Governance Is Functions: Why Your AI Won't Scale Without Discipline by Design
In this episode of the Disambiguation podcast, host Michael Fauscette sits down with Chris Morancie, Fractional CTO and Founder of Digital Operations Factory, for a deeply technical and practical conversation about why AI governance has to be engineered into your architecture, not bolted on after the fact.
Chris brings a unique combination of computer information systems, an MBA in business strategy, and a master's in data science to the problem of getting AI into production safely. His core argument: if your governance cannot stop your model from doing something wrong in real time, then it is not governance, it is just documentation.
The conversation covers his three-part scalability test (design for scale, make sure it doesn't break at scale, don't go broke at scale), the Goldilocks zone for model selection, why agents should be treated through a microservices security lens with least-privilege access and short-term tokens, the firewall pattern for policy enforcement, real-time semantic interceptors for customer-facing AI, operational sovereignty and vendor SLA inheritance, IP leakage through model training, and a practical trust-vs-reasoning quadrant for managing hybrid human-agent teams.
Timestamps:
00:00 - Introduction
00:44 - Chris's background: Caribbean upbringing, CIS + MBA + Data Science
03:48 - The AI production framework: design for scale, don't break at scale, don't go broke at scale
07:17 - The Goldilocks zone: model selection and cost benchmarking
09:28 - Assertion testing vs. evaluation testing for model quality
10:25 - "If your governance can't stop your model in real time, it's just documentation"
13:26 - The firewall pattern: policy agents with least-privilege, short-term tokens
16:09 - AI governance as good old-fashioned software hygiene
17:49 - Real-time semantic interceptors for customer-facing agents
21:15 - Competing goals: why prompts alone cannot prevent policy violations
24:02 - Agent security: every ingress and egress point is a vector
27:55 - RAG poisoning and downstream injection attacks
29:00 - Operational sovereignty: SLA inheritance and vendor risk
34:56 - IP leakage: when your feedback trains a competitor's model
36:16 - Trust vs. reasoning: a quadrant for managing hybrid teams
41:37 - Advice by company size: economics for SMEs, security for enterprise
45:25 - Recommendation: DALI Research Labs (YouTube)
Guest: Chris Morancie, Fractional CTO and Founder, Digital Operations Factory
Host: Michael Fauscette, CEO & Chief Analyst, Arion Research
Subscribe and turn on notifications so you never miss an episode.