Governance as Code: How to Ship Explainable AI That Survives an Audit

About this session

Most AI governance conversations happen in conference rooms. This one happens in the codebase. As AI systems increasingly drive consequential decisions in banking, healthcare, and cybersecurity, every major regulatory framework — the EU AI Act, OCC model risk guidance, and emerging audit standards — now requires the same thing: AI that can explain itself in structured, auditable form. But builders know that "add explainability" is not a user story you can sprint on after the model is already in production. This talk presents a practitioner researcher approach to making governance an engineering discipline, not a compliance afterthought. Drawing on three IEEE peer reviewed publications and production experience building AI systems in regulated environments, I'll walk through the AMIDOL framework — a system that automatically converts domain expert diagrams (the flowcharts compliance already approved) into formally verifiable, executable AI representations that regulators can actually audit. AMIDOL achieves 99.7% semantic fidelity at 45ms translation times, making real time explainability viable at production scale. I'll also cover lessons from building an adaptive AI pipeline for cybersecurity alert classification across multiple data sources, where governance constraints had to coexist with real time threat response. Attendees will leave with a concrete architecture for embedding explainability gates into CI/CD pipelines, a mental model for treating audit requirements as engineering specs rather than documentation exercises, and a framework for collaborating with compliance and legal teams without slowing down shipping velocity.

Description (400 words) There's a growing disconnect in how the AI industry talks about governance. Policy people talk about principles. Builders talk about shipping. Both are right, and both are talking past each other. This session is for the builder who has been told "make it explainable" and needs to know what that actually means in production code running at scale. It is not a regulatory overview. It is a practitioner's account of what happens when you try to ship AI systems that are simultaneously powerful, fast, and provably trustworthy in environments where a failed audit has real consequences. I'll start with the core technical problem: the models domain experts approve (flowcharts, access policy diagrams, process maps) are not the models AI systems execute. That gap is where governance breaks down. The AMIDOL framework I developed and published through IEEE closes it by automatically translating approved domain diagrams into formally defined, mathematically precise, executable representations — so AI explanations are rooted in logic that compliance has already validated, not reconstructed after the fact. I'll demo the architecture: how explainability gates sit inside the deployment pipeline and block any model that can't meet a semantic fidelity threshold from reaching production. I'll show what this looks like in practice for cybersecurity alert classification, where my co-authored adaptive AI pipeline had to maintain governance compliance while responding to threat data from multiple sources in real time. Then I'll get into the organizational engineering — the part nobody writes papers about. How to translate audit requirements into engineering specs your team can actually work with. How to structure the collaboration between engineering, compliance, and legal so that governance accelerates shipping rather than blocking it. And why most bias detection efforts fail when they treat fairness as a post hoc metric instead of a design constraint. This talk is for engineers, ML leads, and technical PMs who are building AI systems in environments where "move fast and break things" is not an option — financial services, healthcare, cybersecurity, critical infrastructure — and who need a working architecture, not another framework slide deck. Speaker credentials: IEEE researcher (3 peer reviewed publications), Gold Winner at Women in Tech Global Awards 2025, CX Network Top 50 AI Leaders in CX 2026, international speaker (US, Singapore, India, Morocco), keynote speaker at NCE3 2026, invited speaker at Data Science Salon.

Speaker

Key takeaways

  • A reusable architecture for embedding explainability gates directly into CI/CD pipelines so that no AI model reaches production without meeting a verifiable semantic fidelity threshold — turning governance from a review meeting into an automated engineering control.
  • A practical method for converting the diagrams and workflows your compliance team has already approved into formally defined, executable AI representations that regulators can audit — eliminating the gap between what domain experts trust and what models actually execute.
  • A framework for translating regulatory and audit requirements into engineering specs your team can sprint on, structuring collaboration between engineering, compliance, and legal so that governance accelerates shipping velocity rather than blocking it.

Related sessions