The AI debate is stuck on the wrong question.
- Lindsay Timcke

- Jun 24
- 2 min read
Everyone is arguing the same two points. Should we use it. Is it good or bad.
Meanwhile almost no one is handing people what they actually need: a way to start governing it.
So I built one, and I am sharing it - my next two posts are these two docs.
Here is what I keep seeing. Teams open the conversation by asking which framework is best. SOC 2? ISO 42001? NIST? The EU AI Act?
That is the wrong question, and asking it is a tell.
Those four are not competitors. They do four different jobs.
SOC 2 attests.
ISO 42001 manages.
NIST guides.
The EU AI Act regulates.
And not one of them hands your engineer a control to implement on Monday morning. That gap is the whole reason I put this together.
The starter kit is two documents:
1. A white paper that kills the framework-shopping reflex and lays out 10 control domains, crosswalked to all four standards.
2. An AI Governance Audit Plan that turns each domain into a real test: a procedure, the evidence to request, and an adversarial probe.
Because a control that has never been attacked is a hypothesis, not a control.
The maturity scale tops out at tested against an adversary, not documented. That is the line most starter kits never cross, and it is where the theater hides.
This is a starting point, not the last word. Take it, use it, push back on it. If you want the working version of the audit plan in Excel, message me and I will send it over (LinkedIn does not allow it to be uploaded:( )
Gut check: if someone attacked your AI controls tomorrow, would you find out what your policy claims, or what your attack surface actually allows?
