Patrick Upmann | Machine Authority & Agentic AI Governance
AI Governance · Machine Authority · Board Oversight · München · Global AI Governance · Machine Authority · Board Oversight · Munich · Global

PatrickUpmannMachine Authority & Agentic AI GovernanceMachine Authority & Agentic AI Governance

Defensible AI Governance für Vorstände, Aufsichtsräte und Betreiber kritischer Systeme — mit dem Ziel, Machine Authority kontrollierbar, nachvollziehbar und verteidigbar zu machen. Defensible AI Governance for boards, supervisory boards, and operators of critical systems — with the goal of making Machine Authority controllable, traceable, and defensible.
Wer hat der Maschine die Autorität gegeben, das zu tun — und können Sie es beweisen? Who gave the machine the authority to do that — and can you prove it?
Ich ersetze nicht Ihre AI-Governance-, Risk-, Compliance-, Security- oder Internal-Audit-Funktion. Ich challenge extern den Punkt, an dem sie zusammenlaufen: die Authority, die Ihre Organisation der Maschine tatsächlich einräumt. I do not replace your AI governance, risk, compliance, security, or internal audit function. I provide an external challenge at the point where they meet: the authority your organisation is actually giving the machine.
Patrick Upmann — AI Governance Advisor, Architect of DART and AIGN Critical OS
Gründer & Architekt · AIGN.Global · AIGN OS 4.0
Autor · The AI Governance Operating Series
Founder & Architect · AIGN.Global · AIGN OS 4.0
Author · The AI Governance Operating Series
25+Jahre Governance & TransformationYears in Governance & Transformation
30+Mandate seit 2014Engagements since 2014
Regulierte & kritische SektorenRegulated & Critical Sectors
3Bücher · The AI Governance Operating SeriesBooks · The AI Governance Operating Series
Geladener SpeakerInvited Speaker · NATO SPS ARW 2026 · ArmenienArmenia
Geladener Speaker · NATO SPS ARW, Yerevan (Sept. 2026) · Speaker/Panelist · Fintech Week Frankfurt (Okt. 2026) · 18 DOI-registrierte Publikationen · 19.400+ LinkedIn · International zitiert:Invited Speaker · NATO SPS ARW, Yerevan (Sep 2026) · Speaker/Panelist · Fintech Week Frankfurt (Oct 2026) · 18 DOI-registered publications · 19,400+ LinkedIn · Quoted internationally: Infobae Mundo · The New Africa Magazine
Nachgewiesene UmsetzungAudit Readiness · Governance Operating Models · Access & Control Structures · +30 % Effizienz in einem Data-Governance-Mandat (E.ON) Verifiable DeliveryAudit readiness · governance operating models · access & control structures · +30% efficiency in one data governance engagement (E.ON)
Wann Governance auf die Agenda gehörtWhen Governance Belongs on the Agenda

Drei Momente, in denen Sie mich anrufen solltenThree moments to call me

Vor dem Go-LiveBefore Go-Live
Ein AI-Agent steht kurz davor, materielle Entscheidungs- oder Handlungsbefugnis zu erhalten.An AI agent is about to receive material decision or action authority.
Wenn sich Authority ändertWhen Authority Changes
Neue API, neuer MCP-Server, neues Transaktionsrecht, neuer Kommunikationskanal, neuer Datenzugriff oder ein höheres Limit.New API, MCP server, transaction right, communication channel, data access, or higher limit.
Nach einem IncidentAfter an Incident
Der Agent hat gehandelt — und das Management muss verstehen, ob Capability, Permission und autorisierte Authority auseinandergefallen sind.The agent acted — and management needs to understand whether capability, permission, and authorised authority diverged.
Weitere typische Situationen ansehenSee more typical situations
„Wir haben plötzlich Agents im Unternehmen.“"We suddenly have agents operating inside the company."
„Der Vorstand bekommt keine belastbare Übersicht.“"The board isn't getting a reliable overview."
„Risk, Compliance, IT und Business erzählen unterschiedliche Geschichten.“"Risk, Compliance, IT, and the business tell different stories."
„Nach Reorganisation/M&A stimmen Entscheidungsrechte und Systemrechte möglicherweise nicht mehr überein.“"After a reorganisation or M&A, decision rights and system permissions may no longer line up."
Warum Governance — ökonomisch betrachtetWhy Governance — the Economic Case
Governance ermöglicht AI schneller zu skalieren, Fehlfreigaben zu vermeiden, Rework zu reduzieren, Entscheidungen zu beschleunigen, Auditfähigkeit herzustellen und kritische AI kontrolliert produktiv zu setzen — nicht, AI zu verlangsamen. Governance enables you to scale AI faster, avoid faulty approvals, reduce rework, speed up decisions, establish audit readiness, and put critical AI into production under control — not slow AI down.
MandateWays to Work Together

Vom Go-Live-Review zur dauerhaften Governance.From go-live review to lasting governance.

Beratung, Keynote und Workshop — für Vorstände, Aufsichtsräte und Prüfungsausschüsse, mit besonderem Fokus auf Energie, Finanzinfrastruktur, Mobilität, Telekommunikation und Defence/Dual-Use.Advisory, keynote, and workshop — for boards, supervisory boards, and audit committees, with a particular focus on energy, financial infrastructure, mobility, telecommunications, and defence/dual-use.

Wer hat der Maschine die Autorität gegeben, das zu tun — und können Sie es beweisen?Who gave the machine the authority to do that — and can you prove it?

01
BeratungAdvisory
Mandate vom fokussierten Machine Authority Go-Live Review bis zur laufenden Board AdvisoryEngagements from a focused Machine Authority Go-Live Review to ongoing board advisory
02
Keynote
Vorstands- und aufsichtsratstaugliche Vorträge für Konferenzen & ForenBoard-ready talks for conferences & executive forums
03
Executive WorkshopExecutive Workshop
Gemeinsames Lagebild für Vorstand, Aufsichtsrat und FührungsteamA shared briefing for board, supervisory board and leadership team
Evidence behind the work — Keynotes, Bücher, Publikationen und Track Record, die diese Positionierung belegen.Evidence behind the work — keynotes, books, publications, and track record that back this positioning. Ansehen →View →
01 · BeratungAdvisory
Flaggschiff · Vor dem Go-LiveFlagship · Before Go-Live
Machine Authority Go-Live ReviewMachine Authority Go-Live Review
Permission is technical. Authority is organisational.

Externe Challenge für einen materiellen AI-Agenten oder Use Case vor Produktivsetzung oder Authority-Erweiterung: Mandat & Owner, organisatorische Authority, technische Permissions, Daten/Tools/APIs/MCP, Kommunikations- & Transaktionsbefugnis, Human Reserved Authority, Runtime-Grenzen, Intervention & Revocation, Evidence & Traceability.
Permission is technical. Authority is organisational.

An external challenge for one material AI agent or use case before production or material authority expansion: mandate & owner, organisational authority, technical permissions, data/tools/APIs/MCP, communication & transaction authority, human reserved authority, runtime limits, intervention & revocation, evidence & traceability.
ScopeScope1 materieller Agent/Use Casematerial agent/use case
FormatFormatFokussierte externe ChallengeFocused external challenge
DauerTimingi.d.R. 5 Werktage ab EvidenzverfügbarkeitTypically 5 business days after evidence availability
ModellModelFixed Scope · Fixed Fee nach ScopingFixed scope · fixed fee after scoping
OutputOutput Machine Authority Decision Memo (Authority Boundary · Material Exposure Findings · Human Reserved Decisions · Control & Evidence Gaps · Conditions Requiring Management Decision) + Executive Readout Machine Authority Decision Memo (authority boundary · material exposure findings · human reserved decisions · control & evidence gaps · conditions requiring management decision) + executive readout
Die Entscheidung über die Produktivsetzung verbleibt bei der Organisation. Das Review liefert eine externe Governance-Challenge — keine Zertifizierung oder Freigabe.The management decision to deploy remains with the organisation. The review provides an external governance challenge — not a certification or approval.
20-Min. Scoping-Gespräch anfragen →Request a 20-min scoping call → oder Scope per E-Mail anfragen →or request scope by email →
Aufsichtsrat & PrüfungsausschussSupervisory Board & Audit Committee
Board AI Governance BriefingBoard AI Governance Briefing
Vertrauliche Executive Session für Aufsichtsrat und Prüfungsausschuss: Machine Authority, Materiality, Oversight und Evidence — strukturiert entlang DART. Kein Management-Beratungsmandat, sondern die Aufsichtsperspektive.A confidential executive session for supervisory boards and audit committees: machine authority, materiality, oversight, and evidence — structured along DART. Not a management advisory mandate — the oversight perspective.
FormatFormat90–120 Min. · vertraulichmin · confidential
FokusFocusMachine Authority · Materiality · Oversight · Evidence
OutputOutput Board Question Set + 90-Day Oversight PrioritiesBoard Question Set + 90-Day Oversight Priorities
Board Briefing anfragen →Request Board Briefing → Board-Vertiefung ansehen →View board deep dive →
Critical Systems · KRITISCritical Systems · KRITIS
Critical AI Governance Review
Sind KI-Systeme in kritischen Prozessen ausreichend begrenzt, kontrollierbar und rekonstruierbar? Für Energie, Finanzinfrastruktur, Mobilität, Telekommunikation und Defence/Dual-Use.Are AI systems in critical processes sufficiently bounded, controllable, and reconstructable? For energy, financial infrastructure, mobility, telecommunications, and defence/dual-use.
Review anfragen →Request review → Critical AI Governance vertiefen →Go deeper on Critical AI Governance →
FolgemandatFollow-on engagement Auf Basis der Review-Findings: Agent Mandate, Authority Envelope und Human Accountability Anchor für den konkreten Einsatzkontext.Building on the review findings: the Agent Mandate, Authority Envelope, and Human Accountability Anchor for the specific context. Agentic AI Governance Design anfragen →Request Agentic AI Governance Design →
02–03 · Keynote & Workshop
Keynote · 30–60 Min.Keynote · 30–60 min
Keynote & VortragKeynote & Talk
Vorstands- und aufsichtsratstaugliche Vorträge zu KI-Governance-Rechenschaft, Machine Authority und EU-AI-Act-Strategie — für Konferenzen, Executive-Foren und Regulierungsbehörden.Board- and supervisory-board-ready talks on AI governance accountability, machine authority, and EU AI Act strategy — for conferences, executive forums, and regulatory bodies.
Keynote anfragen →Request keynote →
Workshop · 90–120 Min.Workshop · 90–120 min
Executive WorkshopExecutive Workshop
Management-Arbeitssession für Vorstand und Führungsteam: konkrete Use Cases, Decision Rights, Governance-Prioritäten und die nächsten 90 Tage — im Unterschied zum Board AI Governance Briefing arbeitsorientiert statt Aufsichtsperspektive.A management working session for the executive team: concrete use cases, decision rights, governance priorities, and the next 90 days — working-level, unlike the oversight perspective of the Board AI Governance Briefing.
Workshop anfragen →Request workshop →
Executive-PrüfrasterExecutive Test Framework
DART: die Challenge für delegierte Machine Authority.DART: the challenge for delegated machine authority.
Kein Enterprise-Governance-Modell, kein regulatorischer Standard — sondern das proprietäre Executive-Prüfraster für die Frage, was einem KI-System tatsächlich übertragen wurde und ob diese Delegation kontrollierbar bleibt. Zentrales Werkzeug jedes Beratungsmandats, einschließlich des Machine Authority Go-Live Review.Not an enterprise governance model, not a regulatory standard — the proprietary executive test for what an AI system has actually been given and whether that delegation remains controllable. The core tool of every advisory engagement, including the Machine Authority Go-Live Review.
DART & Board Oversight ansehen →View DART & board oversight →
D
Delegation
A
Authority
R
Runtime ControlRuntime Control
T
Traceability
Illustrative Governance ScenariosIllustrative Governance Scenarios

Wenn AI handelt, wird Governance konkret.When AI acts, governance becomes concrete.

Die folgenden illustrativen Szenarien zeigen typische Situationen, in denen aus AI Capability reale organisatorische Handlungsmacht wird. Entscheidend ist dann nicht nur, ob ein System funktioniert, sondern welche Authority ihm übertragen wurde, welche Grenzen gelten und ob Management und Aufsicht diese Delegation kontrollieren und nachvollziehen können.The following illustrative scenarios show typical situations in which AI capability turns into real organisational authority to act. What matters then is not only whether a system works, but what authority it has been given, which boundaries apply, and whether management and oversight can control and reconstruct that delegation.

Use Case 01 · VorstandExecutive Board

Agent erhält operative EntscheidungsrechteAgent Gains Operational Decision Rights

SituationSituation

Ein Unternehmen führt einen AI-Agenten ein, der nicht mehr nur analysiert oder empfiehlt, sondern Bestellungen auslösen, Kunden kontaktieren, interne Workflows starten oder Systeme verändern kann.A company deploys an AI agent that no longer just analyses or recommends, but can trigger orders, contact customers, start internal workflows, or change systems.

Governance-FrageGovernance Question

Welche Entscheidungen darf der Agent tatsächlich treffen — und wer hat diese Authority genehmigt?Which decisions may the agent actually make — and who approved that authority?

Typische LückeTypical Gap

Der Use Case wurde fachlich freigegeben, aber niemand hat explizit festgelegt, welche operative Handlungsmacht damit übertragen wurde.The use case was approved from a business perspective, but no one explicitly defined what operational authority it actually transferred.

Executive RelevanzExecutive Relevance

Der Vorstand muss erkennen können, wo aus AI-Nutzung faktische Delegation von Unternehmensentscheidungen wird.The board must be able to recognise where AI use turns into the de facto delegation of corporate decisions.

Governance ResponseGovernance Response

Agent Mandate · Authority Envelope · Human Accountability · Runtime Limits · Evidence

Use Case 02 · AufsichtsratSupervisory Board

Management berichtet über AI, aber nicht über Machine AuthorityManagement Reports on AI, Not on Machine Authority

SituationSituation

Der Aufsichtsrat erhält regelmäßig Informationen über AI-Projekte, Investitionen, Risiken und Compliance. Nicht sichtbar ist jedoch, welche Systeme eigenständig handeln können.The supervisory board regularly receives information on AI projects, investments, risks, and compliance. Not visible, however, is which systems can act independently.

Governance-FrageGovernance Question

Kann das Gremium erkennen, wo AI für Strategie, Risikolage oder operative Kontrolle wirklich wesentlich wird?Can the board recognise where AI truly becomes material to strategy, risk exposure, or operational control?

Typische LückeTypical Gap

Ein AI-Inventar zeigt Modelle und Use Cases, aber nicht deren tatsächliche Berechtigungen, operative Reichweite oder Handlungsmacht.An AI inventory shows models and use cases, but not their actual permissions, operational reach, or authority.

Board RelevanzBoard Relevance

Ein System mit großem technischen Zugriff kann erheblich relevanter sein als ein formal als „AI-Projekt“ klassifizierter Use Case.A system with broad technical access can be far more relevant than a use case formally classified as an "AI project."

Governance ResponseGovernance Response

Board AI Materiality · Machine Authority Exposure · Escalation Thresholds · Board Reporting · Board Question Set

Use Case 03 · Energie / KRITIS

AI optimiert einen kritischen ProzessAI Optimises a Critical Process

SituationSituation

AI erkennt Anomalien, priorisiert Wartung, optimiert Last, Verfügbarkeit oder Betrieb und beeinflusst dadurch Entscheidungen in einem kritischen technischen Prozess.AI detects anomalies, prioritises maintenance, optimises load, availability, or operations — and thereby influences decisions in a critical technical process.

Governance-FrageGovernance Question

Welche Optimierungsentscheidung darf AI autonom treffen — und wo muss eine technische oder menschliche Grenze zwingend Vorrang haben?Which optimisation decisions may AI make autonomously — and where must a technical or human boundary always take precedence?

Typische LückeTypical Gap

Ein wirtschaftliches Optimierungsziel kann unbeabsichtigt mit Safety-, Resilienz- oder Versorgungsvorgaben kollidieren.An economic optimisation goal can unintentionally collide with safety, resilience, or supply requirements.

KRITIS-RelevanzRelevance

Fehler betreffen nicht nur Effizienz, sondern möglicherweise Betriebskontinuität, Versorgung oder Sicherheit.Errors affect not only efficiency but potentially operational continuity, supply, or safety.

Governance ResponseGovernance Response

Critical Authority Envelope · Non-Overrideable Boundaries · Human Intervention · Fail-Safe Logic · Incident Evidence

Weitere Szenarien ansehen (Prüfungsausschuss · Finanzinfrastruktur · Reorganisation/M&A)See more scenarios (audit committee · financial infrastructure · reorganisation/M&A)
Use Case 04 · PrüfungsausschussAudit Committee

Governance existiert, Wirksamkeit ist aber nicht belegbarGovernance Exists, but Effectiveness Cannot Be Proven

SituationSituation

Policies, Risk Assessments und Freigabeprozesse sind vorhanden. Das Unternehmen kann jedoch nicht belastbar zeigen, ob die genehmigten Grenzen während des tatsächlichen Betriebs eingehalten wurden.Policies, risk assessments, and approval processes exist. However, the company cannot reliably show whether the approved boundaries were actually observed during live operation.

Governance-FrageGovernance Question

Woran erkennt der Prüfungsausschuss, dass AI Governance nicht nur dokumentiert, sondern wirksam betrieben wird?How does the audit committee recognise that AI governance is not just documented, but operated effectively?

Typische LückeTypical Gap

Policy, technische Kontrolle, Management Reporting und Audit Evidence sind nicht durchgängig miteinander verbunden.Policy, technical controls, management reporting, and audit evidence are not consistently connected.

Audit-Committee RelevanzAudit Committee Relevance

Zwischen First Line, Risk, Compliance, Security, Internal Audit und Management entsteht eine Evidenzlücke.An evidence gap opens up between first line, risk, compliance, security, internal audit, and management.

Governance ResponseGovernance Response

Control Evidence · Traceability · Independent Challenge & Evidence Map · Exception Reporting · Management Evidence

Use Case 05 · FinanzinfrastrukturFinancial Infrastructure

AI greift in Transaktionen einAI Intervenes in Transactions

SituationSituation

Ein AI-System bewertet Zahlungen oder Transaktionen. Später erhält es zusätzliche Rechte: Transaktionen zurückhalten, Prüfungen initiieren, Limits anwenden oder Kundenkommunikation auslösen.An AI system assesses payments or transactions. It later gains additional rights: holding back transactions, initiating reviews, applying limits, or triggering customer communication.

Governance-FrageGovernance Question

Wann wird aus einer Empfehlung eine finanzielle Handlungsmacht?At what point does a recommendation become financial authority to act?

Typische LückeTypical Gap

Technische Berechtigungen, Risikolimits und organisatorische Entscheidungsrechte stimmen nicht vollständig überein.Technical permissions, risk limits, and organisational decision rights do not fully align.

Business RelevanzBusiness Relevance

Fehler können unmittelbar Kunden, Liquidität, regulatorische Anforderungen oder operative Abläufe betreffen.Errors can immediately affect customers, liquidity, regulatory requirements, or operations.

Governance ResponseGovernance Response

Transaction Authority Limits · Human Escalation · Runtime Controls · Re-Approval · Action Evidence

Use Case 06 · Reorganisation / M&AReorganisation / M&A

Die Organisation ändert sich, Maschinenrechte bleibenThe Organisation Changes, Machine Rights Remain

SituationSituation

Nach Reorganisation, Carve-out oder Akquisition ändern sich Verantwortlichkeiten, Freigabegrenzen und Rollen. AI-Agenten, Service Accounts und automatisierte Workflows besitzen jedoch weiterhin ihre bisherigen Berechtigungen.After a reorganisation, carve-out, or acquisition, responsibilities, approval thresholds, and roles change. AI agents, service accounts, and automated workflows, however, retain their previous permissions.

Governance-FrageGovernance Question

Wer darf nach der organisatorischen Veränderung noch im Namen des Unternehmens handeln?Who is still permitted to act in the company's name after the organisational change?

Typische LückeTypical Gap

Organisatorische Authority wurde geändert — technisch wirksame Machine Authority aber nicht.Organisational authority was changed — technically effective machine authority was not.

Executive RelevanzExecutive Relevance

Das Unternehmen kann unbemerkt alte Entscheidungsstrukturen in automatisierten Systemen weiterbetreiben.The company can unknowingly keep running old decision structures inside automated systems.

Governance ResponseGovernance Response

Authority Revalidation · Ownership Review · Re-Approval · Credential Rotation · Revocation Evidence

Illustrative Governance Scenarios — keine Darstellung konkreter Kundenmandate. Illustrative governance scenarios — not a representation of specific client engagements.
VertiefungDeep Dive

Zwei Perspektiven.
Ein Governance-Ansatz.
Two perspectives.
One governance approach.

Für Aufsichtsrat und Vorstand geht es um Oversight und Entscheidungsfähigkeit. Für kritische, hochkonsequente Systeme geht es um Machine Authority im laufenden Betrieb. Beide Vertiefungen im Detail — inklusive DART-Prüfraster und AIGN Critical OS.For boards and supervisory boards, it is about oversight and decision-making capability. For critical, high-consequence systems, it is about machine authority in live operation. Both deep dives in full detail — including the DART framework and AIGN Critical OS.

Für Aufsichtsrat, Prüfungsausschuss & VorstandFor supervisory boards, audit committees & executive boards

Oversight-System, DART-Prüfraster, Board Pack und die fünf Board-Mandate im Detail.The oversight system, DART framework, board pack, and the five board mandates in detail.

Critical AI Governance

Machine Authority im laufenden Betrieb, AIGN Critical OS und die Materiality-Trigger für hochkonsequente Systeme.Machine authority in live operation, AIGN Critical OS, and the materiality triggers for high-consequence systems.

Evidence Behind the WorkEvidence Behind the Work

Der Nachweis hinter
dem Anspruch.
The evidence behind
the claim.

„KI-Governance scheitert nicht an fehlenden Prinzipien — sie scheitert, weil niemand hinter Entscheidungen steht, wenn es darauf ankommt.“"AI governance does not fail because principles are missing — it fails because no one stands behind decisions when it matters."
— Patrick Upmann · Gründer, AIGN.GlobalFounder, AIGN.Global
2025
TRT World Forum
Istanbul, TürkeiIstanbul, Turkey
Geladener Speaker zu KI-Governance als globaler Infrastruktur — neben Staatsoberhäuptern, Regulierern und internationalen Technologieführern.Invited speaker on AI governance as global infrastructure — alongside heads of state, regulators, and international technology leaders.
Geladener SpeakerInvited Speaker
2026
NATO Science for Peace & Security (SPS) Advanced Research Workshop
ArmenienArmenia
Eingeladener Speaker beim NATO SPS Advanced Research Workshop zu KI-Governance in geopolitischen und sicherheitspolitischen Kontexten. Fokus auf vertrauenswürdige KI-Governance als sicherheitsrelevante Infrastruktur.Invited speaker at a NATO Science for Peace and Security (SPS) Advanced Research Workshop on AI governance in geopolitical and security-policy contexts. Focus on trustworthy AI governance as security-relevant infrastructure.
Eingeladener SpeakerInvited Speaker · NATO SPS ARW · 2026
2026
37. EBS Symposium
EBS Universität, DeutschlandEBS University, Germany
Eingeladen zum Wirtschaftssymposium der EBS Universität für Wirtschaft und Recht — eine der führenden Plattformen Europas für Wirtschaft, Recht und Führung.Invited to the economic symposium of EBS University for Business and Law — one of Europe's leading platforms for business, law, and leadership.
ebs-symposium.de · 37.
2026
5. Fintech Week Frankfurt
Frankfurt am Main, DeutschlandFrankfurt am Main, Germany
Speaker & Panelist · Panel: „AI Governance, Risk & Regulation: From Black Box to Explainable Finance“.Speaker & Panelist · Panel: "AI Governance, Risk & Regulation: From Black Box to Explainable Finance".
Offizieller SpeakerOfficial Speaker
2025
Direct Booking Summit
Mexiko-Stadt, MexikoMexico City, Mexico
Keynote zu KI-Governance in der Hospitality-Branche.Keynote on AI governance in the hospitality industry.
Internationaler SpeakerInternational Speaker
Buch · 2026Book · 2026
Defensible Trust
Von Governance-Prinzipien zu operativen Nachweisen: Welches KI-System wurde genutzt, was durfte es tun, wer hat geprüft, welche Kosten entstanden. Für Vorstände, AI-Offices, Risiko-, Rechts- und Compliance-Verantwortliche.From governance principles to operational evidence: which AI system was used, what was it permitted to do, who reviewed it, what costs arose. For boards, AI offices, risk, legal, and compliance leaders.
Bei Amazon →On Amazon →
Buch · 2026Book · 2026
Defensible Autonomy
Was eine Organisation einer Maschine zu tun erlaubt: Agent Mandate, Authority Envelope, Human Accountability Anchor, Runtime Policy Enforcement und Action Evidence Chain.What an organisation permits a machine to do: the Agent Mandate, Authority Envelope, Human Accountability Anchor, Runtime Policy Enforcement, and Action Evidence Chain.
Bei Amazon →On Amazon →
Buch · 2026Book · 2026
Governing Outsourced Intelligence
Die Ökonomie KI-gestützter Unternehmen: Token-Verbrauch, Anbieterkonzentration, operatives Lock-in — und wie Runtime Economic Governance diese Arbeit kontrollierbar hält.The economics of AI-enabled enterprises: token consumption, supplier concentration, operational lock-in — and how Runtime Economic Governance keeps this work controllable.
Bei Amazon →On Amazon →
Defensible Trust · Defensible Autonomy · Governing Outsourced Intelligence by Patrick Upmann
„KI-Governance kann keine reine Policy-Übung mehr bleiben. Die nächste Ära wird durch Nachweise, Klassifizierung, Berechtigung, Laufzeitkontrolle und Vorstands-Assurance definiert.“"AI governance can no longer remain a policy exercise. The next era will be defined by evidence, classification, permission, runtime control, and board-level assurance."
— Patrick Upmann · The AI Governance Operating Series, 2026
18
DOI-registrierte PublikationenDOI-Registered Publications
SSRN
Zenodo · ORCID
3+
Kontinente zitiertContinents cited
2026
AIGN Runtime Economic Governance: Governing AI Cost, Usage and Value in the Token Economy
DOI: 10.5281/ZENODO.20638267
Zenodo · AIGN
2026
The Control–Liability Paradox in AI Governance: Where AI Liability Actually Begins
DOI: 10.5281/ZENODO.19383750
Zenodo · Report
2026
The Geopolitics of AI Governance — AI Governance as a Geopolitical Infrastructure
DOI: 10.5281/ZENODO.19064602
AIGN Global · Preprint
2026
Operationalizing Responsible AI: A Systemic AI Governance Architecture for Organizational Implementation
DOI: 10.5281/ZENODO.19047363
AIGN Global · Report
Alle 18 Publikationen anzeigenShow all 18 publications
2026
AIGN EOS: Education Operating System for Trustworthy AI Decisions Affecting Children
DOI: 10.5281/ZENODO.19450612
Zenodo · Preprint
2026
AI Slop in the Enterprise: Synthetic Knowledge Amplification and the Governance of Organisational Knowledge Infrastructures
DOI: 10.5281/ZENODO.18936597
AIGN OS Research
2025
AIGN OS — AI Agents: The AI Governance Stack as a New Regulatory Infrastructure
DOI: 10.2139/ssrn.5543162
SSRN Working Paper
2025
AIGN OS — Trust Infrastructure: Certification, Licensing, and Market Enforcement for Responsible AI
DOI: 10.2139/ssrn.5561078
SSRN Working Paper
2025
AIGN — Procurement Governance Gate
DOI: 10.5281/ZENODO.17936982
Zenodo · Working Paper
2025
The AI Navigation Gap: A Cross-Domain Analysis of Why Modern Organizations Cannot Form a Unified Future Logic
DOI: 10.5281/ZENODO.17702876
Zenodo · Working Paper
2025
AIGN OS 2.0 — The Operating System for Responsible AI Governance (Architecture, Compliance & Trust Infrastructure)
DOI: 10.5281/ZENODO.17659911
Zenodo · Working Paper
2025
The ASGR Index — Establishing the First Global Benchmark for Systemic AI Governance Readiness
DOI: 10.5281/ZENODO.17475315
Zenodo · Working Paper
2025
The AIGN Declaration on Systemic AI Governance: Defining the Operating Principles for the Age of Intelligent Systems
DOI: 10.5281/ZENODO.17481653
Zenodo · Working Paper
2025
AIGN Systemic AI Governance Stress Test
DOI: 10.2139/ssrn.5489746
SSRN Working Paper
2025
AIGN — AI Governance Compliance Framework for SAP® S/4HANA
DOI: 10.2139/ssrn.5494068
SSRN Working Paper
2025
AIGN OS — The Operating System for Responsible AI Governance
DOI: 10.2139/ssrn.5382603
SSRN Working Paper
2025
The AIGN Academy — Institutionalizing Systemic AI Governance Education
DOI: 10.5281/ZENODO.17462559
Zenodo · Working Paper
2025
AIGN Legal — From Law to Architecture: Institutionalising Systemic Legal AI Governance
DOI: 10.5281/ZENODO.17573539
Zenodo · Working Paper
The AI Governance Gap Brief — #34: Identity Is Not AuthorityIdentity Is Not Authority
34 Ausgaben · 3.100+ Abonnenten · monatlich auf LinkedIn34 issues · 3,100+ subscribers · monthly on LinkedIn
Alle Ausgaben →All issues →
„The AI Governance Gap Brief“ — der monatliche LinkedIn-Newsletter: eine strukturelle Lücke zwischen KI-Einsatz und Governance, Rechenschaft und Regulierung pro Ausgabe. Keine Framework-Theorie. Kein generischer Ratschlag."The AI Governance Gap Brief" — the monthly LinkedIn newsletter: one structural gap between how organisations deploy AI and how governance, accountability, and regulation actually work, per issue. No framework theory. No generic advice.
— Patrick Upmann · Publisher, The AI Governance Gap BriefPublisher, The AI Governance Gap Brief
34
AusgabenIssues
3.100+
Globale LeserGlobal Readers
MonatlichMonthly
LinkedIn Newsletter
Neueste Ausgabe · Issue #34Latest Issue · Issue #34
The AI Governance Gap — Identity Is Not AuthorityIdentity Is Not Authority
Identity-Systeme entdecken den AI-Agenten: Im April 2026 machte Microsoft Entra Agent ID allgemein verfügbar, Okta behandelt Agenten zunehmend als eigenständige Identitäten, und Gartner hat AI-Agent-IAM zu einem eigenständigen Forschungsthema gemacht — zuletzt mit dem Report „IAM for LLM-Based AI Agents“. Das ist ein wichtiger Schritt. Aber er beantwortet nicht die entscheidende Governance-Frage: Wozu wurde diese Maschine von der Organisation tatsächlich autorisiert — zu entscheiden, zu tun und zu verursachen? Denn AI bewegt sich von der Informationserzeugung zum Handeln innerhalb von Organisationen. Und sobald Software zu handeln beginnt, ist Identity erst der Anfang — nicht die Antwort.Identity systems are discovering the AI agent: in April 2026, Microsoft made Entra Agent ID generally available, Okta increasingly treats agents as first-class identities, and Gartner has made AI-agent IAM a distinct research topic — most recently with "IAM for LLM-Based AI Agents". That is an important step. But it does not answer the most consequential governance question: what was this machine actually authorised by the organisation to decide, do and cause? Because AI is moving from generating information to acting inside organisations. And when software begins to act, identity is only the beginning — not the answer.
Ausgabe #34 lesen →Read Issue #34 →
Technologie & KI-SystemeTechnology & AI Systems 9 AusgabenIssues
Wo einzelne KI-Technologien — Identity- und IAM-Systeme, Coding-Agents, AI Spaces, Chatbots, agentische Systeme, Enterprise-Copilots, Shadow AI, algorithmisches CV-Screening — strukturelle Governance-Risiken erzeugen, die Vorstände erst nach dem Vorfall erkennen.Where specific AI technologies — identity and IAM systems, coding agents, AI Spaces, chatbots, agentic systems, enterprise Copilots, shadow AI, algorithmic CV screening — create structural governance exposure that boards cannot see until after the incident.
Weitere Ausgaben anzeigenShow more issuesWeniger anzeigenShow less
Organisation & KulturOrganisation & Culture 13 AusgabenIssues
Wo KI-Governance innerhalb von Organisationen scheitert — an Kultur, Zeitdruck, Budgetentscheidungen, Beschaffungslücken, institutioneller Ordnung, menschlichen Faktoren und struktureller Fehlausrichtung zwischen Absicht und Umsetzung.Where AI governance fails inside organisations — through culture, time pressure, budget decisions, procurement gaps, institutional order, human factors, and structural misalignment between intent and execution.
Weitere Ausgaben anzeigenShow more issuesWeniger anzeigenShow less
Regulierung & HaftungRegulation & Liability 12 AusgabenIssues
Wo konkrete regulatorische Rahmenwerke — EU AI Act, DORA, Datenschutzrecht — auf reale Einsatzentscheidungen treffen, und wo AI-Einsatz neue oder bislang unzureichend sichtbare Haftungs- und Verantwortlichkeitsexposition erzeugen kann.Where specific regulatory frameworks — EU AI Act, DORA, data protection law — meet real deployment decisions, and where AI use can create new or previously insufficiently visible liability and accountability exposure.
Weitere Ausgaben anzeigenShow more issuesWeniger anzeigenShow less

Der Track Record gliedert sich bewusst in zwei unterschiedliche Beweislinien, die nicht vermischt werden:The track record is deliberately split into two distinct evidence lines, which are not mixed together:

01
Operational Governance Track RecordOperational Governance Track Record
25+ Jahre · 30+ Mandate · Finance, Energy, Mobility, Public Sector — Data Governance, Access Controls, Audit Readiness, ISMS.25+ years · 30+ engagements · finance, energy, mobility, public sector — data governance, access controls, audit readiness, ISMS.
02
AI Governance — Intellectual & Executive LeadershipAI Governance — Intellectual & Executive Leadership
DART · AIGN Critical OS · 3 Bücher · 18 DOI-Publikationen · NATO SPS 2026 · AIGN Education Trust Label Pilot (Seoul 2025) · internationale Speaker-Tätigkeit. Siehe DART · AIGN Critical OS · 3 books · 18 DOI publications · NATO SPS 2026 · AIGN Education Trust Label Pilot (Seoul 2025) · international speaking engagements. See Keynotes, BücherBooks & PublikationenPublications.

Die Beweisführung trennt bewusst zwei Ebenen: Der operative Track Record dokumentiert gelieferte Governance-, Risk- und Compliance-Ergebnisse. Die AI-Governance-Expertise wird zusätzlich durch DART, AIGN Critical OS, Bücher, Publikationen und internationale Executive- und Speaker-Aktivitäten dokumentiert.The evidence deliberately separates two levels: the operational track record documents delivered governance, risk, and compliance outcomes. AI governance expertise is additionally documented through DART, AIGN Critical OS, books, publications, and international executive and speaking engagements.

Die folgende Auswahl zeigt die sechs profiliertesten Mandate des operativen Track Records im Umfeld kritischer bzw. regulierter Sektoren — Kritischer SektorCritical Sector kennzeichnet die Branchenzuordnung, nicht den formalen KRITIS-Status der jeweiligen Organisation.The selection below highlights the six most significant engagements from the operational track record in critical or regulated sectors — the Kritischer SektorCritical Sector label marks the sector classification, not a formal legal KRITIS designation of the specific organisation.

ZeitraumPeriod KundeClient RolleRole ErgebnisseOutcomes
2024E.ON Kritischer SektorCritical SectorData Governance & Controls Architect (Interim)Data Governance & Controls Architect (Interim)Kundendatenplattform mit Consent-Automatisierung (+30 % Effizienz); Data Ownership & ZugriffskontrolleCustomer data platform with consent automation (+30% efficiency); data ownership & access control
2024BSR Kritischer SektorCritical SectorRegulatory Governance Lead – DSGVO/NIS2 (Interim)Regulatory Governance Lead – GDPR/NIS2 (Interim)SAP-Lösch-/Aufbewahrungskonzept; NIS2-Readiness & S/4HANA-Migration begleitetSAP deletion/retention concept; NIS2 readiness & S/4HANA migration support
2023MEAG (Munich Re) Kritischer SektorCritical SectorRisk & Audit Readiness Lead – DORA/NIS (Interim)Risk & Audit Readiness Lead – DORA/NIS (Interim)ISMS + Risiko-Framework; DORA-/NIS2-Anforderungen operationalisiertISMS + risk framework; DORA/NIS2 requirements operationalised
2023Viridium Kritischer SektorCritical SectorGovernance & Access Control Lead – DSGVO/ICT (Interim)Governance & Access Control Lead – GDPR/ICT (Interim)Datenschutz-Audit; Governance-Rollenmodell für KernsystemeData protection audit; governance role model for core systems
2021–23Mobility Inside Kritischer SektorCritical SectorISMS & Datenschutz & Governance Lead (Interim)ISMS & Data Protection & Governance Lead (Interim)Governance-Betriebsmodell für Mobilitätsplattform; Datenschutzanforderungen für das Deutschlandticket operationalisiertGovernance operating model for mobility platform; data protection requirements for the Deutschlandticket operationalised
2023Uniper Kritischer SektorCritical SectorData Governance & DatenschutzData Governance & Data ProtectionUmsetzbares Aufbewahrungskonzept im M365-KontextActionable retention concept in the M365 context
15 ausgewählte Mandate seit 2014 anzeigenShow 15 selected engagements since 2014
ZeitraumPeriod KundeClient RolleRole ErgebnisseOutcomes
2025TEDiTEDiData Governance Lead (Interim)SAP-Data-Lakehouse-Framework mit Rollen- und Verantwortlichkeitsmodellen; Policy-Struktur auf Prüfungsfähigkeit ausgelegtSAP Data Lakehouse framework with role/accountability models; policy structure designed for audit readiness
2025AIGN GlobalAI Governance Lead & GründerAI Governance Lead & FounderAIGN OS als Referenzmodell; 18 DOI-registrierte Publikationen; Education Trust Label Pilot SeoulAIGN OS as reference model; 18 DOI-registered publications; Education Trust Label Pilot Seoul
2024Volkswagen GroupAI Act / Data Act Governance Expert (Interim)AI Act / Data Act Governance Expert (Interim)Governance-Analyse für In-Vehicle-DatenmanagementGovernance analysis for in-vehicle data management
2025Boston Consulting GroupEU-Data-Act-BeraterEU Data Act AdvisorAnalyse & Empfehlungen EU Data Act für den LogistiksektorAnalysis & recommendations on the EU Data Act for logistics
2025GenoAkademieAI Governance Advisor & TrainerAI Governance Advisor & TrainerFührungskräfte-Seminare zu EU Data Act & AI-Governance-ReadinessLeadership seminars on EU Data Act & AI Governance Readiness
2019–20MEAG (Munich Re) Kritischer SektorCritical SectorDatenschutz- & Governance-Berater (Interim)Data Protection & Governance Consultant (Interim)Datenschutzanforderungen über alle Anwendungen operationalisiertData protection requirements operationalised across all applications
2020Volkswagen GroupDatenschutz- & ISMS-Berater (Interim)Data Protection & ISMS Consultant (Interim)Datenschutz- & Sicherheitsprozesse implementiertData protection & security processes implemented
2015–19MediaMarkt DE/CH/ES · Aldi Süd · VorwerkData Governance & Compliance Consultant (Interim)Data Governance & Compliance Consultant (Interim)Data Governance, Datenschutz & Compliance für Retail & E-CommerceData governance, data protection & compliance for retail & e-commerce
2014–17Deutsche Bahn Kritischer SektorCritical Sector · ERGO · Verivox · PaybackGovernance & Compliance Consultant (Interim)Governance & Compliance Consultant (Interim)Governance- & Compliance-Strukturen für Finanz-, Mobilitäts- & E-Commerce-UnternehmenGovernance & compliance structures for finance, mobility & e-commerce companies
Kernkompetenzen & BranchenCore Expertise & Sectors
Energie & KRITIS FinanzinfrastrukturFinancial Infrastructure Mobilität & AutomotiveMobility & Automotive EU AI Act · ISO 27001/42001 DORA · NIS2 · DSGVO Agentic-AI-GovernanceAgentic AI Governance SAP S/4HANA · ServiceNow GRC Vorstands- & AufsichtsratsreportingBoard & Supervisory Reporting
"
KI-Governance ist erst dann real, wenn sie wirksam, kontrollierbar und belegbar ist — gerade in Systemen, deren Ausfall nicht nur ein Unternehmen, sondern Infrastruktur, Versorgung oder Gesellschaft treffen kann.AI governance is real only when it is effective, controllable, and provable — especially in systems whose failure can affect not just a company, but infrastructure, supply, or society.
— Patrick Upmann · Gründer, AIGN.Global · Architekt, AIGN OS 4.0Founder, AIGN.Global · Architect, AIGN OS 4.0