AI GRC tools prove your systems. Who proves your people?
AI GRC tools prove your systems. Who proves your people?
Picture an EU AI Act audit preparation meeting. You open your AI governance platform and show an impressive inventory: every AI system registered, risk-classified, documented, with policy workflows attached. Then the auditor asks a simple question: "Who works with these systems day to day, and how do you prove they are competent to do so?"
That question is where most AI governance stacks go quiet. And it is not a small gap. It is roughly half of what the EU AI Act expects from organizations that deploy AI.
What AI GRC tools actually do, and do well
Platforms like Credo AI, OneTrust AI Governance, Holistic AI and IBM watsonx.governance are built for system-level governance. They are good at it:
- maintaining an inventory of AI systems and use cases;
- running risk assessment workflows and impact assessments;
- mapping systems to regulatory obligations and internal policies;
- collecting model documentation, bias audits and vendor assessments;
- producing dashboards and reports for boards and regulators.
If you operate dozens of AI systems across multiple business units, this layer is not optional. It is the only practical way to keep oversight of a growing AI portfolio. Nothing in this article argues against that.
But notice what every item on that list has in common: the unit of governance is the system. The model, the use case, the vendor, the dataset. People appear in these platforms as workflow approvers and risk owners, not as the subject of evidence themselves.
The half of the EU AI Act they do not cover
The EU AI Act does not only regulate AI systems. It explicitly regulates the relationship between systems and the people who work with them.
Article 4 requires providers and deployers to take measures that support the development of AI literacy among staff and other persons dealing with AI systems on their behalf, taking into account their technical knowledge, experience, education and training, and the context the systems are used in.
Article 26 puts deployer obligations on top of that: organizations using high-risk AI systems must assign human oversight to people who have the necessary competence, training and authority. Article 14 requires high-risk systems to be designed for effective human oversight, but design only works if the humans doing the overseeing actually know what to look for.
Editorial transparency
About the author and sources
Zahed Ashkara is a lawyer, AI governance specialist, and founder of LearnWize. Factual and legal references link to the sources below and in the article. Always check the official publication for the current legal position.
Published on June 11, 2026
Sources for this article
Related articles
Can your people prove their knowledge duties?
Start the 5-minute scan and see which roles cannot yet prove their knowledge duty.