Stop Trying to Control AI. Build to Harness It.
I was speaking with a lender last month who had just finished their Approved AI Tooling Policy. Version one. Six weeks of committee time. A real document, with a model allowlist, a vendor review process, and a standing committee that would meet monthly to rule on requests.
The week they ratified it, it was already wrong.
Two of the models named in it had been replaced by their makers. One rule about context limits no longer described any product on the market. And three tools that would have passed every test they wrote weren’t on the list at all, because they hadn’t existed when the drafting started.
They hadn’t governed the technology. They had photographed a snapshot of it and called the snapshot a policy. The ink dried slower than the landscape moved.
Every leadership team I talk to is trying to do the same thing. Draw a fixed boundary around a moving object. An approved tools list. A model allowlist. A committee that meets monthly to rule on a market that changes weekly. It feels like the responsible thing. It is the org chart equivalent of nailing the weather to the wall.
There is a name for what this costs you. I have started calling it Control Debt. The gap between how fast the technology evolves and how fast your rules about it can be rewritten. You pay it down in drag, in stale decisions, and in cycles you never got to run.
While you spend a quarter writing the rulebook, the operator who built for adaptation runs three cycles. The cost isn’t a fine. It isn’t a breach. It’s compounding irrelevance. The stack freezes at the exact moment you tried to control it.
The instinct to control the AI stack feels like the responsible choice. It is quietly the most expensive bet on the table
.It is worth being honest about why control is the reflex. It comes from somewhere real.
In lending, control is survival. Audit defence, model risk, data handling, the regulator who will ask you to show your work. For two decades the safe move was to standardize, lock the vendor list, and run a quarterly review. That worked because the environment was stable. The tools you approved in January were the same tools in December.
That world is gone. The reflex didn’t notice.
A control system built for a stable environment, run at constant speed inside an environment that stopped being stable, does not produce safety. It produces lag. The committee still meets. The list still gets maintained. And the gap between the list and reality widens every month nobody is willing to admit.
There is a law that explains exactly why this fails, and it is not a metaphor.
W. Ross Ashby, working in cybernetics in the 1950s, gave us the Law of Requisite Variety. His exact words: only variety can destroy variety. The version everyone uses now is softer, only variety can absorb variety, and the meaning holds either way. For a controller to actually regulate a system, it has to have at least as many possible responses as the system has possible states. Less famously and more bluntly: if the thing you are trying to control can do more than you can respond to, you are not controlling it. You just think you are.
Now hold your governance committee up against the AI landscape.
The committee has low variety. It meets twelve times a year. It produces a list. The landscape has enormous and accelerating variety. New models, new capabilities, new failure modes, every week. By Ashby’s own math, a fixed monthly framework cannot regulate a system moving that fast. You are not being careful. You are being outmatched, and the scoreboard is hidden because nothing has broken yet.
So what does the alternative look like? It is not chaos, and it is not no governance. It is a different shape of control.
Stanley McChrystal learned this the hard way. In Team of Teams he describes how a hierarchical, command and control task force kept losing to a decentralized enemy, Al-Qaeda in Iraq, that adapted faster than the chain of command could issue orders. His answer was not to tighten control. It was to replace it with what he called shared consciousness and empowered execution. Everyone sees the same picture. The decision gets made at the edge, by the people closest to the problem, fast.
That is the model. Govern principles, not inventories. Stop maintaining a list of approved tools and start maintaining a clear standard for what good looks like, then let the person doing the work evaluate this week’s option against it. Build infrastructure that assumes the tools will change. Abstraction layers instead of hard vendor bets. Swappable model providers instead of one name welded into the architecture. A standing habit of evaluation instead of a standing approval queue.
You are not loosening the grip. You are moving it to the layer that doesn’t move.
Here is where the regulated reader gets nervous, and they are right to.
None of this means you abandon real controls. It means you govern the invariants instead of the implementation. Where does borrower data go. Who is accountable for an output that reaches a customer. How do we verify a decision before we act on it. Those questions are stable. The answers don’t change when a new model ships. Lock them down hard.
Which specific model, which vendor, which prompt, which tool. Those are implementation. They change constantly, and the moment you write them into policy you have started accruing Control Debt again.
Lock the invariants. Let the implementation move. That single distinction is the whole game.
The leaders who freeze the stack to feel safe are going to be the ones who fell behind safely. Their policy will be airtight and two years out of date. Their committee will still be meeting.
The competitive edge does not go to the company with the tightest guardrails. It goes to the company that built guardrails as direction instead of as walls, and can pick up next quarter’s tooling without convening anyone.
Govern the direction, not the inventory. Build for the next version, not this one.
Stop trying to control the evolution. Build to harness it.
Chris Grimes is the founder of FundMore, an AI native loan origination platform. FundMore builds agentic mortgage and lending infrastructure for institutional clients across Canada and the US.



