INNOVAREModule 6 · AI Project Management

Case 6: Govern Before You Build

The answer to a dangerous AI system is not a smarter one. It is governance, first — risk management, the EU AI Act's teeth, and the costs (human and environmental) that most projects never price.

July 2026 · Case 6 of 6
As you read — hold this question

When a model does exactly what you measured but not what you meant — is the fix a cleverer AI, or governance first?

€35M
or 7% of global turnover — the maximum EU AI Act fine for a prohibited AI practice.

For years, AI governance was voluntary principles. That era is closing. Under the EU AI Act (in force 2024), deploying a prohibited AI practice can cost up to €35 million or 7% of worldwide annual turnover, whichever is higher (Art. 99(3)); other breaches carry €15M/3%. The Act also demands, in Article 72, ongoing post-market monitoring of high-risk systems across their whole life. The most forward-looking idea in the required reading — that harm accrues after launch — is now law across a continent.

Why AI is different
Quiz: Risk & Governance

The blast radius

The thing that makes AI different from ordinary software is the blast radius: the same power that helps thousands can harm thousands, at once. It is a Formula One engine dropped into a family car — not a bigger bug, but a different kind of harm. And an AI system chasing a target it was given will get exactly what you measured, not what you meant — Goodhart's Law at machine speed.

The uncomfortable answer
The fix is not a smarter AI — a more capable model pursues the wrong target faster. The fix is governance, before capability. America's standards body (NIST) puts a "Govern" function at the centre of its AI framework; Europe's AI Act demands human oversight and months of logs. Decide what you will not allow before you find out the hard way. Contain it before you empower it.

The discipline

Risk management — a habit, not paperwork

Risk management is identifying, evaluating and mitigating risks to improve the likelihood of success. Keep a living risk register; for each risk, score likelihood × impact to know where to spend your worry; then choose a response:

Avoid
Design the risk out entirely.
Reduce
Lower its likelihood or its impact.
Transfer
Shift it — to an insurer or a vendor.
Accept
Knowingly, with eyes open.

Miller adds AI-specific mitigations: retraining and fine-tuning models, adding wrappers to original solutions, building functionally equivalent copies, and a model risk assessment. Where more independence is needed: an algorithmic impact assessment (investigates social impact), algorithmic auditing (reveals how the algorithm works, with audit-finding and audit-response records), and third-party certification against a performance standard.

The law catches up

EU AI Act — Article 72 and the end of the voluntary era

The EU AI Act now requires providers of high-risk AI to keep monitoring performance across the system's whole life, after it ships (Article 72), and to conduct a risk assessment for high-risk systems before deployment. Weak policies and no enforcement are what let individuals be subjected to extensive data collection, intrusive models, privacy violations and surveillance with no ability to contest their treatment — exactly the harms Miller's framework exists to prevent, now backed by penalties of up to €35M or 7% of global turnover.

The cost nobody prices

Sustainability — the environmental line on the invoice

Miller lists extreme environmental impacts as a distinct AI risk: training large data models consumes high energy and water and produces carbon emissions — the scale of emissions for training some models is on the order of a trans-American flight. Sustainability is one of the eleven ethical principle categories and one of the criteria for assessing a system at the Consequence stage. Measuring an AI project's success "beyond time, cost and scope" means counting this too.

Take this away

Govern before you build. The answer to a dangerous or drifting AI system is not more capability — it is a risk register with real responses, independent assessment and auditing, human oversight that the law now requires, and an honest accounting of the human and environmental cost. Decide who you are with this technology before you decide what to build with it.

Quick recall — without looking back

Test yourself on this case

Question 1 of 4

Why is 'a smarter AI' not the answer to a dangerous AI system, and what is?

Because a more capable model pursues the wrong objective faster — greater capability widens the blast radius rather than closing it. The answer is governance before capability: decide the controls, oversight and limits first (NIST places a 'Govern' function at the centre of its AI framework; the EU AI Act mandates human oversight and logging). Contain the system before you empower it.
Question 2 of 4

Describe the risk-management process and the four risk responses.

Keep a living risk register of what could go wrong; for each risk, score likelihood × impact to prioritise; then choose a response: Avoid (design it out), Reduce (lower likelihood or impact), Transfer (to an insurer or vendor), or Accept (knowingly). Miller adds AI-specific mitigations — retraining/fine-tuning, wrappers, functional copies, model risk assessment, algorithmic impact assessment, algorithmic auditing, and third-party certification.
Question 3 of 4

What does Article 72 of the EU AI Act require, and what is the maximum penalty for a prohibited practice?

Article 72 requires providers of high-risk AI systems to conduct ongoing post-market monitoring of performance across the system's whole life after deployment. The maximum penalty for a prohibited AI practice is up to €35 million or 7% of worldwide annual turnover, whichever is higher (Art. 99(3)); other breaches are subject to €15M/3%.
Question 4 of 4

Why does Miller count environmental impact as an AI project risk, and how does it relate to measuring success?

Training large models consumes significant energy and water and emits carbon (on the scale of a trans-American flight for some models), so Miller lists environmental impact as a distinct AI risk and 'damage'. Sustainability is one of the eleven ethical principle categories and a Consequence-stage assessment criterion — so measuring an AI project's success beyond time, cost and scope must include ethical compliance, societal impact and environmental sustainability.

Module 6 Videos

Module 6 · Short · The Report That Made Itself Up
Module 6 · Long Form · Why AI Projects Fail

Sources

EU AI Act
Regulation (EU) 2024/1689 (EU AI Act), Art. 72 (post-market monitoring) and Art. 99 (penalties). White & Case; artificialintelligenceact.eu, 2024.
Required reading
Miller, G.J. (2025). Framework for Managing Artificial Intelligence (AI) Projects. Springer — AI risks, mitigation methods, sustainability.
Frameworks
NIST AI Risk Management Framework (2023) — Govern, Map, Measure, Manage.