach is risk-based." DO: ask to see the register, the triggers, the last escalation. PROVE: the register, the evidence, and a ≤90-day attestation cadence are the artefacts — "ask to see it" has an answer, captured in the sealed <a href="/evidence-pack.html">Evidence Pack™</a>.

What KYE Protocol™ reads into it (interpretation, not advice)

TL;DR This section is KYE Protocol™'s interpretation, clearly separated from the cited commentary above, and is not legal or compliance advice.

This section is KYE Protocol™'s interpretation, clearly separated from the cited commentary above, and is not legal or compliance advice. The say-do gap is precisely the gap KYE Protocol™ exists to close: it does not make an organisation's policy wiser or an AI output correct — it makes the control execute at the action boundary and leave a record that is Replay-Proof™, verifiable from published keys alone. The difference between "do" and "prove" is the difference between a control that survives its first incident and one that does not. Whether and how any of this applies to a given organisation is a matter for that organisation's own advisers.

Claims → sources — every claim mapped to a pinned source

This is the claims→source map: no claim ships without a cited, pinned public source (evidence gate). Each numbered claim below is pinned into this edition's sealed evidence pack kye:evidence-pack:research:say-do-gap-ai-governance:2026-06.

  1. Commentary aimed at in-house legal teams has named a 'say-do gap' in AI governance — the distance between what organisations say about their AI controls (a use policy exists, every output is human-reviewed, confidential data never enters public tools, someone is accountable, the approach is risk-based) and what they can actually evidence in practice. https://globallegalai.com/Global Legal AI, 'The Say-Do Gap'. Cited as commentary, not as a statement of law. (retrieved 2026-06-13T00:00:00Z)
  2. The Financial Stability Board's June 2026 consultation on sound practices for AI states that oversight must be meaningful rather than nominal and instructs institutions to investigate cases where humans consistently approve AI recommendations without modification — i.e. oversight that cannot be evidenced is not oversight. https://www.fsb.org/Financial Stability Board (consultation report). Publisher-level citation; deep-link to be pinned. (retrieved 2026-06-13T00:00:00Z)

Replay-verifiable

This edition is sealed and Ed25519-signed over the published keys. Any reader can confirm the seal offline — no KYE service required.

Signature algorithm
EdDSA
Key id
kye:key:self-audit-fixture-2026-06
Seal fingerprint
5a69e556b20cf896 (sha256 of the signature, first 16 hex)
Published keys (JWKS)
/trust/self-audit-jwks.json
Report envelope
kye:research-report:say-do-gap-ai-governance-2026-06 · schema kye.research_report.v1

Verify it yourself: fetch the published JWKS, recompute the Ed25519 signature over this edition's canonicalised envelope (minus seal) bound to the body hash, and confirm it matches the key id above — from public keys alone, no KYE service in the loop.

How verification works