§ Perspectives · AI Governance · July 2, 2026

Judgment is not evidence.

What a Harvard AI-governance intensive teaches your C-suite — and the one thing it structurally cannot give you.

By Lindsay Hiebert · Founder · CISSP

Judgment vs. evidence: a workshop-built AI-governance playbook is self-attested; a verifiable artifact is what a board, auditor, or underwriter can independently confirm.

The pitch for executive AI-governance programs tends to open on fear — a mock newspaper front page, say, of a company fined under the AI Act after an audit turns up no documented risk assessments, no defined governance roles, and no audit trail for automated decisions affecting thousands. It’s an effective hook because the fear underneath it is entirely real. AI governance has become a board-level liability, and most organizations are not ready.

So let me start where most vendor blogs won’t: the course is good, and you should probably take it.

What the intensive actually delivers

Harvard Data Science Review runs a serious executive program — the AI Governance Intensive, a roughly two-and-a-half-week, live and AI-guided online course offered in collaboration with Next Gen Learning, with a certificate of completion from the Harvard Data Science Initiative. Over that stretch, senior leaders work through the course’s S.T.E.E.R. framework (Situate, Tension-test, Establish, Evidence, Roll out and review), which the course credits to Prof. Stephanie Dick (Assistant Professor at Simon Fraser University, with a Harvard history-of-science PhD and an editorial column at Harvard Data Science Review), alongside listed faculty including David Leslie (Director of Ethics and Responsible Innovation Research at the Alan Turing Institute) and Dr. Saara Hyvönen (co-founder of DAIN Studios; Professor of Practice at the University of Jyväskylä). It is aimed squarely at the people who will be held accountable: C-suite, heads of function, boards, and the consultants advising them. No technical background required.

What you walk away with is genuinely valuable:

  • Judgment. A mental model for sociotechnical risk — where fairness tensions bite, what decision rights a governance council needs, how accountability should flow.
  • A peer cohort. Senior leaders wrestling with the same questions, worth as much as the curriculum.
  • A first-draft playbook, personalized to your organization: a landscape scan, a fairness audit, a governance charter, a 90-day plan.

No software replaces that. If a couple of weeks of live sessions and some executive time buy your board a shared language and the confidence to commission governance, that is money well spent. Now the hard part.

Notice what every phase produces

Walk back through those five phases. The landscape scan is your self-report of where AI lives. The fairness audit is your team’s assessment. The governance charter is your stated intent. The 90-day plan is your promise.

All of it is necessary. None of it is evidence.

Every deliverable of a course — or of any manual, consultant-led build — shares three structural limits:

  1. It is self-attested, not verifiable. You cannot audit what you assert. A well-written playbook and an empty one look identical from the outside.
  2. It is self-reported, not observed. A workshop maps the AI you know about; shadow AI is, by definition, the AI you don’t.
  3. It is point-in-time, not current. The day the cohort ends, drift begins. A playbook is a photograph. Your risk surface is a film that keeps rolling.

The program’s own theme is that governance which stays on paper is not governance. Exactly right. I would only extend it: governance you cannot prove is governance you cannot defend — not in an audit, not in a claim, not in a lawsuit, not in a diligence room.

What SanctumShield delivers that the manual approach cannot match

This seam is precisely what SanctumShield was built to close. It produces the same five stages the course teaches — mapped, in our own neutral language, to Discover → Assess → Establish → Prove → Sustain — but as verifiable, observed, continuously refreshed artifacts, in about ten minutes rather than two and a half weeks. The one that matters most: Prove — a verification URL, queryable for five years, that an auditor or underwriter can paste and independently confirm. Observation over attestation. This is the phase the course names “Evidence” and can only template; SanctumShield actually produces the evidence.

Executive intensive / manual buildSanctumShield
OutputFirst-draft playbook, self-authoredBoard-ready artifact set, generated
BasisSelf-reportedObserved (real network egress)
VerifiabilitySelf-attestedThird-party-verifiable URL, 5-year
CurrencyPoint-in-timeRefreshed monthly vs. 12 frameworks
Time~2.5 weeks · live cohort · executive time~10 minutes · $99/month
What it gives youJudgment, cohort, credentialProof

The honest synthesis

None of this is an argument against the course. Take it — for the judgment and the people in the room. Just don’t confuse the binder you bring home with the evidence your board will actually be asked to produce.

The intensive teaches you to want the playbook. SanctumShield is how you hold it — provably, and still true a quarter later. One builds the executive who can lead AI governance. The other builds the artifact that survives the audit. You need both, and only one of them takes ten minutes.

Governance that stays on paper is not governance. Governance you can prove is a different thing entirely. See the full five-stage mapping, read the five stages explained, or run the free Shadow AI Risk Calculator for an observed picture of your exposure.

§ Why this is a legal question, not a tooling preference

Everything above is an argument about method. Underneath it sits an obligation that does not depend on which method you pick. Documented, dated, demonstrable governance is what the law asks for, and the dates have stopped being in the future.

EU AI Act Article 4 — AI literacy
In force since February 2, 2025. National enforcement began August 2, 2026.
EU AI Act Article 50 — transparency
Applies since August 2, 2026.
Colorado SB 26-189
Effective January 1, 2027.
EU AI Act Articles 12, 14 and 17 — record-keeping, human oversight, quality management
High-risk regime: December 2, 2027 (Annex III) and August 2, 2028 (Annex I).

Read those together and the shape is consistent. Each one asks an organization to produce something — a measure taken, a disclosure made, a record kept, a review performed — and to be able to show it after the fact. None of them names a product, a platform or a link, and nothing here should be read as saying a law requires one. What a law requires is the record. Making that record dated and third-party-verifiable is simply how you let an auditor, an underwriter or a board confirm it without being handed the contents, or being asked to take your word for it.

And literacy is not one obligation among several. It is the one the others rest on. You cannot exercise due diligence over a system you cannot recognise, and you cannot govern an authority you do not understand you have delegated.

That is why Article 4 sits in the opening chapter of the Act, ahead of the risk tiers, and why it applied eighteen months before the high-risk regime does. The duty is to take measures that support the development of AI literacy among the people operating AI on the organization’s behalf — and the useful version of that is matched to the seat. What a director needs to recognise is not what a developer needs to recognise, and neither is what the person pasting a contract into a browser tab needs to recognise. A single org-wide module satisfies the form and misses the point.

Free Shadow AI Risk Audit

See what your current stack is missing — in 12 questions.

The SanctumShield free Shadow AI Risk Calculator runs in your browser. No account, no email, no credit card. Twelve questions, instant risk score, three primary findings tailored to what you submit.

Perspectives · a standalone essay outside the numbered CISO Learning Journey · see the full blog →

Judgment Is Not Evidence — What a Harvard AI-Governance Intensive Can't Give You · SanctumShield